Skip to content

5000+ Great Articles

Best Articles & Essays: Interesting Articles to Read Online

  • How To Create Your Own Personal Stickers On WhatsApp (Android) How-To
  • How to Play Among Us on Your Mac Tutorials
  • 15 Games to Play over text with friends technology
  • Top 5 Methods To Fix an iPad Stuck on Apple Logo iPad
  • Top 5 Ways to Extract APK File of Any App on Your Android Phone How-To
  • 7 things to keep in mind when comparing new ISPs Computer Tips
  • How To Manage Your Zoom Recordings History How-To
  • IE 11 Not Remembering Passwords?

    The other day I ran into a nasty problem where Internet Explorer did not remember the password when I entered the site. I don't really remember when

Using Wireshark to Sniff an SMB transmission

Posted on October 9, 2020 By bilal 1983 No Comments on Using Wireshark to Sniff an SMB transmission

Ever wonder what happens under the hood when you connect to a Windows share? There is one easy way to find out. Use a packet sniffer like Wireshark.

What is Wireshark?

Wireshark is an easy-to-install and easy-to-use packet capture tool that is supported on both Windows and Linux. On Windows, Wireshark uses the Windows Pcap module as its primary mechanism for capturing packets. Wireshark sits on top of Pcap to provide an easy-to-use interface and packet filter.

Using Wireshark to Sniff an SMB transmission

The easiest way to monitor packets between two machines is to simply install Wireshark on one of the two machines and then configure a filter to view traffic. In this example, we will monitor traffic between a Windows 10 client computer and a Windows 2012 server.

Create a file share

First, we’ll set up a share on a Windows 2012 machine. On a Windows 2012 machine, create a new folder and name it “Share.” Right click and select Properties. Go to the Sharing tab and select Share. Allow a user with administrative rights to access the share with read and write access. In this case, the administrator is already the owner of the shared folder.

Using Wireshark to Sniff an SMB transmission

Confirm that your share is listening with the net share command.

Using Wireshark to Sniff an SMB transmission

Client setting

Then, on a Windows 10 machine, we will connect to our newly created network share using the command line.

Using Wireshark to Sniff an SMB transmission

After confirming the connection to the share, it’s time to see what happens. Let’s install Wireshark on a Windows 10 computer. Wireshark is available for download from www.wireshark.org In this example, we will use Wireshark-win64-2.6.6.exe. Just click Next and select all the defaults in the setup wizard.

When launching Wireshark, the first step is always to launch the capture on the designated interface. From the Wireshark menu go to Capture | Parameters. Select the desired listening interface and start capturing. In this case, we only have one network adapter to choose from.

Using Wireshark to Sniff an SMB transmission

After listening, you will see all traffic on the interface.

Using Wireshark to Sniff an SMB transmission

Traffic Filter

In order to see only the traffic participating in the SMB exchange, we need to configure some filters. If you don’t know all the filtering commands, Wireshark has a user-friendly graphical interface that you can use to customize your filters. In the top bar next to the search bar, select Expression. The “Wireshark – Display Filter Expression” window opens.

Using Wireshark to Sniff an SMB transmission

In this window, navigate through the protocol to find the appropriate filter. In this case, the simplest introductory filter for narrowing our traffic is restricting traffic by IPv4 address.

We will go to the IPv4 address and set ip.addr == 192.168.31.201, which is the IP address of the SMB share. The same command can simply be entered directly into the search bar if you are a more experienced Wireshark user. Traffic is now only limited to traffic between our client and the Windows 2012 server.

Let’s see if we can get more information from this capture. Let’s delete the share first. On Windows 10, run Command Prompt as administrator and type net use \ 192.168.31.201 share delete. Below is an example of a TCP stream during deletion. This time, a little more information is provided in the open.

Using Wireshark to Sniff an SMB transmission

Then we will restart the entire connection from the beginning to make sure our credentials are protected. First, confirm that the session is not established by running netstat and filtering out any ESTABLISHED sessions. Then reconnect to the share with explicit credentials and then follow TCP flow.

Using Wireshark to Sniff an SMB transmission

Hooray! No passwords in clear text. However, I can see the username. It might be time to move to SMBv3.

Using Wireshark to Sniff an SMB transmission

This simple example demonstrates how to use Wireshark to monitor network connections. Wireshark can be used to listen for all network traffic to troubleshoot connectivity issues, or to determine if there is clear text in a packet exchange, which should be further protected. Wireshark is another tool that can be added to your security arsenal. Happy sniffing!

Share this:

  • Facebook
  • X
How-To Tags:Client setting, Create a file share, Traffic Filter, Using Wireshark to Sniff an SMB transmission, What is Wireshark?

Post navigation

Previous Post: Enable Encryption for Microsoft SQL Server Connections
Next Post: How to Configure IPSec on Windows

Related Posts

  • how to change keyboard language in windows How-To
  • The Best Way to Download YouTube Videos on Android How-To
  • 3 Sites like YouTube to Earn Money With Your Videos How-To
  • How To See Cached Pages And Files From Your Browser How-To
  • How to translate Word documents into multiple languages How-To
  • How to Use YouTube Music Collaborate Playlist Feature How-To

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • November 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • March 2021
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • December 2019
  • July 2019
  • May 2019
  • April 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018

Categories

  • – 436
  • – 939
  • 1xbet Azerbaycan,1xbet az merc saytı, en yaxsi bukmeker 1xbet Azerbaycan merc oyunlari, 1xbet az, Azerbaycan merc saytlari – 280
  • AI Tools & Guides
  • Amazon Web Services
  • Apple Watch
  • Calculator
  • Computer Tips
  • Cool Websites
  • Dasinmaz emlak elanlari, ev elanlari, ev alqi satqisi, kiraye evler, torpaq, obyekt, bina, bina ev, mənzil, villa, kreditle satilan evler – 814
  • Featured Posts
  • Free Software Downloads
  • Gadgets
  • Gaming
  • General Software
  • Google Software/Tips
  • Hardware
  • Help Desk
  • How-To
  • iOS
  • iPad
  • iPhone
  • islamic Books
  • Linux
  • Linux Tips
  • Mac OS X
  • macOS
  • MS Office Tips
  • Networking
  • Office Tips
  • OS X
  • Product Reviews
  • Reviews
  • Safari
  • Smart Home
  • Smartphones
  • Software Reviews
  • technology
  • text
  • Tools Review
  • Troubleshooting
  • Tutorial
  • Tutorials
  • Uncategorized
  • Urdu Books PDF
  • Web Site Tips
  • Windows
  • Windows 10
  • Windows 7
  • Windows XP Tips
  • Wordpress
  • бонусы до 250%, официальный сайт в Узбекистане – 69
  • Мостбет Уз Ставки на спорт и казино в букмекерской конторе Mostbet Uz – 527
  • How To Change IP Address in Windows
  • Приложение Mostbet UZ скачать на Андроид APK, Айфон IOS
  • Приложение Mostbet UZ скачать на Андроид APK, Айфон IOS
  • How To Backup Your Android Phone And Tablet (No Root)
  • 6 Useful Tips to Free Up Space on Your Android Device
DMCA.com Protection Status

Recent Posts

  • MostBet AZ Most Bet Casino Qeydiyyat, Yukle Android App
  • Xarici bukmeykerlər azərbaycanlıların pulunu necə oğurlayır? Birinci yazı
  • Sağlamlığın real məkanı
  • Dünyada müasir tendensiya kimi qumar oyunlarının leqallaşdırılması
  • How do I Find Release Date of Any Google Play App

Recent Comments

  1. Instagram stories not working/loading? Try These 9 Fixes on Can’t update PS5 system software? Try These 10 Fixes
  2. How to Link to a Specific Part Of A Webpage & Share it on Best PDF to Word Converter Online (Free Without Email)
  3. See What’s Taking up Space on Your Hard Drive on 7 best 3D scanning apps for Android and iOS
  4. Make your Devices Read Out Text, With Text to Speech on 9 Best 10K Running Apps for 2023
  5. How to Find your Router’s IP Address on How to Fix Apple CarPlay Not Working? 7 Possible ways
  • 5 Ways iPhone/Android Can Cast Screen to TV Without Chromecast How-To
  • 11 Best useful Ways to Fix Gmail Notifications Not Working in Chrome Google Software/Tips
  • How To Move Your Dropbox Folder Computer Tips
  • How to Delete All Your Comments on YouTube How-To
  • In 2021 Best Android Video Player Mobile Applications Smartphones
  • Fix Scheduled Task Won’t Run for .BAT File Help Desk
  • How to Change the Boot Sequence in the BIOS How-To
  • 4 Early Access Games in 2020 for Android Worth Checking Out Smartphones

Copyright © 2023 How To Blog.

Powered by PressBook News WordPress theme

Go to mobile version