GO KALI FREE
IntermediateGuides

SMB Security Assessment: Testing Share Permissions and Access Controls

Guide to assessing SMB security including anonymous access testing, share permission analysis, credential attacks, and hardening recommendations for Windows file shares.

#smb#security assessment#share permissions#anonymous access#penetration testing#hardening

Finding Weakness Before Attackers Do

SMB security assessment evaluates the configuration and access controls of Server Message Block file sharing services on Windows and Samba systems. The goal is to identify misconfigured shares, weak authentication, anonymous access vulnerabilities, and excessive permissions before attackers can exploit them.

Common SMB issues — anonymous read/write access, default credentials on administrative shares, weak password policies, outdated SMBv1, and missing SMB signing — are among the most frequently exploited misconfigurations in real-world attacks. Knowing how to find and fix them is a core skill for any security professional.

Prerequisites

  • Kali Linux with SMB enumeration tools installed
  • Understanding of Windows file sharing and permissions
  • Network access to the target SMB services
  • Explicit written authorization for the assessment
  • Assessment Methodology

    Phase 1: Discovery and Enumeration

    # Discover SMB-enabled hosts
    nmap -p 139,445 192.168.1.0/24 -oG smb_hosts.txt
    
    # Enumerate shares on each host
    enum4linux -S 192.168.1.10
    
    # Full enumeration
    enum4linux -a 192.168.1.10 > enum_output.txt
    

    Phase 2: Anonymous Access Testing

    The most critical test — can anyone access shares without credentials?

    # Test anonymous share listing
    smbclient -L //192.168.1.10 -N
    
    # Test anonymous connection to each discovered share
    smbclient //192.168.1.10/public -N
    
    # Try accessing common share names
    smbclient //192.168.1.10/backup -N
    smbclient //192.168.1.10/data -N
    smbclient //192.168.1.10/users -N
    

    If anonymous access succeeds, document which shares are accessible and whether files can be listed, downloaded, or uploaded.

    Phase 3: Credential Testing

    Test common and default credentials:

    # Test default credentials
    enum4linux -a -u administrator -p "" 192.168.1.10
    enum4linux -a -u admin -p admin 192.168.1.10
    enum4linux -a -u guest -p "" 192.168.1.10
    
    # Brute-force with Hydra
    hydra -l admin -P /usr/share/wordlists/rockyou.txt smb://192.168.1.10
    
    # Large-scale credential testing
    crackmapexec smb 192.168.1.0/24 -u users.txt -p passwords.txt --continue-on-success
    

    Phase 4: Share Permission Analysis

    For each accessible share, analyze permissions:

    # Connect and enumerate permissions
    smbclient //192.168.1.10/share -U user%pass -c 'ls'
    
    # Check write permissions
    echo "test" > test.txt
    smbclient //192.168.1.10/share -U user%pass -c 'put test.txt'
    
    # Enumerate share properties
    enum4linux -l 192.168.1.10
    

    Check for: read access to sensitive data, write access for file staging, administrative share access (C$, ADMIN$), and IPC share null session access.

    Phase 5: SMB Version and Configuration Analysis

    # Check SMB version
    nmap -p 445 --script smb-os-discovery 192.168.1.10
    
    # Test for SMBv1 (insecure)
    nmap -p 445 --script smb-vuln-ms17-010 192.168.1.10
    
    # Check SMB signing
    nmap -p 445 --script smb-security-mode 192.168.1.10
    

    SMBv1 is deprecated and vulnerable to EternalBlue (MS17-010) and other attacks. SMB signing should be required to prevent relay attacks.

    Phase 6: Data Exposure Assessment

    # Download sample files to assess sensitivity
    smbclient //192.168.1.10/share -U user%pass -c 'get document.xlsx'
    
    # Search for sensitive file types
    smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *.docx; mget *'
    smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *.pdf; mget *'
    smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *.kdbx; mget *'
    
    # Check for password files
    smbclient //192.168.1.10/share -U user%pass -c 'recurse on; mask *password*; mget *'
    

    Security Findings Checklist

    | Finding | Severity | Description |

    |---------|----------|-------------|

    | Anonymous read access | High | Share accessible without credentials |

    | Anonymous write access | Critical | Files can be uploaded without authentication |

    | Default credentials | Critical | Default admin/guest passwords unchanged |

    | SMBv1 enabled | High | Vulnerable to EternalBlue and downgrade attacks |

    | SMB signing disabled | Medium | Susceptible to NTLM relay attacks |

    | Weak password policy | Medium | Short passwords, no complexity requirements |

    | Guest account enabled | Medium | May allow unauthorized access |

    | Excessive share permissions | High | All users have write access to sensitive shares |

    Hardening Recommendations

  • Disable anonymous access on all non-public shares
  • Remove SMBv1 support and require SMB2/SMB3
  • Enable SMB signing and encryption
  • Implement strong password policies with lockout
  • Use least-privilege access controls on all shares
  • Audit share permissions quarterly
  • Enable audit logging for SMB access
  • Segment file shares from general network access
  • Related Tools

  • [Enum4Linux](/tools/enum4linux) — SMB enumeration and discovery
  • [SMBClient](/tools/smbclient) — Share access testing
  • [CrackMapExec](/tools/crackmapexec) — Large-scale credential testing
  • [Hydra](/tools/hydra) — Password brute-force attacks
  • [Nmap](/tools/nmap) — Port scanning and SMB version detection
  • [NetExec](/tools/netexec) — Modern post-exploitation toolkit
  • Related Articles

  • [SMB Enumeration Complete Guide](/learn/smb-enumeration-complete-guide) — Beginner to advanced SMB workflow
  • [SMB Enumeration Guide](/learn/smb-enumeration-guide) — SMB discovery techniques
  • [Windows Reconnaissance Basics](/learn/windows-reconnaissance-basics) — Windows network fundamentals
  • [Active Directory Fundamentals](/learn/active-directory-fundamentals) — AD security assessment
  • Learning Roadmap

  • Learn [Nmap](/tools/nmap) for SMB port discovery
  • Master [Enum4Linux](/tools/enum4linux) for share enumeration
  • Practice with [SMBClient](/tools/smbclient) for share access testing
  • Scale with [CrackMapExec](/tools/crackmapexec) for network-wide assessment
  • Test credentials with [Hydra](/tools/hydra) for brute-force attacks
  • Summary

    SMB security assessment systematically tests file sharing configurations for misconfigurations and vulnerabilities. By testing anonymous access, enumerating shares, analyzing permissions, and verifying SMB versions, you identify security gaps that could lead to data exposure or unauthorized access. Always document findings with severity ratings and provide actionable hardening recommendations.

    Related SMB Tool Recommendations

  • [SMBClient](/tools/smbclient) — Verify share access and browse discovered SMB shares
  • [Enum4Linux](/tools/enum4linux) — Enumerate SMB users, groups, shares, and policies
  • [Enum4Linux-NG](/tools/enum4linux-ng) — Run modern SMB enumeration with structured output
  • [NBTScan](/tools/nbtscan) — Resolve NetBIOS names before deeper SMB testing
  • [CrackMapExec](/tools/crackmapexec) — Scale SMB enumeration across larger networks
  • [NetExec](/tools/netexec) — Use modern SMB and Active Directory automation
  • Knowledge Check

  • Why is anonymous SMB access a critical security finding?
  • What makes SMBv1 dangerous compared to SMB2/3?
  • How does SMB signing prevent NTLM relay attacks?
  • What file extensions should you search for during data exposure assessment?
  • What is the first step in hardening SMB configuration?
  • Frequently Asked Questions

    What is SMB security assessment?

    SMB security assessment evaluates Server Message Block file sharing configurations for misconfigurations including anonymous access, weak credentials, outdated SMB versions, and excessive permissions that could allow unauthorized data access or lateral movement.

    Why is anonymous SMB access a critical security finding?

    Anonymous SMB access allows unauthenticated users to list, read, or write to file shares. This can expose sensitive data, enable file staging for attacks, and provide a direct path for lateral movement without any credentials.

    What makes SMBv1 dangerous compared to SMB2/3?

    SMBv1 is deprecated and vulnerable to EternalBlue (MS17-010), which enabled the WannaCry ransomware worm. It lacks encryption, has weaker integrity protections, and supports downgrade attacks that force connections to use the insecure protocol.

    How does SMB signing prevent NTLM relay attacks?

    SMB signing adds a cryptographic signature to each SMB message, verifying that it has not been tampered with in transit. Without signing, attackers can relay captured NTLM authentication to other services, impersonating legitimate users.

    What file extensions should you search for during data exposure assessment?

    Search for .docx, .xlsx, .pdf, .kdbx (KeePass), .pem, .key, and files containing 'password' in the name. These often contain sensitive data, credentials, or private keys that represent high-impact exposure.

    How do you test for anonymous SMB access?

    Use `smbclient -L //target -N` to list shares without credentials, then attempt `smbclient //target/sharename -N` to connect to each discovered share. If anonymous connection succeeds, document which shares are accessible and whether files can be listed, downloaded, or uploaded.

    What tools are used for SMB security assessment?

    Key tools include Enum4Linux for enumeration, SMBClient for share access testing, CrackMapExec for large-scale credential testing, Hydra for brute-force attacks, and Nmap for SMB version detection and vulnerability scanning.

    How do you check if SMB signing is enabled on a target?

    Run `nmap -p 445 --script smb-security-mode target` to check SMB signing status. You can also use CrackMapExec with the `--gen-relay-list` option to identify hosts with signing disabled that are vulnerable to relay attacks.

    What are the most common SMB security findings?

    The most common findings include anonymous read/write access, default credentials on admin shares, SMBv1 enabled, SMB signing disabled, weak password policies, guest account enabled, and excessive share permissions giving broad groups write access to sensitive data.

    How do you harden SMB configuration after an assessment?

    Disable anonymous access on non-public shares, remove SMBv1 support, enable SMB signing and encryption, implement strong password policies with lockout, use least-privilege access controls, audit share permissions quarterly, and enable audit logging for SMB access.