SMB Security Assessment: Testing Share Permissions and Access Controls
Guide to assessing SMB security including anonymous access testing, share permission analysis, credential attacks, and hardening recommendations for Windows file shares.
Finding Weakness Before Attackers Do
SMB security assessment evaluates the configuration and access controls of Server Message Block file sharing services on Windows and Samba systems. The goal is to identify misconfigured shares, weak authentication, anonymous access vulnerabilities, and excessive permissions before attackers can exploit them.
Common SMB issues — anonymous read/write access, default credentials on administrative shares, weak password policies, outdated SMBv1, and missing SMB signing — are among the most frequently exploited misconfigurations in real-world attacks. Knowing how to find and fix them is a core skill for any security professional.
Prerequisites
Assessment Methodology
Phase 1: Discovery and Enumeration
# Discover SMB-enabled hosts
nmap -p 139,445 192.168.1.0/24 -oG smb_hosts.txt
# Enumerate shares on each host
enum4linux -S 192.168.1.10
# Full enumeration
enum4linux -a 192.168.1.10 > enum_output.txt
Phase 2: Anonymous Access Testing
The most critical test — can anyone access shares without credentials?
# Test anonymous share listing
smbclient -L //192.168.1.10 -N
# Test anonymous connection to each discovered share
smbclient //192.168.1.10/public -N
# Try accessing common share names
smbclient //192.168.1.10/backup -N
smbclient //192.168.1.10/data -N
smbclient //192.168.1.10/users -N
If anonymous access succeeds, document which shares are accessible and whether files can be listed, downloaded, or uploaded.
Phase 3: Credential Testing
Test common and default credentials:
# Test default credentials
enum4linux -a -u administrator -p "" 192.168.1.10
enum4linux -a -u admin -p admin 192.168.1.10
enum4linux -a -u guest -p "" 192.168.1.10
# Brute-force with Hydra
hydra -l admin -P /usr/share/wordlists/rockyou.txt smb://192.168.1.10
# Large-scale credential testing
crackmapexec smb 192.168.1.0/24 -u users.txt -p passwords.txt --continue-on-success
Phase 4: Share Permission Analysis
For each accessible share, analyze permissions:
# Connect and enumerate permissions
smbclient //192.168.1.10/share -U user%pass -c 'ls'
# Check write permissions
echo "test" > test.txt
smbclient //192.168.1.10/share -U user%pass -c 'put test.txt'
# Enumerate share properties
enum4linux -l 192.168.1.10
Check for: read access to sensitive data, write access for file staging, administrative share access (C$, ADMIN$), and IPC share null session access.
Phase 5: SMB Version and Configuration Analysis
# Check SMB version
nmap -p 445 --script smb-os-discovery 192.168.1.10
# Test for SMBv1 (insecure)
nmap -p 445 --script smb-vuln-ms17-010 192.168.1.10
# Check SMB signing
nmap -p 445 --script smb-security-mode 192.168.1.10
SMBv1 is deprecated and vulnerable to EternalBlue (MS17-010) and other attacks. SMB signing should be required to prevent relay attacks.
Phase 6: Data Exposure Assessment
# Download sample files to assess sensitivity
smbclient //192.168.1.10/share -U user%pass -c 'get document.xlsx'
# Search for sensitive file types
smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *.docx; mget *'
smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *.pdf; mget *'
smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *.kdbx; mget *'
# Check for password files
smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *password*; mget *'
Security Findings Checklist
| Finding | Severity | Description |
|---------|----------|-------------|
| Anonymous read access | High | Share accessible without credentials |
| Anonymous write access | Critical | Files can be uploaded without authentication |
| Default credentials | Critical | Default admin/guest passwords unchanged |
| SMBv1 enabled | High | Vulnerable to EternalBlue and downgrade attacks |
| SMB signing disabled | Medium | Susceptible to NTLM relay attacks |
| Weak password policy | Medium | Short passwords, no complexity requirements |
| Guest account enabled | Medium | May allow unauthorized access |
| Excessive share permissions | High | All users have write access to sensitive shares |
Hardening Recommendations
Related Tools
Related Articles
Learning Roadmap
Summary
SMB security assessment systematically tests file sharing configurations for misconfigurations and vulnerabilities. By testing anonymous access, enumerating shares, analyzing permissions, and verifying SMB versions, you identify security gaps that could lead to data exposure or unauthorized access. Always document findings with severity ratings and provide actionable hardening recommendations.