Foothold

❯ smbclient '\\192.168.209.30\nara' -U Guest%''
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Thu Oct 24 06:35:43 2024
  ..                                DHS        0  Thu Oct 24 06:14:06 2024
  Documents                           D        0  Sun Jul 30 09:03:13 2023
  Important.txt                       A     2200  Sun Jul 30 09:05:31 2023
  IT                                  D        0  Sun Jul 30 11:22:50 2023

                7699711 blocks of size 4096. 3934768 blocks available
smb: \> prompt off
smb: \> recurse on
smb: \> mget *
getting file \Important.txt of size 2200 as Important.txt (12.3 KiloBytes/sec) (average 12.3 KiloBytes/sec)
smb: \> cd Documents\
smb: \Documents\> ls
  .                                   D        0  Sun Jul 30 09:03:13 2023
  ..                                  D        0  Thu Oct 24 06:35:43 2024

                7699711 blocks of size 4096. 3934768 blocks available
smb: \Documents\> cd ..
smb: \> cd IT
smb: \IT\> ls
  .                                   D        0  Sun Jul 30 11:22:50 2023
  ..                                  D        0  Thu Oct 24 06:35:43 2024

                7699711 blocks of size 4096. 3934768 blocks available
smb: \IT\>

We can create a malicious lnk file using the slinky netexec module to capture hashes

We can add ourselves to the remote access group

Last updated