Message encoder/decoder and password hasher for the NTLM authentication protocol
PHP Makefile
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Failed to load latest commit information.
src/Robin/Ntlm
tests
.gitignore
.scrutinizer.yml
.travis.yml
LICENSE
Makefile
README.md
composer.json
phpunit.xml.dist

README.md

PHP NTLM

Build Status Quality Score Latest Stable Version

PHP-NTLM is a library that handles the encoding and decoding of messages used in the challenge-and-response flow of the NTLM authentication protocol, while also providing separate injectable credential hashing mechanisms to allow for a more secure version of a credential for storage (rather than storing passwords in "plain-text").

Features

  • NTLM client message encoding and decoding
  • Multiple text-encoding native-extensions supported
  • LM, NTv1, and NTv2 hashing algorithms supported

Requirements

  • 64-bit PHP runtime (NTLM negotiation bit flags extend beyond the 32-bit integer size)
  • PHP >=5.4.0

Installation

  1. Get Composer
  2. Add robinpowered/php-ntlm to your Composer required dependencies: composer require robinpowered/php-ntlm
  3. Include the Composer autoloader

TODO

  • LM hashing
  • NTv1 hashing
  • NTv2 hashing
  • NTLM negotiate message encoding
  • NTLM challenge message decoding
    • Message structure and data validation
    • Negotiate flag decoding
    • Server challenge "nonce" handling
    • TargetName parsing/handling
    • (Optional) TargetInfo parsing/handling
      • (Optional) AV_PAIR decoding
    • (Optional) Version parsing/handling (for debugging purposes only)
  • NTLM authenticate message encoding
    • NTLM v1 response support
    • NTLM v2 response support
    • Extended session security (NTLM2 session key) support
    • (Add-on) Encrypted session key exchange support
  • Datagram ("connectionless") support
  • PHP 5.3.x support
  • Tests... ugh.

License

PHP-NTLM is licensed under the Apache License, Version 2.0.


Copyright 2015 Robin Powered, Inc.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.