Enumerate NTLMv1
You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account
Enumerate the LmCompatibilityLevel on the remote target via the remote registry:
nxc smb <ip> -u user -p password -M ntlmv1
SMB <ip> 445 <FQDN> [*] Windows 10 / Server 2019 Build 17763 x64 (name:<FQDN>) (domain:<FQDN>) (signing:False) (SMBv1:None)
SMB <ip> 445 <FQDN> [+] <FQDN>\user:password (Pwn3d!)
NTLMV1 <ip> 445 <FQDN> NTLMv1 allowed on: <ip> - LmCompatibilityLevel = 2Outgoing NTLMv1 connections are enabled when the target’s LmCompatibilityLevel is lower than 3.
Last updated
Was this helpful?

