Metasploit mailing list archives

Re: problems using SMB_enumshares on Windows 2008R2?


From: Konrads Smelkovs <konrads.smelkovs () gmail com>
Date: Sun, 26 Feb 2012 15:37:19 +0000

I've had a look and that's exactly what's happening LM queries are refused
by server.

--
Konrads Smelkovs
Applied IT sorcery.



On Wed, Feb 8, 2012 at 1:05 AM, HD Moore <hdm () metasploit com> wrote:

On 2/2/2012 10:46 AM, Mee, John H wrote:
I cannot get a list of known shares on a Windows 2008R2 Datacenter
edition. I get messages indicating that it successfully scanned the
server (this is test server in my lab), and I can get to a known share
via "net use" and nMap shows it is alive and well, but likewise, it does
not return any shares.

Based on the .pcap files, it appears that smb_enumshares uses lanman and
2008R2 uses smb2 queries.

Are there any alternatives, fixes, etc. that will get around this
problem? Unfortunately, I am not conversant in ruby and the network
protocol to be able to fix this myself...

By default windows 2008 will use SMB2, but its not mandatory. Can you
look at a pcap of the metasploit module?
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: