Playbook · beginner · 2–3 hours
Exposed NAS share on the LAN
Find an open or weakly shared NAS/folder, prove data exposure without bulk theft, and lock down shares + network path.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Scenario
A home NAS or old PC share is visible to the whole LAN (or guest Wi-Fi). You will enumerate shares, demonstrate read access with minimal data touch, and remediate ACLs and segmentation.
Goals
Discover SMB/NFS services on owned hosts
List shares and permissions safely
Show business/personal impact with minimal evidence
Apply least-privilege share perms and network controls
Requirements
NAS or lab Samba host you own
Attacker/admin host on LAN
Safety
Do not copy personal photo libraries as 'loot' — sample filenames only
Avoid write tests that could damage data unless intentional lab
Steps
Find file services
Intent: Locate SMB/NFS without full-port thrash if inventory exists.
Actions
- nmap -p 139,445,2049 on known hosts or subnet
- Note versions/banners for later patch notes
Enumerate shares
Intent: See what is exposed to whom.
Actions
- smbclient -L //HOST -N and with a normal user
- smbmap -H HOST ; showmount -e HOST for NFS
- Record guest/anonymous access if present
Proportional proof
Intent: Evidence without data exfiltration.
Actions
- List a directory; screenshot filenames only
- If readable sensitive path exists, note path — do not zip the volume
Remediate
Intent: Close the easy path.
Actions
- Disable guest; set per-user ACLs; remove world-readable shares
- Bind shares to trusted VLAN; block guest SSID → NAS
- Enable NAS firewall updates; turn off SMBv1 if present
Remediation outcomes
No anonymous shares on home LAN
Least-privilege user accounts per person/service
NAS not reachable from IoT/guest networks
Backups encrypted; admin UI not WAN-exposed