,以及攻击者通过嗅探网络捕获上述NTLMv2响应的难度有多大--强制它进入密码。但是,假设攻击者一直在嗅探,并且在服务器将SC发送到客户端时已经捕获了SC。攻击者还应该能够从响应中看到客户端的挑战(CC & CC*)对吧..。那么,这是否意味着攻击者可以进行野蛮攻击--强制将NTV2或LMV2哈希包含在响应中,考虑到下面的信息现在就在他们身上。服务器挑战
CC &
[86022.030544] usb 4-2: new SuperSpeed USB device number 2 using xhci_hcd [86032.041106] usb 4-2: New USB device strings: Mfr=2, Product=3, SerialNumber=1
[86032.041110] usb 4-2: Product
Jul 9 09:09:56 me kernel: [ 2740.896079] usb 4-2: new full-speed USB device number 4 using uhci_hcdJul 9 09:09:57 me kernel: [ 2741.080112] usb 4-2: New USB device found, idVendor=046d, idProduct=c52fJul 9 09:09:57 me kernel: [ 2741.080118] usb 4-2: New USB device strin
.[147333.530241] usb 4-2: new SuperSpeed] usb 4-2: Product: VLI Product String
[147333.554422] usb 4-2: Manufacturer: VLI manufacture String[147333.554426] usb 4-2: SerialNumber: 00000000
USB3.0 -蓝色/5 SW/SWBus 004 Device 005: ID 054c:09c2 Sony Corp.[ 241.322233] usb 4-2: new SuperSpeed USB device number 4 using xhci_hcd[ 241.435830] usb 4-2: New US
驱动器设置为从模式.[ 1672.540299] usb 4-2: new SuperSpeed USB device number 7 using xhci_hcd[ 1672.562871] usb 4-2: New USB devicestrings: Mfr=4, Product=5, SerialNumber=6
[ 1672.562873] usb <em