This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi -

While debugging an issue with Windows 7/IE8 and NTLM authentication with our proxy server, noticed that wireshark (observed in versions 1.2.5 and 1.4.0) is truncating the domain name and username in NTLMSSP_AUTH messages to the first letter of each. So... instead of showing the full domain of MYDOMAIN it lists only "M" and instead of showing the full username USERID, it only lists "U".

This is specific to the NTLMSSP_AUTH (NTLM message type 3) message.

That lead us down the WRONG path troubleshooting-wise... Can you please fix?

asked 22 Sep '10, 14:08

Denee's gravatar image

Denee
1111
accept rate: 0%


Would you be so kind to add a bug report at https://bugs.wireshark.org ? It would really help us fix this problem if you also attach a tracefile there that shows this behavior.

(this site is a more like a knowledge base)

permanent link

answered 22 Sep '10, 15:44

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×103
×4
×4

question asked: 22 Sep '10, 14:08

question was seen: 7,032 times

last updated: 22 Sep '10, 15:44

p​o​w​e​r​e​d by O​S​Q​A