Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Reduce What Your Lab Machines Share: Turn Off SMBv1, NetBIOS and Default SNMP, Then Verify from Inside and from the Lab Network

Intermediate40 minYour own Windows 10/11 laptop (PowerShell as admin) · Your Ubuntu VM · Kali in your isolated lab (Lab 18) · nmap

Course: Cyber Security · Chapter 37: Enumeration: NetBIOS, SMB, SNMP, LDAP, SMTP, NFS and DNS

Chapter 37 explains enumeration of NetBIOS, SMB, SNMP and more; this lab removes what those techniques would find on your own machines.

Chala mitrano! Enumeration works because computers are chatty: old file-sharing (SMBv1), name broadcasts (NetBIOS), and device-management services (SNMP) with the default password "public". Today we make our own machines quiet: switch off what we don't use and prove it from both sides. Kami bolka computer, surakshit computer!

Suppose we are…

Suppose we are on the desktop security team at Larsen & Toubro (L&T). After WannaCry spread through SMBv1, the company rule is: no SMBv1 anywhere, NetBIOS off where not needed, no SNMP with default community strings, and no open shares except what is approved. We apply the same rule to our own laptop and lab VM, then verify.

Goal of this lab

By the end you will have:

  • SMBv1 confirmed off on Windows, and a list of your shares.
  • NetBIOS over TCP/IP disabled on your lab (host-only) adapter.
  • SNMP confirmed absent or removed on Windows and Ubuntu, verified with nmap from Kali.

What you need (all free)

  • Your own Windows 10/11 laptop with admin rights.
  • Your isolated lab from Lab 18 with Kali and your Ubuntu VM. About 40 minutes.

Safety and ethics

Scan only your own laptop's lab address (192.168.56.1) and your own lab VMs, as in your scope file. Change network settings only on your own devices; at work, follow your IT team's process.

Part 1: Windows (PowerShell as Administrator)

  1. Right-click Start → Terminal (Admin) or Windows PowerShell (Admin).
  2. Check SMBv1:

    Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol | Select-Object FeatureName, State
    Get-SmbServerConfiguration | Select-Object EnableSMB1Protocol, EnableSMB2Protocol
    

    What you should see: State : Disabled and EnableSMB1Protocol : False, EnableSMB2Protocol : True. If SMB1 is enabled, run Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol and restart.

  3. List your shares:

    Get-SmbShare
    

    What you should see: only the built-in admin shares ADMIN$, C$ and IPC$. Any other share (for example an old Movies folder) should be removed if not needed: Remove-SmbShare -Name Movies.

  4. Disable NetBIOS on the lab adapter: Control Panel → Network and Sharing Center → Change adapter settings → right-click VirtualBox Host-Only Network → Properties → Internet Protocol Version 4 → Properties → Advanced → WINS tab → Disable NetBIOS over TCP/IP → OK. (Repeat for Wi-Fi if you never use old Windows file sharing at home.)

  5. Verify:

    ipconfig /all | Select-String "NetBIOS over Tcpip"
    Get-Service SNMP -ErrorAction SilentlyContinue
    

    What you should see: NetBIOS over Tcpip. . . . . . . . : Disabled for the lab adapter, and no output for SNMP (the service is not installed, which is what we want).

Part 2: Ubuntu VM

  1. Check for SNMP and Samba services:

    sudo ss -tulpn | grep -E ":161|:139|:445" || echo "nothing listening"
    

    What you should see: nothing listening. If snmpd is listed, remove it with sudo apt purge -y snmpd unless you really need it (and then never with community public).

Part 3: verify from the lab network (Kali)

  1. From Kali, check your laptop's lab address for SMB dialects and NetBIOS:

    sudo nmap -p 445 --script smb-protocols 192.168.56.1
    sudo nmap -sU -p 137,161 192.168.56.1 192.168.56.10x
    

    What you should see: for 445 either filtered (Windows Firewall already hides it, good) or a dialect list without NT LM 0.12 (SMBv1). UDP 137 and 161 show closed or open|filtered with no NetBIOS names or SNMP answers.

  2. Write a short "before/after" note: setting, before, after, how verified.

Ravindra Bagale's Tip

SMBv2/v3 is fine and needed for normal Windows file sharing. The danger is SMBv1, which is about 30 years old. Don't disable everything blindly: switch off the old and unused, keep the modern and needed, and write down why. Juna band, navin chalu!

Common mistakes

Mistake What happens Fix
Disabling SMBv2/v3 as well Normal file sharing and some apps break Disable only SMBv1
Running PowerShell without admin Get-​SmbServerConfiguration or Disable fails Open Terminal (Admin)
Disabling NetBIOS on an office network adapter Old printers or shares may stop working Change your own lab/home adapters; ask IT at work
Keeping SNMP with community public Anyone can read device details Remove SNMP or use SNMPv3 with a strong secret
Scanning the office or college network to "verify" Unauthorised scanning Scan only your own lab IPs

Self-check checklist

0 of 5 done

Try-at-home challenge

Check your home router's admin page (Lab 25) for SNMP and UPnP settings. What would you set, and why?

Check your answer

Set SNMP: Off (home users do not need remote device management, and many routers ship with community public). Set UPnP: Off unless a game console or app truly needs it, because UPnP lets devices open ports on your router automatically. Note both in your router card.

Samjla ka? Old protocols off, shares reviewed, verified from inside and outside. Aata pudhe jaauya: Chapter 38 looks at accounts and logons on Windows.