Hi, I have pcap containing DCE/RPC traffic whith authentication over NTLMSSP at the beginning. Is it possible with Wireshark to decrypt DCE/RPC communication provided I have NTLMSSP NT password? asked 09 Oct '17, 04:36 berma |
Hi, I have pcap containing DCE/RPC traffic whith authentication over NTLMSSP at the beginning. Is it possible with Wireshark to decrypt DCE/RPC communication provided I have NTLMSSP NT password? asked 09 Oct '17, 04:36 berma |
EDIT: In NTLMSSP protocol preferences I entered the NT Password, but still in DCE/RPC packets I see "Ecrypted stub data" instead of decrypted content.