diff options
author | Jeremy Allison <jra@samba.org> | 2010-05-19 10:34:44 -0700 |
---|---|---|
committer | Jeremy Allison <jra@samba.org> | 2010-05-19 10:36:39 -0700 |
commit | b0d7a3d123cb96049dc782b317554448acdae1a2 (patch) | |
tree | 47cd4878580d27edbc85581794f10e1be78e1366 /source3/libsmb | |
parent | ac9341245af38fe019c43ad9e413dbc62e26bc7a (diff) | |
download | samba-b0d7a3d123cb96049dc782b317554448acdae1a2.tar.gz samba-b0d7a3d123cb96049dc782b317554448acdae1a2.tar.bz2 samba-b0d7a3d123cb96049dc782b317554448acdae1a2.zip |
Thanks to Andrew Bartlett's advice, fix the NTLMSSP version problem the correct way.
No more magic blobs :-). Use ndr_push_struct_blob() to
push a properly formatted VERSION struct.
Jeremy.
Diffstat (limited to 'source3/libsmb')
-rw-r--r-- | source3/libsmb/ntlmssp.c | 66 |
1 files changed, 34 insertions, 32 deletions
diff --git a/source3/libsmb/ntlmssp.c b/source3/libsmb/ntlmssp.c index 1f6720c125..2fc8adff83 100644 --- a/source3/libsmb/ntlmssp.c +++ b/source3/libsmb/ntlmssp.c @@ -522,45 +522,47 @@ static NTSTATUS ntlmssp_server_negotiate(struct ntlmssp_state *ntlmssp_state, { /* Marshal the packet in the right format, be it unicode or ASCII */ const char *gen_string; - /* "What Windows returns" as a version number. */ - const char vers[] = { 0x6, 0x1, 0xb0, 0x1d, 0, 0, 0, 0xf}; + DATA_BLOB version_blob = data_blob_null; if (chal_flags & NTLMSSP_NEGOTIATE_VERSION) { - DATA_BLOB version_blob = data_blob_talloc(ntlmssp_state, vers, 8); - - if (ntlmssp_state->unicode) { - gen_string = "CdUdbddBb"; - } else { - gen_string = "CdAdbddBb"; + enum ndr_err_code err; + struct VERSION vers; + + /* "What Windows returns" as a version number. */ + ZERO_STRUCT(vers); + vers.ProductMajorVersion = NTLMSSP_WINDOWS_MAJOR_VERSION_6; + vers.ProductMinorVersion = NTLMSSP_WINDOWS_MINOR_VERSION_1; + vers.ProductBuild = 0; + vers.NTLMRevisionCurrent = NTLMSSP_REVISION_W2K3; + + err = ndr_push_struct_blob(&version_blob, + ntlmssp_state, + &vers, + (ndr_push_flags_fn_t)ndr_push_VERSION); + + if (err) { + return NT_STATUS_NO_MEMORY; } + } - msrpc_gen(ntlmssp_state, reply, gen_string, - "NTLMSSP", - NTLMSSP_CHALLENGE, - target_name, - chal_flags, - cryptkey, 8, - 0, 0, - struct_blob.data, struct_blob.length, - version_blob.data, version_blob.length); - data_blob_free(&version_blob); + if (ntlmssp_state->unicode) { + gen_string = "CdUdbddBb"; } else { - if (ntlmssp_state->unicode) { - gen_string = "CdUdbddB"; - } else { - gen_string = "CdAdbddB"; - } - - msrpc_gen(ntlmssp_state, reply, gen_string, - "NTLMSSP", - NTLMSSP_CHALLENGE, - target_name, - chal_flags, - cryptkey, 8, - 0, 0, - struct_blob.data, struct_blob.length); + gen_string = "CdAdbddBb"; } + msrpc_gen(ntlmssp_state, reply, gen_string, + "NTLMSSP", + NTLMSSP_CHALLENGE, + target_name, + chal_flags, + cryptkey, 8, + 0, 0, + struct_blob.data, struct_blob.length, + version_blob.data, version_blob.length); + + data_blob_free(&version_blob); + if (DEBUGLEVEL >= 10) { if (NT_STATUS_IS_OK(ntlmssp_pull_CHALLENGE_MESSAGE(reply, ntlmssp_state, |