139/445 ~ SMB
https://docs.google.com/document/d/15MpM-hypaArwGk7B1n1decet3ZEylSYCSzIkDd_b1PQ/edit?tab=t.0
Key differences between ports 139 and 445:
Port 139: Legacy, relies on NetBIOS over TCP/IP, primarily used for older systems and version of SMB, such as SMB 1.0 or older versions.
Port 445: Used in modern systems. It supports direct SMB over TCP/IP, used by newer versions of SMB (e.g. SMBv2, SMBv3).
$ sudo nmap -sS -n -v <host>
PORT STATE SERVICE
...
139/tcp open netbios-ssn
445/tcp open microsoft-ds
...Metasploit
msf6 > search type:auxiliary smb
msf6 > search type:auxiliary smb scannerauxiliary/scanner/smb/smb_enumsharesauxiliary/scanner/smb/smb_enumusersauxiliary/scanner/smb/smb_versionauxiliary/scanner/smb/smb_ms17_010
Example
Module: scanner/smb/smb_login, targets port 445
Password brute-force on port 445 for a single username.
TryHackMe Metasploit exploitation room, Task 2:
Last updated