Null Sessions

Checking if Null Session is enabled on the network, can be very useful on a Domain Controller to enumerate users, groups, password policy etc

#~ cme smb 10.10.10.161 -u '' -p ''
#~ cme smb 10.10.10.161 --pass-pol
#~ cme smb 10.10.10.161 --users
#~ cme smb 10.10.10.161 --groups

You can also reproduce this behavior with smbclient or rpcclient

Example

Forest or Monteverde machines are good examples to test null session authentication with CrackMapExec

Last updated