,以及攻击者通过嗅探网络捕获上述NTLMv2响应的难度有多大--强制它进入密码。但是,假设攻击者一直在嗅探,并且在服务器将SC发送到客户端时已经捕获了SC。攻击者还应该能够从响应中看到客户端的挑战(CC & CC*)对吧..。那么,这是否意味着攻击者可以进行野蛮攻击--强制将NTV2或LMV2哈希包含在响应中,考虑到下面的信息现在就在他们身上。服务器挑战
CC &
model: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+打印机连接[216143.260035] usb 2-7: reset high-speed USB device number 8 using ehci_hcd[216219.096159] usb 2-7: USB disconnect,
input20[ 16.392232] uvcvideo 2-[ 16.392236] uvcvideo 2-7:1.0: Entity type for entity Processing 2 was not initialized![ 16.392240] uvcvideo 2-7:1.0: Entity type for entity Camera 1 was not initiali