OpenVAS Scanner  7.0.1~git
ntlmssp.c File Reference

Functions to support Authentication(type3 message) for NTLMSSP (NTLMv2, NTLM2, NTLM, KEY GEN) More...

#include "ntlmssp.h"
#include <glib.h>
Include dependency graph for ntlmssp.c:

Go to the source code of this file.

Macros

#define NTLMSSP_NEGOTIATE_LM_KEY   0x00000080
 

Functions

void ntlmssp_genauth_ntlmv2 (char *user, char *domain, char *address_list, int address_list_len, char *challenge_data, uint8_t *lm_response, uint8_t *nt_response, uint8_t *session_key, unsigned char *ntlmv2_hash)
 
void ntlmssp_genauth_ntlm2 (char *password, uint8_t pass_len, uint8_t *lm_response, uint8_t *nt_response, uint8_t *session_key, char *challenge_data, unsigned char *nt_hash)
 
void ntlmssp_genauth_ntlm (char *password, uint8_t pass_len, uint8_t *lm_response, uint8_t *nt_response, uint8_t *session_key, char *challenge_data, unsigned char *nt_hash, int neg_flags)
 
uint8_t * ntlmssp_genauth_keyexchg (uint8_t *session_key, char *challenge_data, unsigned char *nt_hash, uint8_t *new_sess_key)
 

Detailed Description

Functions to support Authentication(type3 message) for NTLMSSP (NTLMv2, NTLM2, NTLM, KEY GEN)

Definition in file ntlmssp.c.

Macro Definition Documentation

◆ NTLMSSP_NEGOTIATE_LM_KEY

#define NTLMSSP_NEGOTIATE_LM_KEY   0x00000080

Definition at line 30 of file ntlmssp.c.

Referenced by ntlmssp_genauth_ntlm().

Function Documentation

◆ ntlmssp_genauth_keyexchg()

uint8_t* ntlmssp_genauth_keyexchg ( uint8_t *  session_key,
char *  challenge_data,
unsigned char *  nt_hash,
uint8_t *  new_sess_key 
)

Definition at line 99 of file ntlmssp.c.

References generate_random_buffer_ntlmssp(), SamOEMhash(), and uint8.

Referenced by nasl_keyexchg().

101 {
102  /* Make up a new session key */
103  uint8 client_session_key[16];
104 
105  (void) challenge_data;
106  (void) nt_hash;
107  generate_random_buffer_ntlmssp (client_session_key,
108  sizeof (client_session_key));
109  /* Encrypt the new session key with the old one */
110 
111  size_t length = sizeof (client_session_key);
112  uint8_t *encrypted_session_key = g_malloc0 (length);
113 
114  memcpy (encrypted_session_key, client_session_key, length);
115  SamOEMhash (encrypted_session_key, session_key, length);
116  memcpy (new_sess_key, client_session_key, 16);
117  return encrypted_session_key;
118 }
void SamOEMhash(uchar *data, const uchar *key, int val)
Definition: smb_crypt.c:331
void generate_random_buffer_ntlmssp(unsigned char *out, int len)
Definition: genrand.c:184
#define uint8
Definition: charcnv.c:58
Here is the call graph for this function:
Here is the caller graph for this function:

◆ ntlmssp_genauth_ntlm()

void ntlmssp_genauth_ntlm ( char *  password,
uint8_t  pass_len,
uint8_t *  lm_response,
uint8_t *  nt_response,
uint8_t *  session_key,
char *  challenge_data,
unsigned char *  nt_hash,
int  neg_flags 
)

Definition at line 75 of file ntlmssp.c.

References E_deshash_ntlmssp(), NTLMSSP_NEGOTIATE_LM_KEY, SMBencrypt_hash_ntlmssp(), SMBNTencrypt_hash_ntlmssp(), SMBsesskeygen_lm_sess_key_ntlmssp(), SMBsesskeygen_ntv1_ntlmssp(), and uchar.

Referenced by nasl_ntlm_response().

79 {
80  unsigned char lm_hash[16];
81 
82  E_deshash_ntlmssp (password, pass_len, lm_hash);
83 
84  SMBencrypt_hash_ntlmssp (lm_hash, (const uchar *) challenge_data,
85  lm_response);
86  SMBNTencrypt_hash_ntlmssp (nt_hash, (uchar *) challenge_data, nt_response);
87 
88  if (neg_flags & NTLMSSP_NEGOTIATE_LM_KEY)
89  {
90  SMBsesskeygen_lm_sess_key_ntlmssp (lm_hash, lm_response, session_key);
91  }
92  else
93  {
94  SMBsesskeygen_ntv1_ntlmssp (nt_hash, NULL, session_key);
95  }
96 }
#define uchar
Definition: hmacmd5.h:35
bool E_deshash_ntlmssp(const char *passwd, uint8_t pass_len, uchar p16[16])
Definition: smb_crypt.c:450
void SMBencrypt_hash_ntlmssp(const uchar lm_hash[16], const uchar *c8, uchar p24[24])
Definition: smb_crypt.c:407
#define NTLMSSP_NEGOTIATE_LM_KEY
Definition: ntlmssp.c:30
void SMBsesskeygen_ntv1_ntlmssp(const uchar kr[16], const uchar *nt_resp, uint8 sess_key[16])
Definition: smb_crypt.c:386
void SMBsesskeygen_lm_sess_key_ntlmssp(const uchar lm_hash[16], const uchar lm_resp[24], uint8 sess_key[16])
Definition: smb_crypt.c:429
void SMBNTencrypt_hash_ntlmssp(const uchar nt_hash[16], uchar *c8, uchar *p24)
Definition: smb_crypt.c:419
Here is the call graph for this function:
Here is the caller graph for this function:

◆ ntlmssp_genauth_ntlm2()

void ntlmssp_genauth_ntlm2 ( char *  password,
uint8_t  pass_len,
uint8_t *  lm_response,
uint8_t *  nt_response,
uint8_t *  session_key,
char *  challenge_data,
unsigned char *  nt_hash 
)

Definition at line 44 of file ntlmssp.c.

References E_deshash_ntlmssp(), generate_random_buffer_ntlmssp(), hmac_md5(), MD5Final(), MD5Init(), MD5Update(), SMBNTencrypt_hash_ntlmssp(), SMBsesskeygen_ntv1_ntlmssp(), and uchar.

Referenced by nasl_ntlm2_response().

47 {
48  unsigned char lm_hash[16];
49 
50  E_deshash_ntlmssp (password, pass_len, lm_hash);
51 
52  struct MD5Context md5_session_nonce_ctx;
53  uchar session_nonce_hash[16];
54  uchar session_nonce[16];
55  uchar user_session_key[16];
56 
57  generate_random_buffer_ntlmssp (lm_response, 8);
58  memset (lm_response + 8, 0, 16);
59 
60  memcpy (session_nonce, challenge_data, 8);
61  memcpy (&session_nonce[8], lm_response, 8);
62 
63  MD5Init (&md5_session_nonce_ctx);
64  MD5Update (&md5_session_nonce_ctx, (unsigned char const *) challenge_data, 8);
65  MD5Update (&md5_session_nonce_ctx, (unsigned char const *) lm_response, 8);
66  MD5Final (session_nonce_hash, &md5_session_nonce_ctx);
67 
68  SMBNTencrypt_hash_ntlmssp (nt_hash, session_nonce_hash, nt_response);
69  SMBsesskeygen_ntv1_ntlmssp (nt_hash, NULL, user_session_key);
70  hmac_md5 (user_session_key, session_nonce, sizeof (session_nonce),
71  session_key);
72 }
#define uchar
Definition: hmacmd5.h:35
bool E_deshash_ntlmssp(const char *passwd, uint8_t pass_len, uchar p16[16])
Definition: smb_crypt.c:450
void generate_random_buffer_ntlmssp(unsigned char *out, int len)
Definition: genrand.c:184
void MD5Final(unsigned char digest[16], struct MD5Context *ctx)
Definition: md5.c:118
void MD5Init(struct MD5Context *ctx)
Definition: md5.c:50
void hmac_md5(uchar key[16], uchar *data, int data_len, uchar *digest)
Function to calculate an HMAC MD5 digest from data. Use the microsoft hmacmd5 init method because the...
Definition: hmacmd5.c:95
Definition: md5.h:46
void MD5Update(struct MD5Context *ctx, unsigned char const *buf, unsigned len)
Definition: md5.c:66
void SMBsesskeygen_ntv1_ntlmssp(const uchar kr[16], const uchar *nt_resp, uint8 sess_key[16])
Definition: smb_crypt.c:386
void SMBNTencrypt_hash_ntlmssp(const uchar nt_hash[16], uchar *c8, uchar *p24)
Definition: smb_crypt.c:419
Here is the call graph for this function:
Here is the caller graph for this function:

◆ ntlmssp_genauth_ntlmv2()

void ntlmssp_genauth_ntlmv2 ( char *  user,
char *  domain,
char *  address_list,
int  address_list_len,
char *  challenge_data,
uint8_t *  lm_response,
uint8_t *  nt_response,
uint8_t *  session_key,
unsigned char *  ntlmv2_hash 
)

Definition at line 33 of file ntlmssp.c.

References SMBNTLMv2encrypt_hash_ntlmssp().

Referenced by nasl_ntlmv2_response().

37 {
38  SMBNTLMv2encrypt_hash_ntlmssp (user, domain, ntlmv2_hash, challenge_data,
39  address_list, address_list_len, lm_response,
40  nt_response, session_key);
41 }
void SMBNTLMv2encrypt_hash_ntlmssp(const char *user, const char *domain, uchar ntlm_v2_hash[16], const char *server_chal, const char *address_list, int address_list_len, uint8_t *lm_response, uint8_t *nt_response, uint8_t *user_session_key)
Definition: smb_crypt.c:568
Here is the call graph for this function:
Here is the caller graph for this function: