All playbooks

Playbook · beginner · 2–3 hours

Exposed NAS share on the LAN

Find an open or weakly shared NAS/folder, prove data exposure without bulk theft, and lock down shares + network path.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Scenario

A home NAS or old PC share is visible to the whole LAN (or guest Wi-Fi). You will enumerate shares, demonstrate read access with minimal data touch, and remediate ACLs and segmentation.

Goals

Discover SMB/NFS services on owned hosts

List shares and permissions safely

Show business/personal impact with minimal evidence

Apply least-privilege share perms and network controls

Requirements

NAS or lab Samba host you own

Attacker/admin host on LAN

Safety

Do not copy personal photo libraries as 'loot' — sample filenames only

Avoid write tests that could damage data unless intentional lab

Steps

Step 1

Find file services

Intent: Locate SMB/NFS without full-port thrash if inventory exists.

Actions

  • nmap -p 139,445,2049 on known hosts or subnet
  • Note versions/banners for later patch notes
Expected: List of hosts with 445/2049 open.
Step 2

Enumerate shares

Intent: See what is exposed to whom.

Actions

  • smbclient -L //HOST -N and with a normal user
  • smbmap -H HOST ; showmount -e HOST for NFS
  • Record guest/anonymous access if present
Expected: Share table with guest vs auth access noted.
Step 3

Proportional proof

Intent: Evidence without data exfiltration.

Actions

  • List a directory; screenshot filenames only
  • If readable sensitive path exists, note path — do not zip the volume
Expected: Finding draft with impact (privacy, credential files, backups).
Step 4

Remediate

Intent: Close the easy path.

Actions

  • Disable guest; set per-user ACLs; remove world-readable shares
  • Bind shares to trusted VLAN; block guest SSID → NAS
  • Enable NAS firewall updates; turn off SMBv1 if present
Expected: Re-enum shows guest denied; only intended users can list shares.

Remediation outcomes

No anonymous shares on home LAN

Least-privilege user accounts per person/service

NAS not reachable from IoT/guest networks

Backups encrypted; admin UI not WAN-exposed