Re: SAMR Communication between Client and Server



I do not know, nor whether it is the password within the crypto
or just a hash of it. Perhaps you now need a new thread asking
in the crypto newsgroup to see if someone there knows.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

<sarshah20@xxxxxxxxx> wrote in message
news:1142315378.196165.264280@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Thanks both of you guys for your replies.
SAMR packets were generated when i made the client PC to join the
domain. The client and server were two separate virtual machines. I
have another question. I was studying the captures and there is a
SamrSetInformationUser2 request from the client. In this request, the
password is sent encrypted. What encryption algo is used to encrypt
this passowrd?

And for those who are studying SAMR like me, this link would be helpful
if they are interested in various SAMR calls.

http://www.hsc.fr/ressources/articles/win_net_srv/ch04s07s03.html


Thanks,
sarshah.

Roger Abell [MVP] wrote:
I am not sure how well this transports back to NT 4 but I do
believe you would, assuming you are capturing the correct
network packet stream, have better luck if you were to do
a join of a machine to the domain or a remote creation of
a domain account.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

<sarshah20@xxxxxxxxx> wrote in message
news:1141999239.758120.33280@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I am studying SAMR and need to examine the SAMR packets that are
actually
sent on the wire.

What I am Doing:
I have setup a virtual machine of Windows NT 4 Server as a
domain controller and created a user (who will login from a remote
machine
joined with this domain controller). Then i took a virtual machine of
Windows
NT 4 Server (which will act as a client) and joined it with the
aforementioned
domain controller. Before logging in using the client machine, i setup
a
network traffic capture application and point it to capture
communication
between client and server. When i logged in on the client using domain
user
name, there were no SAMR packets that i could see in the capture.

The Question:
What kind of environment setup do i need to generate these
packets? By environment setup i mean what kind of client server
environment
must be setup? Or do i need to write a client which will make SAMR
interface
calls (like SamrConnect etc) to connect/authenticate to the SAM
database
residing on the domain controller.

Thanks,
sarshah.




.



Relevant Pages

  • Re: Client performance problem windows 2003 server...
    ... there and install an english client to be doing the errorsearching on. ... to the Windows 2000 server in site A that is a English ... >>be a DNS replication issue. ... >>results from not having a domain controller in a particular site. ...
    (microsoft.public.windows.server.networking)
  • Site-tosite VPN Issue
    ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
    (microsoft.public.windows.server.networking)
  • Re: Kerberos Error Message
    ... the domain controller which you reboot to alleviate the problem? ... > I know for certain there is no time difference between client and server. ... >> A good resource for troubleshooting Kerberos errors is the relatively new ...
    (microsoft.public.win2000.security)
  • Re: Multiple Domain Controllers -- who takes over if one is down?
    ... ....If domain controller fails client may need to reboot their computer... ... We know this is the case right now and it works, so if a client reports ... > * Make sure that you have at least two servers with global catalogs role ... If only one is assigned this role and this server goes down, ...
    (microsoft.public.windows.server.general)
  • Re: SAMR Communication between Client and Server
    ... The client and server were two separate virtual machines. ... And for those who are studying SAMR like me, ... I have setup a virtual machine of Windows NT 4 Server as a ...
    (microsoft.public.win2000.security)