Description
This module exploits CVE-2000-0979, an information disclosure vulnerability in the share-level password authentication of Microsoft Windows 9x/Me SMB servers. The server validates passwords one character at a time, allowing an attacker to enumerate the correct password byte-by-byte based on the server response. A zero-length password is always accepted, and each subsequent character can be brute-forced individually, significantly reducing the search space required to recover the full share password.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/smb/cve/2000_0979msf undefined(2000_0979) > show actions ...actions...msf undefined(2000_0979) > set ACTION < action-name >msf undefined(2000_0979) > show options ...show and set options...msf undefined(2000_0979) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub