2 Unix SMB/Netbios implementation.
4 Password cacheing. obfuscation is planned
5 Copyright (C) Luke Kenneth Casson Leighton 1996-1998
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 2 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program; if not, write to the Free Software
19 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
24 extern int DEBUGLEVEL;
27 /****************************************************************************
28 initialises a password structure
29 ****************************************************************************/
30 void pwd_init(struct pwd_info *pwd)
32 bzero(pwd->password , sizeof(pwd->password ));
33 bzero(pwd->smb_lm_pwd, sizeof(pwd->smb_lm_pwd));
34 bzero(pwd->smb_nt_pwd, sizeof(pwd->smb_nt_pwd));
35 bzero(pwd->smb_lm_owf, sizeof(pwd->smb_lm_owf));
36 bzero(pwd->smb_nt_owf, sizeof(pwd->smb_nt_owf));
37 bzero(pwd->sess_key , sizeof(pwd->sess_key ));
40 pwd->null_pwd = True; /* safest option... */
41 pwd->cleartext = False;
45 /****************************************************************************
46 de-obfuscates a password
47 ****************************************************************************/
48 static void pwd_deobfuscate(struct pwd_info *pwd)
52 /****************************************************************************
54 ****************************************************************************/
55 static void pwd_obfuscate(struct pwd_info *pwd)
59 /****************************************************************************
60 sets the obfuscation key info
61 ****************************************************************************/
62 void pwd_obfuscate_key(struct pwd_info *pwd, uint32 int_key, char *str_key)
66 /****************************************************************************
68 ****************************************************************************/
69 void pwd_read(struct pwd_info *pwd, char *passwd_report, BOOL do_encrypt)
76 user_pass = (char*)getpass(passwd_report);
78 if (user_pass == NULL || user_pass[0] == 0)
84 pwd_make_lm_nt_16(pwd, user_pass);
88 pwd_set_cleartext(pwd, user_pass);
92 /****************************************************************************
93 stores a cleartext password
94 ****************************************************************************/
95 void pwd_set_nullpwd(struct pwd_info *pwd)
99 pwd->cleartext = False;
100 pwd->null_pwd = True;
101 pwd->crypted = False;
104 /****************************************************************************
105 stores a cleartext password
106 ****************************************************************************/
107 void pwd_set_cleartext(struct pwd_info *pwd, char *clr)
110 fstrcpy(pwd->password, clr);
111 pwd->cleartext = True;
112 pwd->null_pwd = False;
113 pwd->crypted = False;
118 /****************************************************************************
119 gets a cleartext password
120 ****************************************************************************/
121 void pwd_get_cleartext(struct pwd_info *pwd, char *clr)
123 pwd_deobfuscate(pwd);
126 fstrcpy(clr, pwd->password);
135 /****************************************************************************
136 stores lm and nt hashed passwords
137 ****************************************************************************/
138 void pwd_set_lm_nt_16(struct pwd_info *pwd, uchar lm_pwd[16], uchar nt_pwd[16])
144 memcpy(pwd->smb_lm_pwd, lm_pwd, 16);
148 bzero(pwd->smb_lm_pwd, 16);
153 memcpy(pwd->smb_nt_pwd, nt_pwd, 16);
157 bzero(pwd->smb_nt_pwd, 16);
160 pwd->null_pwd = False;
161 pwd->cleartext = False;
162 pwd->crypted = False;
167 /****************************************************************************
168 gets lm and nt hashed passwords
169 ****************************************************************************/
170 void pwd_get_lm_nt_16(struct pwd_info *pwd, uchar lm_pwd[16], uchar nt_pwd[16])
172 pwd_deobfuscate(pwd);
175 memcpy(lm_pwd, pwd->smb_lm_pwd, 16);
179 memcpy(nt_pwd, pwd->smb_nt_pwd, 16);
184 /****************************************************************************
185 makes lm and nt hashed passwords
186 ****************************************************************************/
187 void pwd_make_lm_nt_16(struct pwd_info *pwd, char *clr)
191 nt_lm_owf_gen(clr, pwd->smb_nt_pwd, pwd->smb_lm_pwd);
192 pwd->null_pwd = False;
193 pwd->cleartext = False;
194 pwd->crypted = False;
199 /****************************************************************************
200 makes lm and nt OWF crypts
201 ****************************************************************************/
202 void pwd_make_lm_nt_owf2(struct pwd_info *pwd, const uchar srv_key[8],
203 const char *user, const char *server, const char *domain)
207 DEBUG(10,("pwd_make_lm_nt_owf2: user %s, srv %s, dom %s\n",
208 user, server, domain));
210 pwd_deobfuscate(pwd);
212 SMBgenclientchals(pwd->lm_cli_chal,
214 &pwd->nt_cli_chal_len,
217 ntv2_owf_gen(pwd->smb_nt_pwd, user, domain, kr);
220 SMBOWFencrypt_ntv2(kr,
224 memcpy(&pwd->smb_lm_owf[16], pwd->lm_cli_chal, 8);
227 SMBOWFencrypt_ntv2(kr,
229 pwd->nt_cli_chal, pwd->nt_cli_chal_len,
231 memcpy(&pwd->smb_nt_owf[16], pwd->nt_cli_chal, pwd->nt_cli_chal_len);
232 pwd->nt_owf_len = pwd->nt_cli_chal_len + 16;
234 SMBsesskeygen_ntv2(kr, pwd->smb_nt_owf, pwd->sess_key);
239 #ifdef DEBUG_PASSWORD
240 DEBUG(100,("server cryptkey: "));
241 dump_data(100, srv_key, 8);
243 DEBUG(100,("client lmv2 cryptkey: "));
244 dump_data(100, pwd->lm_cli_chal, 8);
246 DEBUG(100,("client ntv2 cryptkey: "));
247 dump_data(100, pwd->nt_cli_chal, pwd->nt_cli_chal_len);
249 DEBUG(100,("ntv2_owf_passwd: "));
250 dump_data(100, pwd->smb_nt_owf, pwd->nt_owf_len);
251 DEBUG(100,("nt_sess_pwd: "));
252 dump_data(100, pwd->smb_nt_pwd, sizeof(pwd->smb_nt_pwd));
254 DEBUG(100,("lmv2_owf_passwd: "));
255 dump_data(100, pwd->smb_lm_owf, sizeof(pwd->smb_lm_owf));
256 DEBUG(100,("lm_sess_pwd: "));
257 dump_data(100, pwd->smb_lm_pwd, sizeof(pwd->smb_lm_pwd));
259 DEBUG(100,("session key:\n"));
260 dump_data(100, pwd->sess_key, sizeof(pwd->sess_key));
267 /****************************************************************************
268 makes lm and nt OWF crypts
269 ****************************************************************************/
270 void pwd_make_lm_nt_owf(struct pwd_info *pwd, uchar cryptkey[8])
274 #ifdef DEBUG_PASSWORD
275 DEBUG(100,("pwd_make_lm_nt_owf: NULL password\n"));
280 pwd_deobfuscate(pwd);
282 /* generate 24-byte hashes */
283 SMBOWFencrypt(pwd->smb_lm_pwd, cryptkey, pwd->smb_lm_owf);
284 SMBOWFencrypt(pwd->smb_nt_pwd, cryptkey, pwd->smb_nt_owf);
285 pwd->nt_owf_len = 24;
287 SMBsesskeygen_ntv1(pwd->smb_nt_pwd, pwd->smb_nt_owf, pwd->sess_key);
289 #ifdef DEBUG_PASSWORD
290 DEBUG(100,("client cryptkey: "));
291 dump_data(100, cryptkey, 8);
293 DEBUG(100,("nt_owf_passwd: "));
294 dump_data(100, pwd->smb_nt_owf, pwd->nt_owf_len);
295 DEBUG(100,("nt_sess_pwd: "));
296 dump_data(100, pwd->smb_nt_pwd, sizeof(pwd->smb_nt_pwd));
298 DEBUG(100,("lm_owf_passwd: "));
299 dump_data(100, pwd->smb_lm_owf, sizeof(pwd->smb_lm_owf));
300 DEBUG(100,("lm_sess_pwd: "));
301 dump_data(100, pwd->smb_lm_pwd, sizeof(pwd->smb_lm_pwd));
303 DEBUG(100,("session key:\n"));
304 dump_data(100, pwd->sess_key, sizeof(pwd->sess_key));
312 /****************************************************************************
313 gets lm and nt crypts
314 ****************************************************************************/
315 void pwd_get_lm_nt_owf(struct pwd_info *pwd, uchar lm_owf[24],
316 uchar *nt_owf, size_t *nt_owf_len,
321 #ifdef DEBUG_PASSWORD
322 DEBUG(100,("pwd_get_lm_nt_owf: NULL password\n"));
324 if (nt_owf_len != NULL)
331 pwd_deobfuscate(pwd);
334 memcpy(lm_owf, pwd->smb_lm_owf, 24);
338 memcpy(nt_owf, pwd->smb_nt_owf, pwd->nt_owf_len);
340 if (sess_key != NULL)
342 memcpy(sess_key, pwd->sess_key, 16);
344 if (nt_owf_len != NULL)
346 *nt_owf_len = pwd->nt_owf_len;