OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Issue with netshareenum handshaking

From: Christopher R. Hertel (crhNTS.UMN.EDU)
Date: Mon Mar 22 2004 - 14:28:15 CST


>Hmmm... That's interesting... I wonder if a UID is valid across VCs. I
>doubt it. That *might* be why they're using VCs. Dunno.

It's been too long since I read up on this stuff. I'm doubting my doubts in
the above comment.

The SMB-LM1X.PS doc says (on pg 11) "A UID ... uniquely identifies a user
within a given VC environment." Thing is, a VC environment is a *set* of
VCs. That is, one or more VCs create a "Virtual Circuit Environment".

Urg.

This is where the Session Key (smb_sesskey, in SMB-LM1X.PS) comes in. It's
supposed to "...validate additional VCs added t a session (via the Session
Set Up protocol)".

As far as I know, the Session Key is not used in newer versions of Windows.
I'm happy to be proven wrong on this. The wording *does* suggest, however,
that the new VC must be authenticated (via SessionSetupAndX) before it may
join a given Virtual Circuit Environment.

Hmmm... If the Session Key is used then the question is *how?*.

---

Alan Wright pointed out this entry from Steve French in the archives:

http://discuss.microsoft.com/SCRIPTS/WA-MSD.EXE?A2=ind0011b&L=cifs&T=0&F=&S=&P=552

The SMB-LM1X.PS document I mentioned found here:
  ftp://ftp.microsoft.com/developr/drg/cifs/SMB-LM1X.PS

Chris -)-----

----------------------------------------------------------------
Users Guide http://discuss.microsoft.com/archives/mailfaq.html
contains important info including how to unsubscribe. Save time, search
the archives at http://discuss.microsoft.com/archives/index.html