Wrigs icon

Samba Setup - Ubuntu

Wrigs | PRO | 03/01/26 06:32:06 PM UTC | 0 ⭐ | 8985 👁️ | Never ⏰ | [samba]
text |

3.05 KB

|

None

|

0 👍

/

0 👎

Samba file sharing scenario:
• 3 private shares
• Each mapped to one user only
• Force ownership of all files to that user
• 1 public share (read/write for everyone)
• No interactive login allowed
 1. Install Samba:
sudo apt update
sudo apt install samba
 1a. Enable service:
sudo systemctl enable smbd
sudo systemctl start smbd
 2. Create a base directory:
sudo mkdir -p /srv/samba/{user1,user2,user3,public}
 3. Create Non-Login System Users
• Disable shell access
• Disable home directory creation
 sudo useradd -M -s /usr/sbin/nologin user1
sudo useradd -M -s /usr/sbin/nologin user2
sudo useradd -M -s /usr/sbin/nologin user3
 3a. Verify:
getent passwd user1
 3b. You should see:
user1:x:1001:1001::/home/user1:/usr/sbin/nologin
 ✔ Cannot SSH
✔ Cannot log in locally
 Public Folder:
 Create a shared group:
sudo groupadd smbpublic
sudo usermod -aG smbpublic user1
sudo usermod -aG smbpublic user2
sudo usermod -aG smbpublic user3
 Set ownership:
sudo chown root:smbpublic /srv/samba/public
sudo chmod 2775 /srv/samba/public
 Explanation:
• 2 sets the SGID bit
• New files inherit group smbpublic
• 775 allows group write
 5. Add Samba Passwords
sudo smbpasswd -a user1
sudo smbpasswd -a user2
sudo smbpasswd -a user3
 5a. Enable them:
sudo smbpasswd -e user1
sudo smbpasswd -e user2
sudo smbpasswd -e user3
 6. Configure Samba
sudo nano /etc/samba/smb.conf
 6a. Ensure in [global] section:
security = user
map to guest = never
 6b. Private Shares (Ownership Forced). Add:
 [user1]
   path = /srv/samba/user1
   valid users = user1
   read only = no
   browseable = yes
   force user = user1
   create mask = 0600
   directory mask = 0700
 [user2]
   path = /srv/samba/user2
   valid users = user2
   read only = no
   browseable = yes
   force user = user2
   create mask = 0600
   directory mask = 0700
 [user3]
   path = /srv/samba/user3
   valid users = user3
   read only = no
   browseable = yes
   force user = user3
   create mask = 0600
   directory mask = 0700
 ✔ force user ensures all files are owned by that user
✔ Even if accessed from Windows as that user
 7. Public Share. Add:
 [public]
   path = /srv/samba/public
   valid users = @smbpublic
   read only = no
   browseable = yes
   force group = smbpublic
   create mask = 0664
   directory mask = 2775
 Explanation:
• Any authenticated user in smbpublic can read/write
• Group ownership is forced
• SGID keeps group consistent
 8. Test Configuration
sudo testparm
 If no errors:
sudo systemctl restart smbd
 9. Firewall (if enabled)
sudo ufw allow samba
 10. What You Now Have:
 Share   Access       Ownership Behavior
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
user1   user1 only   All files owned by user1
user2   user2 only   All files owned by user2
user3   user3 only   All files owned by user3
public  All users    Group-owned, shared
 ✔ No SSH login
✔ No shell access
✔ Clean forced ownership
✔ Proper group inheritance

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  • Sinmirin icon
    03/29/26 10:57:42 PM UTC
    CSS |

    0 B

    |

    0 👍

    /

    0 👎

    ✅ Leaked Exploit Documentation:
     
    https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
     
    This made me $13,000 in 2 days.
     
    Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% — they will simply correct the exchange rate.
    The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
     
    Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap — instant swap).
    
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎