NMB Auto Responding and SMB Fixed Challenges

03/19/2007


I know this has been discussed before, but I thought I'd post my own implementation anyways. The patch linked below modifies Samba to respond to all broadcast NetBIOS name requests and uses a fixed challenge for LM/NTLM authentication. All sorts of fun can be had by running this on an internal network or combining it with Karma. The current challenge works with Cain & Abel and the various Rainbow Tables floating around.

Patch [Samba 3.0.24]
Example smb.conf
John the Ripper Patch for NetLM/NetNTLM (against clean 1.7.0.2)
* This patch is now included in the "Jumbo" patch on the Official John Site. Please use this version for John 1.7.2 and newer.
RainbowCrack Patch for NetLM/NetNTLM/NetHalfLM
Helper script for using HalfLM cracked portion of password as seed to John.