ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-dev: [Ethereal-dev] Dissection of NTLMSSP blob inside ResponseToken of SPNEGO (in SMB

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Yaniv Kaul <ykaul@xxxxxxxxxxxx>
Date: Sun, 13 Mar 2005 16:23:40 +0200
Any ideas how one might add this?
The PREVIOUS packet contained the OID (1.3.6....2.2.10), which is NTLMSSP, and properly dissected within MechToken the NTLMSSP blob (which was NTLMSSP_NEGOTIATE). However, the next packet contains the NTLMSSP_CHALLANGE (I assume, I can see 'NTLMSSP 3' there), but since there's no OID, it's not dissected?
I was under the impression it should get it from the conversation data.