Attacking SMB via Metasploit and PSexec
Recon
simple scan
nmap -A 10.2.23.46 -vv
data:image/s3,"s3://crabby-images/7b72e/7b72ede8c3781b2ef5ffe2ac6698c4b8140996e7" alt=""
TIP: TTL could be handy in enumerating operating systems.
Unix: TTL 64
Windows: TTL 128
Solaris/AIX: TTL 25
445 port is open
nmap -p445 — script smb-protocols 10.2.23.46 -vv
data:image/s3,"s3://crabby-images/69e74/69e74b77006648283b1fe56e44374930f09a831b" alt=""
Setting up Metasploit.
data:image/s3,"s3://crabby-images/3c572/3c57269456e4f747fe012ab8b6bd574dd956eb1c" alt=""
Setting up smb_login module.
data:image/s3,"s3://crabby-images/ab864/ab864a277c533e565e620269e0f5b3edb79563f5" alt=""
Setting up brute force word lists and auxillary scan.
data:image/s3,"s3://crabby-images/e3fd3/e3fd3be10fc8d489634d9b0e6280e793d37dc354" alt=""
data:image/s3,"s3://crabby-images/fd879/fd879c2fa97935027ed0888a2c0f9e0a51332f9a" alt=""
Identified list of compromised accounts.
data:image/s3,"s3://crabby-images/3cb71/3cb71f2556c57dc20a1e53d344bb6cd61dc4c240" alt=""
Setting up PSexec.
data:image/s3,"s3://crabby-images/62ecd/62ecd462e3eae05ae6011cfcdfcc34eefdff1279" alt=""
data:image/s3,"s3://crabby-images/7fdc0/7fdc0ef598967cb8b42e3695ef2a9694817ea9ab" alt=""
Meterpreter shell.
data:image/s3,"s3://crabby-images/250d7/250d7dc084188bb719c84f7efd00cf7c74b3264a" alt=""
data:image/s3,"s3://crabby-images/2d5b6/2d5b65237638efa4b0878cd567a7f977c2f5c2a0" alt=""
MITRE ATT&CK
PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.