Basic NTLMSSP Parsing Scheme
LMO Type
|
Field Name |
Length |
Value |
|
Length |
USHORT |
Length of the message |
|
Maxlen |
USHORT |
Maximum length of the message |
|
Offset |
DWORD |
Offset of the start of the message |
NTLMSSP Message
|
Field Name |
Length |
Value |
|
NTLMSSP identifier |
Fixed: 8 |
Ascii "NTLMSSP"+0x0 |
|
NTLM message Type |
DWORD |
|
|
Lan Manager Response |
LMO Type |
Binary |
|
NTLM Response |
LMO Type |
Binary |
|
Domain name |
LMO Type |
Unicode w/o NULL termination |
|
User name |
LMO Type |
Unicode w/o NULL termination |
|
Host name |
LMO Type |
Unicode w/o NULL termination |
|
Session Key |
8 Bytes |
|
|
Flags |
DWORD |
|
'리버스 엔지니어링' 카테고리의 다른 글
| 인터넷 개인 정보 뒷조사 도구-말티고(Maltego) (0) | 2007/10/24 |
|---|---|
| Multiple Vulnerabilities in CA ARCserve for Laptops & Desktops (0) | 2007/10/22 |
| Basic NTLMSSP Parsing SchemeLMO TypeNTLMSSP Message (0) | 2007/10/11 |
| Yahoo! Webcam ActiveX 취약점에 대한 디스어셈블리 (0) | 2007/09/25 |
| Norman Sandbox AnalyzerStartupSetting Filename and optionsStartCompletedResults (1) | 2007/09/25 |
| MS 06-074에 대한 Diffing Result (0) | 2007/09/25 |



Prev
Rss Feed