ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
ntlm.h File Reference

NTLMv2 response computation (MS-NLMP §3.3.2) for the SMB2 client (PROTOCORE_ENABLE_SMB). More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  NtlmNs
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Functions

 PROTOCORE_NS_LAYOUT (NtlmNs, nt_hash, ntowfv2, v2_response, set_mic_flag, mic)
 
void protocore_ntlm_nt_hash (uint8_t *work, const char *password, uint8_t *nt_hash)
 The NT hash: MD4 of the UTF-16LE password (password is ASCII/UTF-8, .
 
proto_bool protocore_ntlm_ntowfv2 (uint8_t *work, const uint8_t *nt_hash, const char *user, const char *domain, uint8_t *owf)
 NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)). .
 
size_t protocore_ntlm_v2_response (uint8_t *work, const uint8_t *owf, const uint8_t *server_challenge, const uint8_t *client_challenge, const uint8_t *timestamp, const uint8_t *target_info, size_t ti_len, uint8_t *out, size_t out_cap, uint8_t *session_key)
 Compute the NTLMv2 NtChallengeResponse (NTProofStr + temp) and the .
 
size_t protocore_ntlm_set_mic_flag (uint8_t *work, const uint8_t *target_info, size_t ti_len, uint8_t *out, size_t out_cap)
 Copy the CHALLENGE target-info AV_PAIR list into out, setting the .
 
void protocore_ntlm_mic (uint8_t *work, const uint8_t *session_key, const uint8_t *neg, size_t neg_len, const uint8_t *chal, size_t chal_len, const uint8_t *auth, size_t auth_len, uint8_t *out)
 The NTLMSSP AUTHENTICATE MIC (MS-NLMP §3.1.5.1.2): HMAC-MD5 over .
 

Variables

PROTOCORE_NS NtlmNs Ntlm PROTOCORE_UNUSED
 Module namespace.
 

Detailed Description

NTLMv2 response computation (MS-NLMP §3.3.2) for the SMB2 client (PROTOCORE_ENABLE_SMB).

The auth core: from the user's password and the server's CHALLENGE (the 8-byte server challenge

  • the target-info AV_PAIR blob), compute the NtChallengeResponse and the session base key that seed SESSION_SETUP. Built on the KAT-verified MD4 / MD5 / HMAC-MD5 (crypto/hash/md.h). Pure, zero heap.

NThash = MD4(UTF-16LE(password)) NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)) temp = 0x01 0x01 Z(6) Time(8) ClientChallenge(8) Z(4) TargetInfo Z(4) NTProofStr = HMAC-MD5(NTOWFv2, ServerChallenge(8) + temp) NtChallengeResponse = NTProofStr(16) + temp SessionBaseKey = HMAC-MD5(NTOWFv2, NTProofStr)

Verified against the MS-NLMP §4.2 worked example (test_ntlm).

work is bytes the CALLER holds. This module reads none of them: it carries nothing between calls, so there is no state to keep and nothing to wipe. The parameter is there so a caller drives every namespace the same way.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file ntlm.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( NtlmNs  ,
nt_hash  ,
ntowfv2  ,
v2_response  ,
set_mic_flag  ,
mic   
)

◆ protocore_ntlm_nt_hash()

void protocore_ntlm_nt_hash ( uint8_t *  work,
const char *  password,
uint8_t *  nt_hash 
)

The NT hash: MD4 of the UTF-16LE password (password is ASCII/UTF-8, .

Parameters
workPROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call.
passwordPassword
nt_hash16 bytes

◆ protocore_ntlm_ntowfv2()

proto_bool protocore_ntlm_ntowfv2 ( uint8_t *  work,
const uint8_t *  nt_hash,
const char *  user,
const char *  domain,
uint8_t *  owf 
)

NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)). .

Parameters
workPROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call.
nt_hash16 bytes
userUser
domainDomain
owf16 bytes
Returns
PROTO_TRUE on success.

◆ protocore_ntlm_v2_response()

size_t protocore_ntlm_v2_response ( uint8_t *  work,
const uint8_t *  owf,
const uint8_t *  server_challenge,
const uint8_t *  client_challenge,
const uint8_t *  timestamp,
const uint8_t *  target_info,
size_t  ti_len,
uint8_t *  out,
size_t  out_cap,
uint8_t *  session_key 
)

Compute the NTLMv2 NtChallengeResponse (NTProofStr + temp) and the .

Parameters
workPROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call.
owfNTOWFv2 (from protocore_ntlm_ntowfv2) 16 bytes
server_challengethe 8-byte challenge from the server's CHALLENGE_MESSAGE 8 bytes
client_challengethe 8-byte client-generated challenge 8 bytes
timestampthe 8-byte little-endian FILETIME (may be zero) 8 bytes
target_infothe AV_PAIR blob from the CHALLENGE_MESSAGE
ti_lenTi len
outOut
out_capOut cap
session_keyreceives the 16-byte SessionBaseKey (may be null) 16 bytes
Returns
The size_t.

◆ protocore_ntlm_set_mic_flag()

size_t protocore_ntlm_set_mic_flag ( uint8_t *  work,
const uint8_t *  target_info,
size_t  ti_len,
uint8_t *  out,
size_t  out_cap 
)

Copy the CHALLENGE target-info AV_PAIR list into out, setting the .

Parameters
workPROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call.
target_infoTarget info
ti_lenTi len
outOut
out_capOut cap
Returns
The size_t.

◆ protocore_ntlm_mic()

void protocore_ntlm_mic ( uint8_t *  work,
const uint8_t *  session_key,
const uint8_t *  neg,
size_t  neg_len,
const uint8_t *  chal,
size_t  chal_len,
const uint8_t *  auth,
size_t  auth_len,
uint8_t *  out 
)

The NTLMSSP AUTHENTICATE MIC (MS-NLMP §3.1.5.1.2): HMAC-MD5 over .

Parameters
workPROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call.
session_key16 bytes
negNeg
neg_lenNeg len
chalChal
chal_lenChal len
authAuth
auth_lenAuth len
out16 bytes

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS NtlmNs Ntlm PROTOCORE_UNUSED
Initial value:
= {.nt_hash = protocore_ntlm_nt_hash,
.set_mic_flag = protocore_ntlm_set_mic_flag,
size_t protocore_ntlm_set_mic_flag(uint8_t *work, const uint8_t *target_info, size_t ti_len, uint8_t *out, size_t out_cap)
Copy the CHALLENGE target-info AV_PAIR list into out, setting the .
void protocore_ntlm_nt_hash(uint8_t *work, const char *password, uint8_t *nt_hash)
The NT hash: MD4 of the UTF-16LE password (password is ASCII/UTF-8, .
size_t protocore_ntlm_v2_response(uint8_t *work, const uint8_t *owf, const uint8_t *server_challenge, const uint8_t *client_challenge, const uint8_t *timestamp, const uint8_t *target_info, size_t ti_len, uint8_t *out, size_t out_cap, uint8_t *session_key)
Compute the NTLMv2 NtChallengeResponse (NTProofStr + temp) and the .
void protocore_ntlm_mic(uint8_t *work, const uint8_t *session_key, const uint8_t *neg, size_t neg_len, const uint8_t *chal, size_t chal_len, const uint8_t *auth, size_t auth_len, uint8_t *out)
The NTLMSSP AUTHENTICATE MIC (MS-NLMP §3.1.5.1.2): HMAC-MD5 over .
proto_bool protocore_ntlm_ntowfv2(uint8_t *work, const uint8_t *nt_hash, const char *user, const char *domain, uint8_t *owf)
NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)). .

Module namespace.

Definition at line 115 of file ntlm.h.