2004-05-02 08:45:00 +00:00
/*
Unix SMB / CIFS implementation .
Password and authentication handling
2004-05-13 23:16:33 +00:00
Copyright ( C ) Andrew Bartlett < abartlet @ samba . org > 2001 - 2004
Copyright ( C ) Gerald Carter 2003
Copyright ( C ) Luke Kenneth Casson Leighton 1996 - 2000
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-10 02:07:03 +00:00
the Free Software Foundation ; either version 3 of the License , or
2004-05-02 08:45:00 +00:00
( at your option ) any later version .
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
You should have received a copy of the GNU General Public License
2007-07-10 02:07:03 +00:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2004-05-02 08:45:00 +00:00
*/
# include "includes.h"
2019-02-27 08:02:24 +01:00
# include "lib/crypto/md4.h"
2006-03-16 00:23:11 +00:00
# include "librpc/gen_ndr/netlogon.h"
2006-03-14 15:03:25 +00:00
# include "libcli/auth/libcli_auth.h"
2004-05-02 08:45:00 +00:00
/****************************************************************************
Core of smb password checking routine .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2007-10-06 22:16:19 +00:00
static bool smb_pwd_check_ntlmv1 ( TALLOC_CTX * mem_ctx ,
2004-10-08 08:05:11 +00:00
const DATA_BLOB * nt_response ,
2004-06-01 08:30:34 +00:00
const uint8_t * part_passwd ,
2004-05-02 08:45:00 +00:00
const DATA_BLOB * sec_blob ,
DATA_BLOB * user_sess_key )
{
/* Finish the encryption of part_passwd. */
2004-06-01 08:30:34 +00:00
uint8_t p24 [ 24 ] ;
2019-11-08 15:40:01 +01:00
int rc ;
2020-01-03 14:10:00 +01:00
bool ok ;
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
if ( part_passwd = = NULL ) {
DEBUG ( 10 , ( " No password set - DISALLOWING access \n " ) ) ;
/* No password set - always false ! */
2007-10-06 22:16:19 +00:00
return false ;
2004-05-02 08:45:00 +00:00
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
if ( sec_blob - > length ! = 8 ) {
2020-01-03 14:24:13 +01:00
DBG_ERR ( " incorrect challenge size (%zu) \n " , sec_blob - > length ) ;
2007-10-06 22:16:19 +00:00
return false ;
2004-05-02 08:45:00 +00:00
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
if ( nt_response - > length ! = 24 ) {
2020-01-03 14:24:13 +01:00
DBG_ERR ( " incorrect password length (%zu) \n " ,
nt_response - > length ) ;
2007-10-06 22:16:19 +00:00
return false ;
2004-05-02 08:45:00 +00:00
}
2019-11-08 15:40:01 +01:00
rc = SMBOWFencrypt ( part_passwd , sec_blob - > data , p24 ) ;
if ( rc ! = 0 ) {
return false ;
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
# if DEBUG_PASSWORD
DEBUG ( 100 , ( " Part password (P16) was | \n " ) ) ;
dump_data ( 100 , part_passwd , 16 ) ;
DEBUGADD ( 100 , ( " Password from client was | \n " ) ) ;
dump_data ( 100 , nt_response - > data , nt_response - > length ) ;
DEBUGADD ( 100 , ( " Given challenge was | \n " ) ) ;
dump_data ( 100 , sec_blob - > data , sec_blob - > length ) ;
DEBUGADD ( 100 , ( " Value from encryption was | \n " ) ) ;
dump_data ( 100 , p24 , 24 ) ;
# endif
2022-05-11 12:07:43 +12:00
ok = mem_equal_const_time ( p24 , nt_response - > data , 24 ) ;
2020-01-03 14:10:00 +01:00
if ( ! ok ) {
return false ;
}
if ( user_sess_key ! = NULL ) {
* user_sess_key = data_blob_talloc ( mem_ctx , NULL , 16 ) ;
if ( user_sess_key - > data = = NULL ) {
DBG_ERR ( " data_blob_talloc failed \n " ) ;
return false ;
2005-01-06 12:13:31 +00:00
}
2020-01-03 14:10:00 +01:00
SMBsesskeygen_ntv1 ( part_passwd , user_sess_key - > data ) ;
}
return true ;
2004-05-02 08:45:00 +00:00
}
/****************************************************************************
Core of smb password checking routine . ( NTLMv2 , LMv2 )
Note : The same code works with both NTLMv2 and LMv2 .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2007-10-06 22:16:19 +00:00
static bool smb_pwd_check_ntlmv2 ( TALLOC_CTX * mem_ctx ,
2004-10-08 08:05:11 +00:00
const DATA_BLOB * ntv2_response ,
2004-06-01 08:30:34 +00:00
const uint8_t * part_passwd ,
2004-05-02 08:45:00 +00:00
const DATA_BLOB * sec_blob ,
const char * user , const char * domain ,
DATA_BLOB * user_sess_key )
{
/* Finish the encryption of part_passwd. */
2004-06-01 08:30:34 +00:00
uint8_t kr [ 16 ] ;
uint8_t value_from_encryption [ 16 ] ;
2004-05-02 08:45:00 +00:00
DATA_BLOB client_key_data ;
2019-11-13 12:52:44 +01:00
NTSTATUS status ;
2020-01-03 14:10:00 +01:00
bool ok ;
2004-05-02 08:45:00 +00:00
if ( part_passwd = = NULL ) {
DEBUG ( 10 , ( " No password set - DISALLOWING access \n " ) ) ;
2007-10-06 22:16:19 +00:00
/* No password set - always false */
return false ;
2004-05-02 08:45:00 +00:00
}
if ( sec_blob - > length ! = 8 ) {
2020-01-03 14:24:13 +01:00
DBG_ERR ( " incorrect challenge size (%zu) \n " , sec_blob - > length ) ;
2007-10-06 22:16:19 +00:00
return false ;
2004-05-02 08:45:00 +00:00
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
if ( ntv2_response - > length < 24 ) {
/* We MUST have more than 16 bytes, or the stuff below will go
crazy . No known implementation sends less than the 24 bytes
for LMv2 , let alone NTLMv2 . */
2020-01-03 14:24:13 +01:00
DBG_ERR ( " incorrect password length (%zu) \n " ,
ntv2_response - > length ) ;
2007-10-06 22:16:19 +00:00
return false ;
2004-05-02 08:45:00 +00:00
}
2004-10-08 08:05:11 +00:00
client_key_data = data_blob_talloc ( mem_ctx , ntv2_response - > data + 16 , ntv2_response - > length - 16 ) ;
2004-05-02 08:45:00 +00:00
/*
todo : should we be checking this for anything ? We can ' t for LMv2 ,
but for NTLMv2 it is meant to contain the current time etc .
*/
2012-08-23 16:02:09 -07:00
if ( ! ntv2_owf_gen ( part_passwd , user , domain , kr ) ) {
2007-10-06 22:16:19 +00:00
return false ;
2004-05-02 08:45:00 +00:00
}
2019-11-13 12:52:44 +01:00
status = SMBOWFencrypt_ntv2 ( kr ,
sec_blob ,
& client_key_data ,
value_from_encryption ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return false ;
}
2004-05-02 08:45:00 +00:00
# if DEBUG_PASSWORD
DEBUG ( 100 , ( " Part password (P16) was | \n " ) ) ;
dump_data ( 100 , part_passwd , 16 ) ;
DEBUGADD ( 100 , ( " Password from client was | \n " ) ) ;
dump_data ( 100 , ntv2_response - > data , ntv2_response - > length ) ;
DEBUGADD ( 100 , ( " Variable data from client was | \n " ) ) ;
dump_data ( 100 , client_key_data . data , client_key_data . length ) ;
DEBUGADD ( 100 , ( " Given challenge was | \n " ) ) ;
dump_data ( 100 , sec_blob - > data , sec_blob - > length ) ;
DEBUGADD ( 100 , ( " Value from encryption was | \n " ) ) ;
dump_data ( 100 , value_from_encryption , 16 ) ;
# endif
data_blob_clear_free ( & client_key_data ) ;
2020-01-03 14:10:00 +01:00
2022-05-11 12:07:43 +12:00
ok = mem_equal_const_time ( value_from_encryption , ntv2_response - > data , 16 ) ;
2020-01-03 14:10:00 +01:00
if ( ! ok ) {
return false ;
}
if ( user_sess_key ! = NULL ) {
* user_sess_key = data_blob_talloc ( mem_ctx , NULL , 16 ) ;
if ( user_sess_key - > data = = NULL ) {
DBG_ERR ( " data_blob_talloc failed \n " ) ;
return false ;
}
status = SMBsesskeygen_ntv2 (
kr , value_from_encryption , user_sess_key - > data ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return false ;
2005-01-06 12:13:31 +00:00
}
}
2020-01-03 14:10:00 +01:00
return true ;
2005-01-06 12:13:31 +00:00
}
/****************************************************************************
Core of smb password checking routine . ( NTLMv2 , LMv2 )
Note : The same code works with both NTLMv2 and LMv2 .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2007-10-06 22:16:19 +00:00
static bool smb_sess_key_ntlmv2 ( TALLOC_CTX * mem_ctx ,
2005-01-06 12:13:31 +00:00
const DATA_BLOB * ntv2_response ,
const uint8_t * part_passwd ,
const DATA_BLOB * sec_blob ,
const char * user , const char * domain ,
DATA_BLOB * user_sess_key )
{
/* Finish the encryption of part_passwd. */
uint8_t kr [ 16 ] ;
uint8_t value_from_encryption [ 16 ] ;
DATA_BLOB client_key_data ;
2019-11-13 12:45:04 +01:00
NTSTATUS status ;
2005-01-06 12:13:31 +00:00
if ( part_passwd = = NULL ) {
DEBUG ( 10 , ( " No password set - DISALLOWING access \n " ) ) ;
2007-10-06 22:16:19 +00:00
/* No password set - always false */
return false ;
2005-01-06 12:13:31 +00:00
}
if ( sec_blob - > length ! = 8 ) {
2020-01-03 14:24:13 +01:00
DBG_ERR ( " incorrect challenge size (%zu) \n " , sec_blob - > length ) ;
2007-10-06 22:16:19 +00:00
return false ;
2005-01-06 12:13:31 +00:00
}
2010-09-13 11:08:40 +02:00
2005-01-06 12:13:31 +00:00
if ( ntv2_response - > length < 24 ) {
/* We MUST have more than 16 bytes, or the stuff below will go
crazy . No known implementation sends less than the 24 bytes
for LMv2 , let alone NTLMv2 . */
2020-01-03 14:24:13 +01:00
DBG_ERR ( " incorrect password length (%zu) \n " ,
ntv2_response - > length ) ;
2007-10-06 22:16:19 +00:00
return false ;
2005-01-06 12:13:31 +00:00
}
client_key_data = data_blob_talloc ( mem_ctx , ntv2_response - > data + 16 , ntv2_response - > length - 16 ) ;
2012-08-23 16:02:09 -07:00
if ( ! ntv2_owf_gen ( part_passwd , user , domain , kr ) ) {
2007-10-06 22:16:19 +00:00
return false ;
2005-01-06 12:13:31 +00:00
}
2019-11-13 12:52:44 +01:00
status = SMBOWFencrypt_ntv2 ( kr ,
sec_blob ,
& client_key_data ,
value_from_encryption ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return false ;
}
2005-01-06 12:13:31 +00:00
* user_sess_key = data_blob_talloc ( mem_ctx , NULL , 16 ) ;
2020-01-03 14:04:02 +01:00
if ( user_sess_key - > data = = NULL ) {
DBG_ERR ( " data_blob_talloc failed \n " ) ;
return false ;
}
2019-11-13 12:45:04 +01:00
status = SMBsesskeygen_ntv2 ( kr ,
value_from_encryption ,
user_sess_key - > data ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
return false ;
}
2007-10-06 22:16:19 +00:00
return true ;
2004-05-02 08:45:00 +00:00
}
/**
2005-07-22 04:10:07 +00:00
* Compare password hashes against those from the SAM
2004-05-02 08:45:00 +00:00
*
* @ param mem_ctx talloc context
2005-07-22 04:10:07 +00:00
* @ param client_lanman LANMAN password hash , as supplied by the client
* @ param client_nt NT ( MD4 ) password hash , as supplied by the client
2004-05-02 08:45:00 +00:00
* @ param username internal Samba username , for log messages
* @ param client_username username the client used
* @ param client_domain domain name the client used ( may be mapped )
2005-07-22 04:10:07 +00:00
* @ param stored_lanman LANMAN password hash , as stored on the SAM
* @ param stored_nt NT ( MD4 ) password hash , as stored on the SAM
2004-05-02 08:45:00 +00:00
* @ param user_sess_key User session key
* @ param lm_sess_key LM session key ( first 8 bytes of the LM hash )
*/
2005-07-22 04:10:07 +00:00
NTSTATUS hash_password_check ( TALLOC_CTX * mem_ctx ,
2010-08-26 20:08:15 +02:00
bool lanman_auth ,
2022-05-19 16:45:55 +12:00
enum ntlm_auth_level ntlm_auth ,
2005-07-22 04:10:07 +00:00
const struct samr_Password * client_lanman ,
const struct samr_Password * client_nt ,
2004-05-02 08:45:00 +00:00
const char * username ,
2005-07-22 04:10:07 +00:00
const struct samr_Password * stored_lanman ,
2005-08-20 05:59:27 +00:00
const struct samr_Password * stored_nt )
2004-05-02 08:45:00 +00:00
{
2022-05-19 16:45:55 +12:00
if ( ntlm_auth = = NTLM_AUTH_DISABLED ) {
DBG_WARNING ( " hash_password_check: NTLM authentication not "
" permitted by configuration. \n " ) ;
return NT_STATUS_NTLM_BLOCKED ;
}
2005-07-22 04:10:07 +00:00
if ( stored_nt = = NULL ) {
2018-03-14 15:36:05 +01:00
DEBUG ( 3 , ( " hash_password_check: NO NT password stored for user %s. \n " ,
2004-05-02 08:45:00 +00:00
username ) ) ;
}
2005-07-22 04:10:07 +00:00
if ( client_nt & & stored_nt ) {
2022-05-11 12:07:43 +12:00
if ( mem_equal_const_time ( client_nt - > hash , stored_nt - > hash , sizeof ( stored_nt - > hash ) ) ) {
2004-05-02 08:45:00 +00:00
return NT_STATUS_OK ;
} else {
2018-03-14 15:36:05 +01:00
DEBUG ( 3 , ( " hash_password_check: Interactive logon: NT password check failed for user %s \n " ,
2004-05-02 08:45:00 +00:00
username ) ) ;
return NT_STATUS_WRONG_PASSWORD ;
}
2005-07-22 04:10:07 +00:00
} else if ( client_lanman & & stored_lanman ) {
2008-11-01 17:55:57 +01:00
if ( ! lanman_auth ) {
2018-03-14 15:36:05 +01:00
DEBUG ( 3 , ( " hash_password_check: Interactive logon: only LANMAN password supplied for user %s, and LM passwords are disabled! \n " ,
2004-05-02 08:45:00 +00:00
username ) ) ;
return NT_STATUS_WRONG_PASSWORD ;
}
2005-10-28 11:20:48 +00:00
if ( strchr_m ( username , ' @ ' ) ) {
return NT_STATUS_NOT_FOUND ;
}
2004-05-02 08:45:00 +00:00
2022-05-11 12:07:43 +12:00
if ( mem_equal_const_time ( client_lanman - > hash , stored_lanman - > hash , sizeof ( stored_lanman - > hash ) ) ) {
2004-05-02 08:45:00 +00:00
return NT_STATUS_OK ;
} else {
2018-03-14 15:36:05 +01:00
DEBUG ( 3 , ( " hash_password_check: Interactive logon: LANMAN password check failed for user %s \n " ,
2004-05-02 08:45:00 +00:00
username ) ) ;
return NT_STATUS_WRONG_PASSWORD ;
}
}
2005-10-28 11:20:48 +00:00
if ( strchr_m ( username , ' @ ' ) ) {
return NT_STATUS_NOT_FOUND ;
}
2005-07-22 04:10:07 +00:00
return NT_STATUS_WRONG_PASSWORD ;
}
/**
* Check a challenge - response password against the value of the NT or
* LM password hash .
*
* @ param mem_ctx talloc context
* @ param challenge 8 - byte challenge . If all zero , forces plaintext comparison
* @ param nt_response ' unicode ' NT response to the challenge , or unicode password
* @ param lm_response ASCII or LANMAN response to the challenge , or password in DOS code page
* @ param username internal Samba username , for log messages
* @ param client_username username the client used
* @ param client_domain domain name the client used ( may be mapped )
* @ param stored_lanman LANMAN ASCII password from our passdb or similar
* @ param stored_nt MD4 unicode password from our passdb or similar
* @ param user_sess_key User session key
* @ param lm_sess_key LM session key ( first 8 bytes of the LM hash )
*/
NTSTATUS ntlm_password_check ( TALLOC_CTX * mem_ctx ,
2010-08-26 20:08:15 +02:00
bool lanman_auth ,
2017-07-03 12:11:51 +12:00
enum ntlm_auth_level ntlm_auth ,
2005-10-28 08:54:37 +00:00
uint32_t logon_parameters ,
2005-07-22 04:10:07 +00:00
const DATA_BLOB * challenge ,
const DATA_BLOB * lm_response ,
const DATA_BLOB * nt_response ,
const char * username ,
const char * client_username ,
const char * client_domain ,
const struct samr_Password * stored_lanman ,
const struct samr_Password * stored_nt ,
DATA_BLOB * user_sess_key ,
DATA_BLOB * lm_sess_key )
{
DATA_BLOB tmp_sess_key ;
2012-08-23 15:46:16 -07:00
const char * upper_client_domain = NULL ;
2017-07-03 14:16:50 +12:00
if ( ntlm_auth = = NTLM_AUTH_DISABLED ) {
DBG_WARNING ( " ntlm_password_check: NTLM authentication not "
" permitted by configuration. \n " ) ;
return NT_STATUS_NTLM_BLOCKED ;
}
2012-08-23 15:46:16 -07:00
if ( client_domain ! = NULL ) {
upper_client_domain = talloc_strdup_upper ( mem_ctx , client_domain ) ;
if ( upper_client_domain = = NULL ) {
return NT_STATUS_NO_MEMORY ;
}
}
2005-07-22 04:10:07 +00:00
if ( stored_nt = = NULL ) {
DEBUG ( 3 , ( " ntlm_password_check: NO NT password stored for user %s. \n " ,
username ) ) ;
}
2005-08-20 05:59:27 +00:00
* lm_sess_key = data_blob ( NULL , 0 ) ;
* user_sess_key = data_blob ( NULL , 0 ) ;
2004-05-02 08:45:00 +00:00
/* Check for cleartext netlogon. Used by Exchange 5.5. */
2005-10-28 08:54:37 +00:00
if ( ( logon_parameters & MSV1_0_CLEARTEXT_PASSWORD_ALLOWED )
2016-12-31 12:45:51 +00:00
& & challenge - > length = = 8
& & ( all_zero ( challenge - > data , challenge - > length ) ) ) {
2005-08-20 05:59:27 +00:00
struct samr_Password client_nt ;
struct samr_Password client_lm ;
2005-10-29 11:11:05 +00:00
char * unix_pw = NULL ;
2007-10-06 22:16:19 +00:00
bool lm_ok ;
2011-03-29 11:16:26 -07:00
size_t converted_size = 0 ;
2004-05-02 08:45:00 +00:00
DEBUG ( 4 , ( " ntlm_password_check: checking plaintext passwords for user %s \n " ,
username ) ) ;
2005-08-20 05:59:27 +00:00
mdfour ( client_nt . hash , nt_response - > data , nt_response - > length ) ;
2010-09-13 11:08:40 +02:00
2005-10-29 11:11:05 +00:00
if ( lm_response - > length & &
2008-11-01 17:55:57 +01:00
( convert_string_talloc ( mem_ctx , CH_DOS , CH_UNIX ,
2005-10-29 11:11:05 +00:00
lm_response - > data , lm_response - > length ,
2023-08-09 16:52:31 +12:00
& unix_pw , & converted_size ) ) ) {
2005-10-29 11:11:05 +00:00
if ( E_deshash ( unix_pw , client_lm . hash ) ) {
2007-10-06 22:16:19 +00:00
lm_ok = true ;
2005-10-29 11:11:05 +00:00
} else {
2007-10-06 22:16:19 +00:00
lm_ok = false ;
2005-10-29 11:11:05 +00:00
}
} else {
2007-10-06 22:16:19 +00:00
lm_ok = false ;
2005-10-29 11:11:05 +00:00
}
2005-10-28 11:20:48 +00:00
return hash_password_check ( mem_ctx ,
2008-11-01 17:55:57 +01:00
lanman_auth ,
2022-05-19 16:45:55 +12:00
ntlm_auth ,
2005-10-29 11:11:05 +00:00
lm_ok ? & client_lm : NULL ,
2005-10-28 11:20:48 +00:00
nt_response - > length ? & client_nt : NULL ,
2005-08-20 05:59:27 +00:00
username ,
stored_lanman , stored_nt ) ;
2004-05-02 08:45:00 +00:00
}
if ( nt_response - > length ! = 0 & & nt_response - > length < 24 ) {
2020-01-03 14:24:13 +01:00
DBG_NOTICE ( " invalid NT password length (%zu) for user %s \n " ,
nt_response - > length ,
username ) ;
2004-05-02 08:45:00 +00:00
}
2010-09-13 11:08:40 +02:00
2005-07-22 04:10:07 +00:00
if ( nt_response - > length > 24 & & stored_nt ) {
2005-01-03 06:23:02 +00:00
/* We have the NT MD4 hash challenge available - see if we can
use it
*/
2012-08-23 15:46:16 -07:00
DEBUG ( 4 , ( " ntlm_password_check: Checking NTLMv2 password with domain [%s] \n " ,
client_domain ? client_domain : " <NULL> " ) ) ;
2005-01-03 06:23:02 +00:00
if ( smb_pwd_check_ntlmv2 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2005-01-03 06:23:02 +00:00
client_username ,
client_domain ,
user_sess_key ) ) {
2005-08-20 05:59:27 +00:00
if ( user_sess_key - > length ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , user_sess_key - > data , MIN ( 8 , user_sess_key - > length ) ) ;
2004-05-02 08:45:00 +00:00
}
2005-01-03 06:23:02 +00:00
return NT_STATUS_OK ;
}
2010-09-13 11:08:40 +02:00
2012-08-23 15:46:16 -07:00
DEBUG ( 4 , ( " ntlm_password_check: Checking NTLMv2 password with uppercased version of domain [%s] \n " ,
upper_client_domain ? upper_client_domain : " <NULL> " ) ) ;
2005-01-03 06:23:02 +00:00
if ( smb_pwd_check_ntlmv2 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2005-01-03 06:23:02 +00:00
client_username ,
2012-08-23 15:46:16 -07:00
upper_client_domain ,
2005-01-03 06:23:02 +00:00
user_sess_key ) ) {
2005-08-20 05:59:27 +00:00
if ( user_sess_key - > length ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , user_sess_key - > data , MIN ( 8 , user_sess_key - > length ) ) ;
2004-05-02 08:45:00 +00:00
}
2005-01-03 06:23:02 +00:00
return NT_STATUS_OK ;
}
2010-09-13 11:08:40 +02:00
2005-01-03 06:23:02 +00:00
DEBUG ( 4 , ( " ntlm_password_check: Checking NTLMv2 password without a domain \n " ) ) ;
if ( smb_pwd_check_ntlmv2 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2005-01-03 06:23:02 +00:00
client_username ,
" " ,
user_sess_key ) ) {
2005-08-20 05:59:27 +00:00
if ( user_sess_key - > length ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , user_sess_key - > data , MIN ( 8 , user_sess_key - > length ) ) ;
2004-05-02 08:45:00 +00:00
}
2005-01-03 06:23:02 +00:00
return NT_STATUS_OK ;
} else {
DEBUG ( 3 , ( " ntlm_password_check: NTLMv2 password check failed \n " ) ) ;
2004-05-02 08:45:00 +00:00
}
2005-07-22 04:10:07 +00:00
} else if ( nt_response - > length = = 24 & & stored_nt ) {
2017-07-03 12:11:51 +12:00
if ( ntlm_auth = = NTLM_AUTH_ON
| | ( ntlm_auth = = NTLM_AUTH_MSCHAPv2_NTLMV2_ONLY & & ( logon_parameters & MSV1_0_ALLOW_MSVCHAPV2 ) ) ) {
2004-05-02 08:45:00 +00:00
/* We have the NT MD4 hash challenge available - see if we can
use it ( ie . does it exist in the smbpasswd file ) .
*/
DEBUG ( 4 , ( " ntlm_password_check: Checking NT MD4 password \n " ) ) ;
2004-10-08 08:05:11 +00:00
if ( smb_pwd_check_ntlmv1 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2004-05-02 08:45:00 +00:00
user_sess_key ) ) {
/* The LM session key for this response is not very secure,
so use it only if we otherwise allow LM authentication */
2010-09-13 11:08:40 +02:00
2008-11-01 17:55:57 +01:00
if ( lanman_auth & & stored_lanman ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , stored_lanman - > hash , MIN ( 8 , user_sess_key - > length ) ) ;
2004-05-02 08:45:00 +00:00
}
return NT_STATUS_OK ;
} else {
DEBUG ( 3 , ( " ntlm_password_check: NT MD4 password check failed for user %s \n " ,
username ) ) ;
return NT_STATUS_WRONG_PASSWORD ;
}
} else {
DEBUG ( 2 , ( " ntlm_password_check: NTLMv1 passwords NOT PERMITTED for user %s \n " ,
username ) ) ;
2010-03-03 16:03:13 +01:00
/* no return, because we might pick up LMv2 in the LM field */
2004-05-02 08:45:00 +00:00
}
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
if ( lm_response - > length = = 0 ) {
DEBUG ( 3 , ( " ntlm_password_check: NEITHER LanMan nor NT password supplied for user %s \n " ,
username ) ) ;
return NT_STATUS_WRONG_PASSWORD ;
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
if ( lm_response - > length < 24 ) {
2020-01-03 14:24:13 +01:00
DBG_NOTICE ( " invalid LanMan password length (%zu) for "
" user %s \n " ,
nt_response - > length , username ) ;
2004-05-02 08:45:00 +00:00
return NT_STATUS_WRONG_PASSWORD ;
}
2010-09-13 11:08:40 +02:00
2008-11-01 17:55:57 +01:00
if ( ! lanman_auth ) {
2004-05-02 08:45:00 +00:00
DEBUG ( 3 , ( " ntlm_password_check: Lanman passwords NOT PERMITTED for user %s \n " ,
username ) ) ;
2005-07-22 04:10:07 +00:00
} else if ( ! stored_lanman ) {
2004-05-02 08:45:00 +00:00
DEBUG ( 3 , ( " ntlm_password_check: NO LanMan password set for user %s (and no NT password supplied) \n " ,
username ) ) ;
2005-10-28 11:20:48 +00:00
} else if ( strchr_m ( username , ' @ ' ) ) {
DEBUG ( 3 , ( " ntlm_password_check: NO LanMan password allowed for username@realm logins (user: %s) \n " ,
username ) ) ;
2004-05-02 08:45:00 +00:00
} else {
DEBUG ( 4 , ( " ntlm_password_check: Checking LM password \n " ) ) ;
2004-10-08 08:05:11 +00:00
if ( smb_pwd_check_ntlmv1 ( mem_ctx ,
lm_response ,
2005-07-22 04:10:07 +00:00
stored_lanman - > hash , challenge ,
2004-05-02 08:45:00 +00:00
NULL ) ) {
2004-06-07 22:17:51 +00:00
/* The session key for this response is still very odd.
It not very secure , so use it only if we otherwise
allow LM authentication */
2008-11-01 17:55:57 +01:00
if ( lanman_auth & & stored_lanman ) {
2004-06-07 22:17:51 +00:00
uint8_t first_8_lm_hash [ 16 ] ;
2005-07-22 04:10:07 +00:00
memcpy ( first_8_lm_hash , stored_lanman - > hash , 8 ) ;
2004-06-07 22:17:51 +00:00
memset ( first_8_lm_hash + 8 , ' \0 ' , 8 ) ;
2004-10-08 08:05:11 +00:00
* user_sess_key = data_blob_talloc ( mem_ctx , first_8_lm_hash , 16 ) ;
2005-07-22 04:10:07 +00:00
* lm_sess_key = data_blob_talloc ( mem_ctx , stored_lanman - > hash , 8 ) ;
2004-06-07 22:17:51 +00:00
}
2004-05-02 08:45:00 +00:00
return NT_STATUS_OK ;
}
}
2010-09-13 11:08:40 +02:00
2005-07-22 04:10:07 +00:00
if ( ! stored_nt ) {
2004-05-02 08:45:00 +00:00
DEBUG ( 4 , ( " ntlm_password_check: LM password check failed for user, no NT password %s \n " , username ) ) ;
return NT_STATUS_WRONG_PASSWORD ;
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
/* This is for 'LMv2' authentication. almost NTLMv2 but limited to 24 bytes.
- related to Win9X , legacy NAS pass - though authentication
*/
2012-08-23 15:46:16 -07:00
DEBUG ( 4 , ( " ntlm_password_check: Checking LMv2 password with domain %s \n " ,
client_domain ? client_domain : " <NULL> " ) ) ;
2004-10-08 08:05:11 +00:00
if ( smb_pwd_check_ntlmv2 ( mem_ctx ,
lm_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2004-10-08 08:05:11 +00:00
client_username ,
client_domain ,
2005-01-06 12:13:31 +00:00
& tmp_sess_key ) ) {
if ( nt_response - > length > 24 ) {
2014-03-30 04:01:06 +02:00
/* If NTLMv2 authentication has preceded us
2005-01-06 12:13:31 +00:00
* ( even if it failed ) , then use the session
* key from that . See the RPC - SAMLOGON
* torture test */
smb_sess_key_ntlmv2 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2005-01-06 12:13:31 +00:00
client_username ,
client_domain ,
user_sess_key ) ;
2005-08-20 05:59:27 +00:00
} else {
2005-01-06 12:13:31 +00:00
/* Otherwise, use the LMv2 session key */
* user_sess_key = tmp_sess_key ;
}
2005-08-20 05:59:27 +00:00
if ( user_sess_key - > length ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , user_sess_key - > data , MIN ( 8 , user_sess_key - > length ) ) ;
2005-01-03 06:23:02 +00:00
}
2004-05-02 08:45:00 +00:00
return NT_STATUS_OK ;
}
2010-09-13 11:08:40 +02:00
2012-08-23 15:46:16 -07:00
DEBUG ( 4 , ( " ntlm_password_check: Checking LMv2 password with upper-cased version of domain %s \n " ,
upper_client_domain ? upper_client_domain : " <NULL> " ) ) ;
2004-10-08 08:05:11 +00:00
if ( smb_pwd_check_ntlmv2 ( mem_ctx ,
lm_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2004-10-08 08:05:11 +00:00
client_username ,
2012-08-23 15:46:16 -07:00
upper_client_domain ,
2005-01-06 12:13:31 +00:00
& tmp_sess_key ) ) {
if ( nt_response - > length > 24 ) {
2014-03-30 04:01:06 +02:00
/* If NTLMv2 authentication has preceded us
2005-01-06 12:13:31 +00:00
* ( even if it failed ) , then use the session
* key from that . See the RPC - SAMLOGON
* torture test */
smb_sess_key_ntlmv2 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2005-01-06 12:13:31 +00:00
client_username ,
2012-08-23 15:46:16 -07:00
upper_client_domain ,
2005-01-06 12:13:31 +00:00
user_sess_key ) ;
2005-08-20 05:59:27 +00:00
} else {
2005-01-06 12:13:31 +00:00
/* Otherwise, use the LMv2 session key */
* user_sess_key = tmp_sess_key ;
}
2005-08-20 05:59:27 +00:00
if ( user_sess_key - > length ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , user_sess_key - > data , MIN ( 8 , user_sess_key - > length ) ) ;
2005-01-03 06:23:02 +00:00
}
2004-05-02 08:45:00 +00:00
return NT_STATUS_OK ;
}
2010-09-13 11:08:40 +02:00
2004-05-02 08:45:00 +00:00
DEBUG ( 4 , ( " ntlm_password_check: Checking LMv2 password without a domain \n " ) ) ;
2004-10-08 08:05:11 +00:00
if ( smb_pwd_check_ntlmv2 ( mem_ctx ,
lm_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2004-10-08 08:05:11 +00:00
client_username ,
" " ,
2005-01-06 12:13:31 +00:00
& tmp_sess_key ) ) {
if ( nt_response - > length > 24 ) {
2014-03-30 04:01:06 +02:00
/* If NTLMv2 authentication has preceded us
2005-01-06 12:13:31 +00:00
* ( even if it failed ) , then use the session
* key from that . See the RPC - SAMLOGON
* torture test */
smb_sess_key_ntlmv2 ( mem_ctx ,
nt_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2005-01-06 12:13:31 +00:00
client_username ,
" " ,
user_sess_key ) ;
2005-08-20 05:59:27 +00:00
} else {
2005-01-06 12:13:31 +00:00
/* Otherwise, use the LMv2 session key */
* user_sess_key = tmp_sess_key ;
}
2005-08-20 05:59:27 +00:00
if ( user_sess_key - > length ) {
2009-04-20 10:54:57 +02:00
* lm_sess_key = data_blob_talloc ( mem_ctx , user_sess_key - > data , MIN ( 8 , user_sess_key - > length ) ) ;
2005-01-03 06:23:02 +00:00
}
2004-05-02 08:45:00 +00:00
return NT_STATUS_OK ;
}
/* Apparently NT accepts NT responses in the LM field
- I think this is related to Win9X pass - though authentication
*/
DEBUG ( 4 , ( " ntlm_password_check: Checking NT MD4 password in LM field \n " ) ) ;
2018-03-13 16:56:20 +01:00
if ( ntlm_auth = = NTLM_AUTH_ON ) {
2004-10-08 08:05:11 +00:00
if ( smb_pwd_check_ntlmv1 ( mem_ctx ,
lm_response ,
2005-07-22 04:10:07 +00:00
stored_nt - > hash , challenge ,
2004-05-02 08:45:00 +00:00
NULL ) ) {
/* The session key for this response is still very odd.
It not very secure , so use it only if we otherwise
allow LM authentication */
2008-11-01 17:55:57 +01:00
if ( lanman_auth & & stored_lanman ) {
2004-05-25 17:50:17 +00:00
uint8_t first_8_lm_hash [ 16 ] ;
2005-07-22 04:10:07 +00:00
memcpy ( first_8_lm_hash , stored_lanman - > hash , 8 ) ;
2004-05-02 08:45:00 +00:00
memset ( first_8_lm_hash + 8 , ' \0 ' , 8 ) ;
2004-10-08 08:05:11 +00:00
* user_sess_key = data_blob_talloc ( mem_ctx , first_8_lm_hash , 16 ) ;
2005-07-22 04:10:07 +00:00
* lm_sess_key = data_blob_talloc ( mem_ctx , stored_lanman - > hash , 8 ) ;
2004-05-02 08:45:00 +00:00
}
return NT_STATUS_OK ;
}
DEBUG ( 3 , ( " ntlm_password_check: LM password, NT MD4 password in LM field and LMv2 failed for user %s \n " , username ) ) ;
} else {
DEBUG ( 3 , ( " ntlm_password_check: LM password and LMv2 failed for user %s, and NT MD4 password in LM field not permitted \n " , username ) ) ;
}
2005-10-28 11:20:48 +00:00
/* Try and match error codes */
if ( strchr_m ( username , ' @ ' ) ) {
return NT_STATUS_NOT_FOUND ;
}
2004-05-02 08:45:00 +00:00
return NT_STATUS_WRONG_PASSWORD ;
}