SMB (445)
Anonymous Login
smbclient -L \\\\$IP -NBulk enumeration
crackmapexec smb 172.16.20.3-254 -u '' -p '' --sharesIf you able to login to the machine, to retrieve all share folder in the specific hostname:
net view <hostname> /allEnumerate / list the shares
smbclient -L //$IP/
smbmap -H $IP
crackmapexec smb $IP -u '' -p '' --shares -M spider_plusAccessing the shares
smbclient //$IP/shares
# input blank password for anonymous login
smbclient //$IP/shares -U <username>%<password>
smbmap -u <username> -p <password -H $IPthere are some dir shares?
Last updated