[prev in list] [next in list] [prev in thread] [next in thread] 

List:       cifs-protocol
Subject:    [cifs-protocol] ntproof field
From:       Matthieu Patou <mat () samba ! org>
Date:       2012-02-12 7:14:12
Message-ID: 4F3766C4.8090106 () samba ! org
[Download RAW message or body]

Hello Dochelp,

MS-NLMP didn't provide much information about the ntrpoof field use, 
it's explained how to calculate it but it's not explained what the 
server should do with this attribute/value.

My understanding is that the server when receiving an 
AUTHENTICATE_MESSAGE with a NTLMv2 response must check the ntproof 
(first 16 bytes of the nt response field) and the lm response field. In 
the fact it seems that the proof is not verified.
With the help of ntlm_auth I provided 2 almost similar nt_response with 
just the first byte of the ntproof being different, Windows 2008R2 
accepted both authenticate message.

Is it the expected behavior ?

Thanks for your answer.

Matthieu

-- 
Matthieu Patou
Samba Team
http://samba.org

_______________________________________________
cifs-protocol mailing list
cifs-protocol@cifs.org
https://lists.samba.org/mailman/listinfo/cifs-protocol
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic