|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
NTLMv2 response computation (MS-NLMP §3.3.2) for the SMB2 client (PROTOCORE_ENABLE_SMB). More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | NtlmNs |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Functions | |
| PROTOCORE_NS_LAYOUT (NtlmNs, nt_hash, ntowfv2, v2_response, set_mic_flag, mic) | |
| void | protocore_ntlm_nt_hash (uint8_t *work, const char *password, uint8_t *nt_hash) |
| The NT hash: MD4 of the UTF-16LE password (password is ASCII/UTF-8, . | |
| proto_bool | protocore_ntlm_ntowfv2 (uint8_t *work, const uint8_t *nt_hash, const char *user, const char *domain, uint8_t *owf) |
| NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)). . | |
| size_t | protocore_ntlm_v2_response (uint8_t *work, const uint8_t *owf, const uint8_t *server_challenge, const uint8_t *client_challenge, const uint8_t *timestamp, const uint8_t *target_info, size_t ti_len, uint8_t *out, size_t out_cap, uint8_t *session_key) |
| Compute the NTLMv2 NtChallengeResponse (NTProofStr + temp) and the . | |
| size_t | protocore_ntlm_set_mic_flag (uint8_t *work, const uint8_t *target_info, size_t ti_len, uint8_t *out, size_t out_cap) |
| Copy the CHALLENGE target-info AV_PAIR list into out, setting the . | |
| void | protocore_ntlm_mic (uint8_t *work, const uint8_t *session_key, const uint8_t *neg, size_t neg_len, const uint8_t *chal, size_t chal_len, const uint8_t *auth, size_t auth_len, uint8_t *out) |
| The NTLMSSP AUTHENTICATE MIC (MS-NLMP §3.1.5.1.2): HMAC-MD5 over . | |
Variables | |
| PROTOCORE_NS NtlmNs Ntlm | PROTOCORE_UNUSED |
| Module namespace. | |
NTLMv2 response computation (MS-NLMP §3.3.2) for the SMB2 client (PROTOCORE_ENABLE_SMB).
The auth core: from the user's password and the server's CHALLENGE (the 8-byte server challenge
NThash = MD4(UTF-16LE(password)) NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)) temp = 0x01 0x01 Z(6) Time(8) ClientChallenge(8) Z(4) TargetInfo Z(4) NTProofStr = HMAC-MD5(NTOWFv2, ServerChallenge(8) + temp) NtChallengeResponse = NTProofStr(16) + temp SessionBaseKey = HMAC-MD5(NTOWFv2, NTProofStr)
Verified against the MS-NLMP §4.2 worked example (test_ntlm).
work is bytes the CALLER holds. This module reads none of them: it carries nothing between calls, so there is no state to keep and nothing to wipe. The parameter is there so a caller drives every namespace the same way.
Definition in file ntlm.h.
| PROTOCORE_NS_LAYOUT | ( | NtlmNs | , |
| nt_hash | , | ||
| ntowfv2 | , | ||
| v2_response | , | ||
| set_mic_flag | , | ||
| mic | |||
| ) |
| void protocore_ntlm_nt_hash | ( | uint8_t * | work, |
| const char * | password, | ||
| uint8_t * | nt_hash | ||
| ) |
The NT hash: MD4 of the UTF-16LE password (password is ASCII/UTF-8, .
| work | PROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call. |
| password | Password |
| nt_hash | 16 bytes |
| proto_bool protocore_ntlm_ntowfv2 | ( | uint8_t * | work, |
| const uint8_t * | nt_hash, | ||
| const char * | user, | ||
| const char * | domain, | ||
| uint8_t * | owf | ||
| ) |
NTOWFv2 = HMAC-MD5(NThash, UTF-16LE(Uppercase(user) + domain)). .
| work | PROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call. |
| nt_hash | 16 bytes |
| user | User |
| domain | Domain |
| owf | 16 bytes |
| size_t protocore_ntlm_v2_response | ( | uint8_t * | work, |
| const uint8_t * | owf, | ||
| const uint8_t * | server_challenge, | ||
| const uint8_t * | client_challenge, | ||
| const uint8_t * | timestamp, | ||
| const uint8_t * | target_info, | ||
| size_t | ti_len, | ||
| uint8_t * | out, | ||
| size_t | out_cap, | ||
| uint8_t * | session_key | ||
| ) |
Compute the NTLMv2 NtChallengeResponse (NTProofStr + temp) and the .
| work | PROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call. |
| owf | NTOWFv2 (from protocore_ntlm_ntowfv2) 16 bytes |
| server_challenge | the 8-byte challenge from the server's CHALLENGE_MESSAGE 8 bytes |
| client_challenge | the 8-byte client-generated challenge 8 bytes |
| timestamp | the 8-byte little-endian FILETIME (may be zero) 8 bytes |
| target_info | the AV_PAIR blob from the CHALLENGE_MESSAGE |
| ti_len | Ti len |
| out | Out |
| out_cap | Out cap |
| session_key | receives the 16-byte SessionBaseKey (may be null) 16 bytes |
| size_t protocore_ntlm_set_mic_flag | ( | uint8_t * | work, |
| const uint8_t * | target_info, | ||
| size_t | ti_len, | ||
| uint8_t * | out, | ||
| size_t | out_cap | ||
| ) |
Copy the CHALLENGE target-info AV_PAIR list into out, setting the .
| work | PROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call. |
| target_info | Target info |
| ti_len | Ti len |
| out | Out |
| out_cap | Out cap |
| void protocore_ntlm_mic | ( | uint8_t * | work, |
| const uint8_t * | session_key, | ||
| const uint8_t * | neg, | ||
| size_t | neg_len, | ||
| const uint8_t * | chal, | ||
| size_t | chal_len, | ||
| const uint8_t * | auth, | ||
| size_t | auth_len, | ||
| uint8_t * | out | ||
| ) |
The NTLMSSP AUTHENTICATE MIC (MS-NLMP §3.1.5.1.2): HMAC-MD5 over .
| work | PROTOCORE_NTLM_BORROW bytes the caller took. Not held past the call. |
| session_key | 16 bytes |
| neg | Neg |
| neg_len | Neg len |
| chal | Chal |
| chal_len | Chal len |
| auth | Auth |
| auth_len | Auth len |
| out | 16 bytes |
| PROTOCORE_NS NtlmNs Ntlm PROTOCORE_UNUSED |
Module namespace.