No Credentials

Scan Network

nmap -Pn -sC -sV -p- $ip
nmap -Pn --script smb-vuln* -p139,445 $ip
nmap -sU -sC -sV -p- $ip
nxc smb $net


Anonymous & Guest access on SMB

enum4linux-ng -u '' -p '' $ip
nxc smb $ip -u '' -p ''
nxc smb $ip -u '' -p '' -M spider_plus
nxc smb $net -u '' -p ''
nxc smb $net -u 'a' -p '' -M spider_plus
smbclient -U '%' -L //$ip
smbclient -U 'guest%' -L //$ip
nxc ldap $ip -u '' -p '' --users

DNS zone transfer

dig axfr $domain @nameserver

Enum LDAP & users


  1. Bruteforce user


  1. Poisoning

Last updated