Smb/smb version
De www.metasploit-es.com.ar
El escaneador "smb_version" conecta con cada estacion de trabajo en un rango de hosts dado y determina la version del servicio SMB en ejecucion.
msf > use auxiliary/scanner/smb/smb_version msf auxiliary(smb_version) > show options Module options: Name Current Setting Required Description ---- --------------- -------- ----------- RHOSTS yes The target address range or CIDR identifier SMBDomain WORKGROUP no The Windows domain to use for authentication SMBPass no The password for the specified username SMBUser no The username to authenticate as THREADS 1 yes The number of concurrent threads msf auxiliary(smb_version) > set RHOSTS 192.168.1.150-165 RHOSTS => 192.168.1.150-165 msf auxiliary(smb_version) > set THREADS 16 THREADS => 16 msf auxiliary(smb_version) > run [*] 192.168.1.162 is running Windows 7 Enterprise (Build 7600) (language: Unknown) (name:XEN-WIN7-BARE) (domain:HOTZONE) [*] 192.168.1.154 is running Unix Samba 3.0.20-Debian (language: Unknown) (domain:WORKGROUP) [*] 192.168.1.150 is running Windows XP Service Pack 2 (language: English) (name:V-XPSP2-SPLOIT-) (domain:WORKGROUP) [*] Scanned 04 of 16 hosts (025% complete) [*] 192.168.1.160 is running Windows XP Service Pack 3 (language: English) (name:XEN-XP-PATCHED) (domain:HOTZONE) [*] 192.168.1.161 is running Windows XP Service Pack 2 (language: English) (name:XEN-XP-SP2-BARE) (domain:XEN-XP-SP2-BARE) [*] Scanned 11 of 16 hosts (068% complete) [*] Scanned 14 of 16 hosts (087% complete) [*] Scanned 16 of 16 hosts (100% complete) [*] Auxiliary module execution completed
Ejecutando este mismo escaneo con un conjunto de credenciales devolvera diferentes, y quizas inesperados, resultados.
msf auxiliary(smb_version) > set SMBPass s3cr3t SMBPass => s3cr3t msf auxiliary(smb_version) > set SMBUser Administrator SMBUser => Administrator msf auxiliary(smb_version) > run [*] 192.168.1.160 is running Windows XP Service Pack 3 (language: English) (name:XEN-XP-PATCHED) (domain:XEN-XP-PATCHED) [*] 192.168.1.150 is running Windows XP Service Pack 2 (language: English) (name:V-XPSP2-SPLOIT-) (domain:V-XPSP2-SPLOIT-) [*] Scanned 05 of 16 hosts (031% complete) [*] 192.168.1.161 is running Windows XP Service Pack 2 (language: English) (name:XEN-XP-SP2-BARE) (domain:XEN-XP-SP2-BARE) [*] Scanned 12 of 16 hosts (075% complete) [*] Scanned 14 of 16 hosts (087% complete) [*] Scanned 15 of 16 hosts (093% complete) [*] Scanned 16 of 16 hosts (100% complete) [*] Auxiliary module execution completed msf auxiliary(smb_version) >
Contrariamente a muchos otros casos, un escaneo con credenciales en este caso no necesariamente proporciona mejores resultados. Si las credenciales no son validas en un sistema en particular, no obtendras ningun resultado del escaneo.
© Offensive Security 2009
Original de www.offensive-security.com Traducido por cbk999