r14701: Allow, with non-default options, NTLMSSP to access the LM session key,
authorAndrew Bartlett <abartlet@samba.org>
Sat, 25 Mar 2006 01:00:37 +0000 (01:00 +0000)
committerGerald (Jerry) Carter <jerry@samba.org>
Wed, 10 Oct 2007 18:59:10 +0000 (13:59 -0500)
commiteb66b26cd18ceef2368506479d90bf7e4f0f83a0
tree3612d2f97fe8257661b3d942c0c1c1049bc5e333
parent3fdc3cf0c224fd4ce923bb0df7e8f175356cecf2
r14701: Allow, with non-default options, NTLMSSP to access the LM session key,
even when not sending the LM response.  Needed to pass the
test_session_key against Win2k3.

Yes, I think this is a security flaw in the use of Win2k3-compatible NTLM.

Andrew Bartlett
(This used to be commit cb6c27b4f29878a6a904f798e228eea05cc658e1)
source4/auth/credentials/credentials_ntlm.c
source4/auth/ntlmssp/ntlmssp_client.c