<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_SMB</id>
	<title>Draft:Introduction to SMB - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_SMB"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_SMB&amp;action=history"/>
	<updated>2026-09-24T04:43:38Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_SMB&amp;diff=178&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_SMB&amp;diff=178&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:49Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l109&quot;&gt;Line 109:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 109:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows SMB|015]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows SMB|015]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-98:rev-178:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_SMB&amp;diff=98&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/windows/app_sec/smb/intro_smb.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_SMB&amp;diff=98&amp;oldid=prev"/>
		<updated>2026-09-18T17:06:32Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/windows/app_sec/smb/intro_smb.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/windows/app_sec/smb/intro_smb (source: docs/windows/app_sec/smb/intro_smb.md) --&amp;gt;&lt;br /&gt;
Author(s): a_person&lt;br /&gt;
&lt;br /&gt;
Last Updated: 07-23-2025&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Recommended Prerequisites (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
* Basic knowledge of Windows &amp;lt;br /&amp;gt;&lt;br /&gt;
* Basic knowledge of Networking&lt;br /&gt;
* Basic knowledge of the Registry&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What is it? ==&lt;br /&gt;
&lt;br /&gt;
Server Message Block (SMB) is a communication protocol used to share files, printers, serial ports, and miscellaneous communications between nodes on a network. On Microsoft Windows, the SMB implementation consists of two Windows services: &amp;lt;code&amp;gt;Server&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;Workstation&amp;lt;/code&amp;gt; (full service names are LanmanServer and LanmanWorkstation). Their full service names also are their names in their respective registry path. It uses NTLM or Kerberos protocols for user authentication. It also provides an authenticated inter-process communication (IPC) mechanism.&lt;br /&gt;
&lt;br /&gt;
=== Why and Where is SMB Used? ===&lt;br /&gt;
&lt;br /&gt;
The main purpose of SMB is to help computers on a network share resources easily. This connection between a client machine and a server&amp;#039;s resources makes it an important protocol in almost every Windows-based environment.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Corporate File Sharing:&amp;#039;&amp;#039;&amp;#039; Accessing a shared network drive on a company file server to open, edit, and save documents.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Domain Administration:&amp;#039;&amp;#039;&amp;#039; When a computer logs into a Windows domain, it uses SMB to connect to the Domain Controller’s &amp;lt;code&amp;gt;SYSVOL&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;NETLOGON&amp;lt;/code&amp;gt; shares to download important login scripts and Group Policy security settings.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Shared Network Printing:&amp;#039;&amp;#039;&amp;#039; Sending a print job from your computer to a central printer that is shared across the office network.&lt;br /&gt;
&lt;br /&gt;
== How does it work? ==&lt;br /&gt;
&lt;br /&gt;
* The client sends an SMB request to the server to initiate the connection.&lt;br /&gt;
* When the server receives the request, it sends an SMB response back to the client, establishing the communication channel necessary for a two-way conversation.&lt;br /&gt;
* Once it is granted access, the client can access the required resource for reading, writing, executing and so on.&lt;br /&gt;
&lt;br /&gt;
Since the network server has a resource that it shares with one or more clients, the protocol is also known as a server-client protocol. The SMB protocol operates on the application layer of the TCP/IP model, but relies on lower network levels for transport. When SMB was using NBT, it relied on ports 137, 138 and 139 for transport. Now, SMB runs directly over TCP/IP and uses port 445. Port 445 supports data encryption and digital signing of SMB packets, providing a more secure means of communication than port 139.&lt;br /&gt;
&lt;br /&gt;
== Important Files and Locations ==&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares&amp;lt;/code&amp;gt; - Stores the definitions and paths of all SMB shares on the system.&lt;br /&gt;
* &amp;lt;code&amp;gt;HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters&amp;lt;/code&amp;gt; - Controls SMB server settings.&lt;br /&gt;
* &amp;lt;code&amp;gt;HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters&amp;lt;/code&amp;gt; - Controls SMB client settings.&lt;br /&gt;
* &amp;lt;code&amp;gt;C:\Windows\System32\srvsvc.dll&amp;lt;/code&amp;gt; - Core DLL for the SMB server service.&lt;br /&gt;
* &amp;lt;code&amp;gt;C:\Windows\System32\srv.sys&amp;lt;/code&amp;gt; - Kernel driver for SMB server functionality.&lt;br /&gt;
* &amp;lt;code&amp;gt;%SystemRoot%\System32\config&amp;lt;/code&amp;gt; - Location of system registry hives, including those that store SMB configuration.&lt;br /&gt;
* &amp;lt;code&amp;gt;%UserProfile%\NTUSER.DAT&amp;lt;/code&amp;gt; - Contains user-specific registry settings, including recent SMB connections and mount points.&lt;br /&gt;
* &amp;lt;code&amp;gt;UNC Paths (\Server\Share)&amp;lt;/code&amp;gt; - Standard syntax for accessing SMB shares in Windows Explorer or via command line.&lt;br /&gt;
* &amp;lt;code&amp;gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices]&amp;lt;/code&amp;gt; - Maps network drives for all users by assigning a drive letter to a UNC path.&lt;br /&gt;
* &amp;lt;code&amp;gt;Administrative shares (C$, ADMIN$, IPC$)&amp;lt;/code&amp;gt; - Hidden default shares for administrative access, automatically created by Windows.&lt;br /&gt;
&lt;br /&gt;
== SMB Versions ==&lt;br /&gt;
&lt;br /&gt;
=== SMB 1.x ===&lt;br /&gt;
&lt;br /&gt;
* Designed in early 1980s by IBM; extended by Microsoft around 1990.&lt;br /&gt;
* Sends a lot of messages, causing performance issues on high-latency networks.&lt;br /&gt;
* Uses weak authentication (LAN Manager passwords, flawed DES).&lt;br /&gt;
* No native encryption; limited signing capabilities.&lt;br /&gt;
&lt;br /&gt;
=== SMB 2.x (SMB 2.0 and 2.1) ===&lt;br /&gt;
&lt;br /&gt;
* Introduced in 2006 with Windows Vista and Server 2008.&lt;br /&gt;
* Reduced messages sent with fewer commands and pipelining.&lt;br /&gt;
* Improved security with better signing (HMAC SHA-256).&lt;br /&gt;
* Improved performance and scalability.&lt;br /&gt;
&lt;br /&gt;
=== SMB 3.x (3.0, 3.0.2, 3.1.1 and later) ===&lt;br /&gt;
&lt;br /&gt;
* Introduced with Windows 8 / Server 2012.&lt;br /&gt;
* Major features for virtualization and datacenters&lt;br /&gt;
* Native &amp;#039;&amp;#039;&amp;#039;encryption&amp;#039;&amp;#039;&amp;#039; support:&lt;br /&gt;
** SMB 3.0: AES-128 CCM encryption.&lt;br /&gt;
** SMB 3.1.1 (Windows 10 / Server 2016): AES-128 GCM encryption and pre-authentication integrity (SHA-512).&lt;br /&gt;
* Mandatory secure negotiation on SMB 3.1.1.&lt;br /&gt;
* SMB 1 disabled by default starting Windows Server 2012 R2.&lt;br /&gt;
&lt;br /&gt;
You can read more [https://en.wikipedia.org/wiki/Server_Message_Block#History here]&lt;br /&gt;
&lt;br /&gt;
== Security ==&lt;br /&gt;
&lt;br /&gt;
Some important security settings should be enforced, such as:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Disable SMB 1.0&amp;#039;&amp;#039;&amp;#039; - Older versions of SMB are less secure. Disable more if it does not harm compatibility.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Strong Authentication&amp;#039;&amp;#039;&amp;#039; - Use Kerberos when possible.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Principle of Least Privilege&amp;#039;&amp;#039;&amp;#039; - Grant users only the necessary permissions.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Siging and Encrpytion&amp;#039;&amp;#039;&amp;#039; - Use AES-128-GCM and enable SMB Signing on both clients and servers.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Auditing&amp;#039;&amp;#039;&amp;#039; - Obviously&lt;br /&gt;
&lt;br /&gt;
== References &amp;amp;amp; Further Reading ==&lt;br /&gt;
&lt;br /&gt;
* https://en.wikipedia.org/wiki/Server_Message_Block&lt;br /&gt;
* https://www.techtarget.com/searchnetworking/definition/Server-Message-Block-Protocol&lt;br /&gt;
* https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview&lt;br /&gt;
* https://learn.microsoft.com/en-us/previous-versions/windows/desktop/mscs/file-share&lt;br /&gt;
&lt;br /&gt;
== Practice ==&lt;br /&gt;
&lt;br /&gt;
DPRK(3 vulns), Mushroom Kingdom(3 vulns), PPTH(3 vulns), and Among the Reindeer(2 vulns) are some images with SMB. https://images.cypat.guide#gid=0&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
== Vulnerability Research ==&lt;br /&gt;
&lt;br /&gt;
* https://stigviewer.com/stigs/microsoft_windows_server_2022&lt;br /&gt;
* https://workbench.cisecurity.org/benchmarks/21344&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows SMB|015]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>