SMB Enumeration Techniques using Backtrack:
- NBTSCAN
root@bt:~# nbtscan -r 10.0.2.0/24 Doing NBT name scan for addresses from 10.0.2.0/24
IP address NetBIOS Name Server User MAC address
10.0.2.0 Sendto failed: Permission denied
10.0.2.10
10.0.2.15 METASPLOITABLE
- NMAP
nmap -p 1-65535 -T4 -O -A -v 10.0.2.15
- SMBCLIENT
root@bt:~# smbclient -L=10.0.2.15
Null Sessions
root@bt:~# smbclient \\10.0.2.15\tmp Enter root's password: Anonymous login successful
SMB Enumeration Techniques using Windows Tools:
- NetBIOS Enumerator (nbtenum)
http://nbtenum.sourceforge.net/