[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffnQeBGlr8ngtWSo5kKLs9ZGhHC-pFlTQyhvr63uWzw0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},708,"How does the open-source PowerShell script provided in the article handle both enabling and disabling anonymous shares?","The script `Invoke-BuildAnonymousSMBServer` automates all the registry, group policy, and sharing changes. In enable mode, it performs the five steps mentioned in the command-line section. In disable mode, it reverses each change: disables the share, deactivates the Guest user, removes the `EveryoneIncludesAnonymous` registry value, deletes the `NullSessionShares` entry, and re-adds Guest to the deny network logon policy. The script handles the edge case where the deny policy line may be missing by inserting it correctly. It is tested on Windows 7 through Server 2016.","\u003Cp>The script `Invoke-BuildAnonymousSMBServer` automates all the registry, group policy, and sharing changes. In enable mode, it performs the five steps mentioned in the command-line section. In disable mode, it reverses each change: disables the share, deactivates the Guest user, removes the `EveryoneIncludesAnonymous` registry value, deletes the `NullSessionShares` entry, and re-adds Guest to the deny network logon policy. The script handles the edge case where the deny policy line may be missing by inserting it correctly. It is tested on Windows 7 through Server 2016.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-enabling-anonymous-access-shares-on-windows-systems-via-command-line\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-open-source-powershell-script-provided-in-the-article-handle-both-e-1777482291512","PowerShell, Invoke-BuildAnonymousSMBServer, open-source, automation, enabling\u002Fdisabling",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},175,"Penetration Techniques - Enabling Anonymous Access Shares on Windows Systems via Command Line","penetration-techniques-enabling-anonymous-access-shares-on-windows-systems-via-command-line","Learn to enable anonymous access file shares on Windows via command line for penetration testing, data transfer, and payload delivery in internal networks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, especially in internal network penetration, it is often necessary to enable an anonymously accessible file share within the internal network to facilitate vulnerability exploitation.\u003C\u002Fp>\u003Cp>Therefore, we need a universal method that is not only convenient to use but also capable of running via the command line.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Usage Scenarios\u003C\u002Fli>\u003Cli>Enabling an anonymously accessible file share server via the GUI\u003C\u002Fli>\u003Cli>Enabling an anonymously accessible file share server via the command line\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage Scenarios\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After enabling an anonymously accessible file share, other users can directly access the shared files on the file server without entering a username or password.\u003C\u002Fp>\u003Cp>Typically, there are two common uses:\u003C\u002Fp>\u003Col>\u003Cli>As a channel for data transmission\u003C\u002Fli>\u003Cli>Used in conjunction with vulnerability exploitation, serving as the download address for the payload\u003C\u002Fli>\u003C\u002Fol>\u003Cp>File sharing servers need to be deployable across different operating systems\u003C\u002Fp>\u003Cp>For Linux systems, a file sharing server with anonymous access can be set up using the Samba service\u003C\u002Fp>\u003Cp>Here is the usage method for Kali systems:\u003C\u002Fp>\u003Cp>Modify the file \u002Fetc\u002Fsamba\u002Fsmb.conf with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[global]\u003Cbr>    map to guest = test1\u003Cbr>    server role = standalone server\u003Cbr>    usershare allow guests = yes\u003Cbr>    idmap config * : backend = tdb\u003Cbr>    smb ports = 445\u003Cbr>\u003Cbr>[smb]\u003Cbr>    comment = Samba\u003Cbr>    path = \u002Ftmp\u002F\u003Cbr>    guest ok = yes\u003Cbr>    read only = no\u003Cbr>    browsable = yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Start services:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>service smbd start\u003Cbr>service nmbd start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For Windows systems, domain environment and workgroup environment need to be considered. To support anonymous access, the Guest user needs to be enabled, allowing Guest users to access the content of the file sharing server.\u003C\u002Fp>\u003Ch2>0x03 Enabling an anonymously accessible file sharing server via the interface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The specific method is as follows:\u003C\u002Fp>\u003Ch4>1. Enable the Guest user\u003C\u002Fh4>\u003Cp>Run gpedit.msc to open Group Policy\u003C\u002Fp>\u003Cp>Location: Computer Configuration-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;Security Options\u003C\u002Fp>\u003Cp>Select the policy Accounts: Guest account status and set it to Enabled\u003C\u002Fp>\u003Ch4>2. Apply Everyone permissions to anonymous users\u003C\u002Fh4>\u003Cp>Location: Computer Configuration-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;Security Options\u003C\u002Fp>\u003Cp>Select policy Network access: Let Everyone permissions apply to anonymous users, set to Enabled\u003C\u002Fp>\u003Ch4>3. Specify the location for anonymous shared files\u003C\u002Fh4>\u003Cp>Location: Computer Configuration-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;Security Options\u003C\u002Fp>\u003Cp>Select policy Network access: Shares that can be accessed anonymously, set the name, here you can enter smb\u003C\u002Fp>\u003Ch4>4. Remove Guest user from the policy \"Deny access to this computer from the network\"\u003C\u002Fh4>\u003Cp>Location: Computer Configuration-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;User Rights Assignment\u003C\u002Fp>\u003Cp>Select policy Deny access to this computer from the network, remove user Guest\u003C\u002Fp>\u003Ch4>5. Set up file sharing\u003C\u002Fh4>\u003Cp>Select the folder to share, set up advanced sharing, share name as smb, share permissions group or username as Everyone\u003C\u002Fp>\u003Cp>At this point, the anonymously accessible file sharing server is successfully enabled, and the access address is \u002F\u002F\u003Cip>\u002Fsmb\u003C\u002Fip>\u003C\u002Fp>\u003Ch2>0x04 Enable an anonymously accessible file sharing server via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding commands for the specific methods are as follows:\u003C\u002Fp>\u003Ch4>1. Enable Guest user\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user guest \u002Factive:yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Apply Everyone permissions to anonymous users\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\System\\CurrentControlSet\\Control\\Lsa\" \u002Fv EveryoneIncludesAnonymous \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Specify the location of anonymous shared files\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\System\\CurrentControlSet\\Services\\LanManServer\\Parameters\" \u002Fv NullSessionShares \u002Ft REG_MULTI_SZ \u002Fd smb \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Remove Guest user from the policy \"Deny access to this computer from the network\"\u003C\u002Fh4>\u003Cp>Export Group Policy:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>secedit \u002Fexport \u002Fcfg gp.inf \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify the file gp.inf, change SeDenyNetworkLogonRight = Guest to SeDenyNetworkLogonRight =, save\u003C\u002Fp>\u003Cp>Re-import Group Policy:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>secedit \u002Fconfigure \u002Fdb gp.sdb \u002Fcfg gp.inf \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Force refresh Group Policy to take effect immediately (otherwise, it will take effect after reboot):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate\u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Set up file sharing\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\share\\ \u002FT \u002Fgrant Everyone:r\u003Cbr>net share share=c:\\share \u002Fgrant:everyone,full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the anonymous access file sharing server has been successfully enabled, and the access address is \u002F\u002F\u003Cip>\u002Fsmb\u003C\u002Fip>\u003C\u002Fp>\u003Ch2>0x05 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The complete PowerShell code has been open-sourced, and the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code has been successfully tested on the following operating systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows 7\u003C\u002Fli>\u003Cli>Windows 8\u003C\u002Fli>\u003Cli>Windows 10\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2012 R2\u003C\u002Fli>\u003Cli>Windows Server 2016\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Supports Windows operating systems in both domain and workgroup environments\u003C\u002Fp>\u003Cp>Requires local administrator privileges to execute\u003C\u002Fp>\u003Cp>Enable anonymously accessible file sharing server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-BuildAnonymousSMBServer -Path c:\\share -Mode Enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disable anonymously accessible file sharing server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-BuildAnonymousSMBServer -Path c:\\share -Mode Disable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Disabling the anonymously accessible file sharing server performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Disable sharing permissions for the specified directory\u003C\u002Fli>\u003Cli>Disable Guest user\u003C\u002Fli>\u003Cli>Disable applying Everyone permissions to anonymous users\u003C\u002Fli>\u003Cli>Remove the anonymous shared file location specified in Group Policy\u003C\u002Fli>\u003Cli>Add Guest user to the policy 'Deny access to this computer from the network'\u003C\u002Fli>\u003C\u002Ful>\u003Cp>When exporting Group Policy, if the content in the policy 'Deny access to this computer from the network' is empty, this option will not exist. When we need to add this policy, we must manually add a line: SeDenyNetworkLogonRight = Guest\u003C\u002Fp>\u003Cp>In the code implementation, I adopted the following method:\u003C\u002Fp>\u003Cp>SeDenyInteractiveLogonRight = Guest\u003C\u002Fp>\u003Cp>Replace with\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SeDenyNetworkLogonRight = Guest\u003Cbr>SeDenyInteractiveLogonRight = Guest\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding PowerShell example code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>(Get-Content a.txt) -replace \"SeDenyInteractiveLogonRight = Guest\",\"SeDenyNetworkLogonRight = Guest`r`nSeDenyInteractiveLogonRight = Guest\" | Set-Content \"a.txt\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article implements enabling and disabling anonymous access to shares from the command line, with open-source code, which can be used to test CVE-2021-1675 and CVE-2021-34527.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:38:21.203Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Enable Anonymous Windows File Shares via Command Line for Penetration Testing","anonymous file share, Windows penetration testing, command line shares, internal network security, SMB configuration, Guest user access, penetration techniques",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44],709,707,706,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.181Z","2026-07-23T16:01:59.434Z","draft","2026-07-23T16:14:19.699Z"]