Metasploit mailing list archives

Re: problems using SMB_enumshares on Windows 2008R2?


From: HD Moore <hdm () metasploit com>
Date: Tue, 07 Feb 2012 20:05:46 -0500

On 2/2/2012 10:46 AM, Mee, John H wrote:
I cannot get a list of known shares on a Windows 2008R2 Datacenter
edition. I get messages indicating that it successfully scanned the
server (this is test server in my lab), and I can get to a known share
via "net use" and nMap shows it is alive and well, but likewise, it does
not return any shares.

Based on the .pcap files, it appears that smb_enumshares uses lanman and
2008R2 uses smb2 queries.

Are there any alternatives, fixes, etc. that will get around this
problem? Unfortunately, I am not conversant in ruby and the network
protocol to be able to fix this myself...

By default windows 2008 will use SMB2, but its not mandatory. Can you
look at a pcap of the metasploit module?
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: