Fetchfile found /usr/local/bin/../share/nmap/nmap-services Fetchfile found /usr/local/bin/../share/nmap/nmap.xsl # Nmap 7.01 scan initiated Thu Feb 18 10:25:43 2016 as: nmap -Pn --script smb* and not(dos or brute) -oA /Users/calderpwn/Code/calderon/smb2/win2003-trace --packet-trace -d3 -p139,445 192.168.0.22 --------------- Timing report --------------- hostgroups: min 1, max 100000 rtt-timeouts: init 1000, min 100, max 10000 max-scan-delay: TCP 1000, UDP 1000, SCTP 1000 parallelism: min 0, max 0 max-retries: 10, host-timeout: 0 min-rate: 0, max-rate: 0 --------------------------------------------- Fetchfile found /usr/local/bin/../share/nmap/nse_main.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/lpeg-utility.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/stdnse.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/strict.lua Fetchfile found /usr/local/bin/../share/nmap/scripts/script.db Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-enum-domains.nse Fetchfile found /usr/local/bin/../share/nmap/nselib/msrpc.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/msrpctypes.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/unicode.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/unittest.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/nsedebug.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/listop.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/netbios.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/dns.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/ipOps.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/base32.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/smb.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/asn1.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/match.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/smbauth.lua Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-enum-groups.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-enum-processes.nse Fetchfile found /usr/local/bin/../share/nmap/nselib/msrpcperformance.lua Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-enum-sessions.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-enum-shares.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-enum-users.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-ls.nse Fetchfile found /usr/local/bin/../share/nmap/nselib/ls.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/tab.lua Fetchfile found /usr/local/bin/../share/nmap/nselib/strbuf.lua Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-mbenum.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-os-discovery.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-print-text.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-psexec.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-security-mode.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-server-stats.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-system-info.nse Fetchfile found /usr/local/bin/../share/nmap/scripts/smb-vuln-ms10-061.nse Fetchfile found /usr/local/bin/../share/nmap/nselib/vulns.lua Fetchfile found /usr/local/bin/../share/nmap/scripts/smbv2-enabled.nse Fetchfile found /usr/local/bin/../share/nmap/nmap-payloads CONN (0.3760s) TCP localhost > 192.168.0.22:139 => Operation now in progress CONN (0.3761s) TCP localhost > 192.168.0.22:445 => Operation now in progress **TIMING STATS** (0.3761s): IP, probes active/freshportsleft/retry_stack/outstanding/retranwait/onbench, cwnd/ssthresh/delay, timeout/srtt/rttvar/ Groupstats (1/1 incomplete): 2/*/*/*/*/* 10.00/75/* 1000000/-1/-1 Current sending rates: 9090.91 packets / s. Overall sending rates: 9090.91 packets / s. CONN (0.3763s) TCP localhost > 192.168.0.22:139 => Connected Changing ping technique for 192.168.0.22 to connect to port 139 CONN (0.3763s) TCP localhost > 192.168.0.22:445 => Connected Moving 192.168.0.22 to completed hosts list with 0 outstanding probes. Changing global ping host to 192.168.0.22. Nmap scan report for 192.168.0.22 Host is up, received user-set (0.00036s latency). Scanned at 2016-02-18 10:25:44 EST for 4s PORT STATE SERVICE REASON 139/tcp open netbios-ssn syn-ack 445/tcp open microsoft-ds syn-ack Host script results: | smb-enum-domains: |_ ERROR: NT_STATUS_ACCESS_DENIED (samr.connect4) | smb-enum-groups: |_ ERROR: Couldn't enumerate groups: NT_STATUS_ACCESS_DENIED (samr.connect4) | smb-enum-processes: |_ ERROR: NT_STATUS_ACCESS_DENIED | smb-enum-shares: | note: ERROR: Enumerating shares failed, guessing at common ones (NT_STATUS_ACCESS_DENIED) | account_used: | ADMIN$: | warning: Couldn't get details for share: NT_STATUS_ACCESS_DENIED | Anonymous access: | C$: | warning: Couldn't get details for share: NT_STATUS_ACCESS_DENIED | Anonymous access: | IPC$: | warning: Couldn't get details for share: NT_STATUS_ACCESS_DENIED |_ Anonymous access: READ | smb-enum-users: |_ ERROR: Access denied while trying to enumerate users; except against Windows 2000, Guest or better is typically required | smb-os-discovery: | OS: Windows Server 2003 3790 Service Pack 1 (Windows Server 2003 5.2) | OS CPE: cpe:/o:microsoft:windows_server_2003::sp1 | Computer name: win1b2c3-lhqnxv | NetBIOS computer name: WIN1B2C3-LHQNXV | Workgroup: WORKGROUP |_ System time: 2016-02-18T10:25:44-05:00 |_smb-print-text: false | smb-psexec: Can't find the service file: nmap_service.exe (or nmap_service). | Due to false positives in antivirus software, this module is no | longer included by default. Please download it from | https://nmap.org/psexec/nmap_service.exe |_and place it in nselib/data/psexec/ under the Nmap DATADIR. | smb-security-mode: | account_used: | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) | smb-system-info: |_ ERROR: NT_STATUS_ACCESS_DENIED |_smb-vuln-ms10-061: NT_STATUS_OBJECT_NAME_NOT_FOUND |_smbv2-enabled: Server doesn't support SMBv2 protocol Read from /usr/local/bin/../share/nmap: nmap-payloads nmap-services. # Nmap done at Thu Feb 18 10:25:48 2016 -- 1 IP address (1 host up) scanned in 4.81 seconds