日韩av黄I国产麻豆传媒I国产91av视频在线观看I日韩一区二区三区在线看I美女国产在线I麻豆视频国产在线观看I成人黄色短片

歡迎訪問 生活随笔!

生活随笔

當前位置: 首頁 > 运维知识 > windows >内容正文

windows

signature=095ed28e83b68620637b3a67436b0f8f,SMB 3.1.1 Encryption in Windows 10

發布時間:2024/7/23 windows 43 豆豆
生活随笔 收集整理的這篇文章主要介紹了 signature=095ed28e83b68620637b3a67436b0f8f,SMB 3.1.1 Encryption in Windows 10 小編覺得挺不錯的,現在分享給大家,幫大家做個參考.

SMB 3.1.1 Encryption in Windows 10

09/09/2015

13 分鐘可看完

本文內容

SMB 3 encryption offers data packet confidentiality and prevents an attacker from both tampering with and eavesdropping on any data packet. Encryption has been enhanced in SMB 3.1.1. The cipher can now be negotiated during connection establishment. In addition to AES-128-CCM for SMB 3.0.x compatibility, Windows 10 (and Windows Server 2016) added AES-128-GCM in SMB 3.1.1. The GCM mode offers a significant performance gain. Both ciphers [RFC5084] provide authenticated encryption, i.e. message integrity (signing). This blog takes a protocol walk on the enhancement and provides sample test vectors.

NOTE: This is written based on Windows 10, and Windows Server 2016 Technical Preview 3.

Encryption capability negotiate context

SMB 3.1.1 client and server negotiate encryption support via SMB2_ENCRYPTION_CAPABILITIES negotiate context in the NEGOTIATE request and response.

The client advertises its list of supported cipher IDs in the order of most preferred encryption algorithm. Windows 10 implements cipher IDs 0x0002 (AES-128-GCM) and 0x0001 (AES-128-CCM).

If the client sends 3.0.x in the dialect array and supports encryption, it must advertise the SMB2_GLOBAL_CAP_ENCRYPTION capability flag as well since it does not know yet what dialect the server supports.

If the server selects dialect 3.1.1 and supports encryption, it responds with the encryption negotiate context. SMB2_GLOBAL_CAP_ENCRYPTION capability flag should not be set because it is valid for the SMB 3.0 and 3.0.2 dialects.

The encryption capability negotiate context has the same format in the Negotiate request and response, except that the response context must have CipherCount set to 1, and the cipher ID that conveys the server’s selection.

Multichannel encryption

Session binding (multichannel) requires that all channels bound to a given session negotiate the same encryption cipher as the master session’s connection.

As in SMB 3.0.x, all SMB 3.1.1 channels (primary and alternate) bound to a given master session share the same encryption and decryption keys.

The cipher ID is kept consistent as multichannel traffic can be spread across channels.

Server-wide or per-share encryption

For a global level encryption, SessionSetup_response.SessionFlags includes SMB2_SESSION_FLAG_ENCRYPT_DATA. Encryption is enforced on the whole server.

For a per-share level encryption, TreeConnect_response.ShareFlags includes SMB2_SHAREFLAG_ENCRYPT_DATA.

If server-wide encryption is configured, share level encryption will not have any effect. This means, when global encryption is enabled, you cannot selectively disable encryption for certain shares.

Encryption enforcement can be bypassed if “unencrypted access” is allowed. See RejectUnencryptedAccess.

Configuration

PowerShell cmdlets can be used to configure encryption on both Windows 10 and Windows Server 2016:

Global level encryption on the server:

Set-SmbServerConfiguration -EncryptData <0|1>

Share level encryption:

Set-SmbShare -Name -EncryptData <0|1>

Share level encryption enabled at creation:

New-SmbShare -Name -Path -EncryptData 1

Unencrypted access:

Set-SmbServerConfiguration -RejectUnencryptedAccess <0|1>

See notes in Section “Unencrypted access”.

Encryption keys

Upon successful SessionSetup (Session.EncryptData), or successful TreeConnect (Share.EncryptData), the server and client generate EncryptionKey and DecryptionKey as specified in [MS-SMB2].

The key derivation in SMB 3.1.1 uses the same function as in SMB 3.0.x with new labels and context as follows. The context Session.PreauthIntegrityHashValue is derived from pre-authentication integrity hashing. The respective labels are shown in the following key formulas.

EncryptionKey (Client) = DecryptionKey (Server) = SMB3KDF (SessionKey, "SMBC2SCipherKey\0", Session.PreauthIntegrityHashValue)

DecryptionKey (Client) = EncryptionKey (Server) = SMB3KDF ( SessionKey, "SMBS2CCipherKey\0", Session.PreauthIntegrityHashValue)

Note that SMB3KDF() and the calculation of Session.PreauthIntegrityHashValue are described in the blog post:

SMB 3.1.1 Pre-authentication integrity in Windows 10

http://blogs.msdn.com/b/openspecification/archive/2015/08/11/smb-3-1-1-pre-authentication-integrity-in-windows-10.aspx

Transformed message

A transformed message consists of a transform_header followed by its encrypted SMB2 message.

A transform_header has the same size and most of the same fields as defined for dialect 3.0.x with two specific changes for dialect 3.1.1:

ProtocolId (4 bytes):? 0xFD534D42 (in network order)

Signature (16 bytes):? Signature of the encrypted message.

Nonce (16 bytes):? An implementation-specific value unique for this encrypted message.

OriginalMessageSize (4 bytes):? The size in bytes of the SMB2 message.

Reserved (2 bytes):? Set to zeros and ignored.

Flags (2 bytes): This field indicates how the SMB2 message was transformed.

SessionId (8 bytes):? Uniquely identifies the established session for the command.

The two changes to the transform_header for SMB 3.1.1 are as follows:

Nonce (16 bytes) field: If CipherId is AES-128-GCM, the nonce used for encryption is the leftmost 12 bytes of the Nonce field, AES128GCM_Nonce (12 bytes), and the remaining 4 bytes are reserved. If CipherId is AES-128-CCM, the nonce used for encryption is the leftmost 11 bytes of the Nonce field, AES128CCM_Nonce (11 bytes), and the remaining 5 bytes are reserved.

Flags (2 bytes): this field repurposes the EncryptionAlgorithm (2 bytes) field used in SMB 3.0.x. When Flags’ value is set to 0x0001, it indicates that the message is encrypted using the negotiated cipher ID.

Encrypting the message

The sender encrypts the message with these specifics:

- The encryption algorithm specified by Connection.CipherId (AES-GCM or AES-CCM) is called with the following inputs:

- AES key: Session.EncryptionKey.

- AES-nonce or IV: AES128CCM_Nonce for AES-CCM, AES128GCM_Nonce for AES-GCM.

- Plaintext: The SMB2 message including the header and the payload.

- The optional authenticated data (AAD):? The SMB2 transform_header excluding the ProtocolId and Signature fields; these are the 32 bytes starting from the Nonce field.

The AES-CCM or AES-GCM outputs are:

- Ciphertext: the encrypted SMB2 message

- Message authentication code: the Signature field of the transform_header.

The sender appends the encrypted SMB2 message to the transform_header and sends it to the receiver.

Decrypting the message

The message is decrypted using:

- The encryption algorithm specified by Connection.CipherId.

- The Session.DecryptionKey of the Session that corresponds to the SessionId in the transform_header.

- The AAD passed to the algorithm is the transform_header excluding the ProtocolId and Signature fields.

- The nonce passed to the algorithm is based on CipherId as previously described.

The signature returned by the decryption algorithm is then verified against the Signature in the transform_header.

Encryption clauses

The encryption clauses are generally the same as for SMB 3.0.x. See the blog post at:

Encryption in SMB 3.0: A protocol perspective

http://blogs.msdn.com/b/openspecification/archive/2012/10/05/encryption-in-smb-3-0-a-protocol-perspective.aspx

Unencrypted Access: RejectUnencryptedAccess

Set-SmbServerConfiguration -RejectUnencryptedAccess <0|1>

The behavior is mainly unchanged in Windows Server 2016. The default value of RejectUnencryptedAccess is TRUE. When encryption is required (per share or server wide), the server returns ACCESS_DENIED for an unencrypted access attempt. A value of FALSE allows access from clients which do not support encryption or are not encryption-capable (e.g. SMB 1, SMB2 dialects 2.02, 2.1, SMB 3.x without encryption).

This configuration item is meant for a transition phase to support down-level clients which use older dialects (SMB 2.1 or earlier) by literally “allowing any unencrypted access" whenever the deployment scenario requires.

Note that if RejectUnencryptedAccess is disabled (FALSE), it opens the possibility for a man-in-the-middle (MITM) attacker to prevent the connection from negotiating encryption. If SMB 3.x is negotiated, the Windows 10 client will leverage negotiate validation or pre-authentication integrity to verify the properties of the connection with the server. In SMB 2.x.x, the encryption feature is not available even if the Windows 10 client still performs secure negotiate validation.

However, setting RejectUnencryptedAccess to FALSE makes it un-detectible if the MITM downgrades the connection's dialect to SMB1, thus preventing encryption negotiation and allowing “clear text” eavesdropping.

As a result, it is recommended to disable SMB1 on the client as soon as it is no longer needed.

Conclusion

Encryption is a very important feature whenever data confidentiality is required. This is the case when transferring high business impact data over untrusted networks. The addition of encryption negotiate context in SMB 3.1.1 is an enhancement that would interest many implementers. It also makes the feature extensible as new cryptographic ciphers become available and adopted. Some benchmark testing showed that AES-128-GCM provides as much as two times performance improvement over AES-128-CCM, while providing authenticated encryption at the same time.

Appendix A. Test vector for SMB 3.1.1 encryption

This sample data should be considered “as-is”. It should also be noted that examples do not replace normative protocol specifications. The authoritative reference is [MS-SMB2].

The test client negotiates SMB 3.1.1 and communicates with a Windows 2016 server. It opens a file and WRITEs the following content. It then READs back the file.

This is the content written and read:

Smb3 encryption testing

Hex value:

536D623320656E6372797074696F6E2074657374696E67

These outputs show pre-authentication integrity phase for key derivation, then the encryption and decryption of the WRITE and READ commands.

The decrypted content is verified to be same at the end of the SMB2 READ response.

Appendix A.1 Test vector with AES-GCM

--- Key derivation ---

Header.Command 0x0000 NEGOTIATE

Preauth integrity hash ---

PreauthIntegrityCaps.HashAlgorithmCount 0x1

PreauthIntegrityCaps.SaltLength 0x20

PreauthIntegrityCaps.HashAlgorithms 0x0001

PreauthIntegrityCaps.Salt

D1709D7196E1BD0B6EBF95213D76553435763514392649FD6F216ED8BF269CD8

Encryption capabilites ---

EncryptionCaps.CipherCount 0x2

EncryptionCaps.Ciphers[0] 0x0002

EncryptionCaps.Ciphers[1] 0x0001

Connection.PreauthIntegrityHashId 0x0001

NEGOTIATE Request

Preauth integrity hash ---

Current

Connection.PreauthIntegrityHashValue

00000000000000000000000000000000000000000000000000000000000000000000000000000000

000000000000000000000000000000000000000000000000

Negotiate request packet

FE534D4240000100000000000000010000000000000000000000000000000000FFFE000000000000

0000000000000000000000000000000000000000000000002400050001000000660000004F0D7FA0

09F5B246B2EF62551D7D7C0970000000020000000202100200030203110300000100260000000000

010020000100D1709D7196E1BD0B6EBF95213D76553435763514392649FD6F216ED8BF269CD80000

0200060000000000020002000100

Concatenate Connection.PreauthIntegrityHashValue and Negotiate request packet

SHA-512 Input Hash Data

00000000000000000000000000000000000000000000000000000000000000000000000000000000

000000000000000000000000000000000000000000000000FE534D42400001000000000000000100

00000000000000000000000000000000FFFE00000000000000000000000000000000000000000000

00000000000000002400050001000000660000004F0D7FA009F5B246B2EF62551D7D7C0970000000

020000000202100200030203110300000100260000000000010020000100D1709D7196E1BD0B6EBF

95213D76553435763514392649FD6F216ED8BF269CD800000200060000000000020002000100

New

Connection.PreauthIntegrityHashValue

550442DAF311412870AD9E58E602B0312D61328D6B1AC28F22AF46D6EA581F23A9BFABE0CC041197

6BF3F9DA23D3433352CB48CF00B8659BC1A3695E1B1A52A8

NEGOTIATE Response

Updating Preauth integrity hash ---

Current

Connection.PreauthIntegrityHashValue

550442DAF311412870AD9E58E602B0312D61328D6B1AC28F22AF46D6EA581F23A9BFABE0CC041197

6BF3F9DA23D3433352CB48CF00B8659BC1A3695E1B1A52A8

Negotiate response packet

FE534D4240000100000000000000010001000000000000000000000000000000FFFE000000000000

000000000000000000000000000000000000000000000000410001001103020039CBCAF329714942

BDCE5D60F09AB3FB27000000000080000000800000008000D1168E69CDAED00109094AB095AED001

80004001C00100006082013C06062B0601050502A08201303082012CA01A3018060A2B0601040182

3702021E060A2B06010401823702020AA282010C048201084E45474F455854530100000000000000

6000000070000000807CC0FD06D6362D02DDE1CF343BFE29C16AA4EA4741FB0EF645DC5C5D3C3E6A

8DE5D0BAEF7A06DC070076174356EDA0000000000000000060000000010000000000000000000000

5C33530DEAF90D4DB2EC4AE3786EC3084E45474F4558545303000000010000004000000098000000

807CC0FD06D6362D02DDE1CF343BFE295C33530DEAF90D4DB2EC4AE3786EC3084000000058000000

3056A05430523027802530233121301F06035504031318546F6B656E205369676E696E6720507562

6C6963204B65793027802530233121301F06035504031318546F6B656E205369676E696E67205075

626C6963204B65790100260000000000010020000100B51C002C28941192737A08344B05CE90786E

EC146D99CDB60AE44E5A86127D270000020004000000000001000200

Concatenate Connection.PreauthIntegrityHashValue and Negotiate response packet

SHA-512 Input Hash Data

550442DAF311412870AD9E58E602B0312D61328D6B1AC28F22AF46D6EA581F23A9BFABE0CC041197

6BF3F9DA23D3433352CB48CF00B8659BC1A3695E1B1A52A8FE534D42400001000000000000000100

01000000000000000000000000000000FFFE00000000000000000000000000000000000000000000

0000000000000000410001001103020039CBCAF329714942BDCE5D60F09AB3FB2700000000008000

0000800000008000D1168E69CDAED00109094AB095AED00180004001C00100006082013C06062B06

01050502A08201303082012CA01A3018060A2B06010401823702021E060A2B06010401823702020A

A282010C048201084E45474F4558545301000000000000006000000070000000807CC0FD06D6362D

02DDE1CF343BFE29C16AA4EA4741FB0EF645DC5C5D3C3E6A8DE5D0BAEF7A06DC070076174356EDA0

0000000000000000600000000100000000000000000000005C33530DEAF90D4DB2EC4AE3786EC308

4E45474F4558545303000000010000004000000098000000807CC0FD06D6362D02DDE1CF343BFE29

5C33530DEAF90D4DB2EC4AE3786EC30840000000580000003056A05430523027802530233121301F

06035504031318546F6B656E205369676E696E67205075626C6963204B6579302780253023312130

1F06035504031318546F6B656E205369676E696E67205075626C6963204B65790100260000000000

010020000100B51C002C28941192737A08344B05CE90786EEC146D99CDB60AE44E5A86127D270000

020004000000000001000200

New

Connection.PreauthIntegrityHashValue

ABE4DA6E875F6FB05033AF04DCC38C92888B4E13D1EAB7AA05CADE142064974CB3EAB0782600549B

A27207AA213B0D190B9950FA36D45BE32A888BFEE8389B74

Add NEW SessionId 0x100000000025 to Preauth Integrity hash table with value

Connection.PreauthIntegrityHashValue

ABE4DA6E875F6FB05033AF04DCC38C92888B4E13D1EAB7AA05CADE142064974CB3EAB0782600549B

A27207AA213B0D190B9950FA36D45BE32A888BFEE8389B74

SESSION SETUP Request

PreauthSession.SessionId 0x100000000025

Current

PreauthSession.PreauthIntegrityHashValue

ABE4DA6E875F6FB05033AF04DCC38C92888B4E13D1EAB7AA05CADE142064974CB3EAB0782600549B

A27207AA213B0D190B9950FA36D45BE32A888BFEE8389B74

SessionSetup request packet

FE534D4240000100000000000100800000000000000000000100000000000000FFFE000000000000

00000000000000000000000000000000000000000000000019000001010000000000000058004A00

0000000000000000604806062B0601050502A03E303CA00E300C060A2B06010401823702020AA22A

04284E544C4D5353500001000000978208E200000000000000000000000000000000060380250000

000F

Concatenate PreauthSession.PreauthIntegrityHashValue and Session Setup request packet

SHA-512 Input Hash Data

ABE4DA6E875F6FB05033AF04DCC38C92888B4E13D1EAB7AA05CADE142064974CB3EAB0782600549B

A27207AA213B0D190B9950FA36D45BE32A888BFEE8389B74FE534D42400001000000000001008000

00000000000000000100000000000000FFFE00000000000000000000000000000000000000000000

000000000000000019000001010000000000000058004A000000000000000000604806062B060105

0502A03E303CA00E300C060A2B06010401823702020AA22A04284E544C4D53535000010000009782

08E200000000000000000000000000000000060380250000000F

PreauthSession.PreauthIntegrityHashValue

A5E8AB87E2ADB8FA5F4545D20F1FD2019D66CCD0F4DFD1F762F1DFC8DCB15B98D0BD1F1450F6A0AF

C70F80B353C2D959217681949CF22DF35F31257A281C6A80

SESSION SETUP Response

--- STATUS_MORE_PROCESSING_REQUIRED - Updating Preauth integrity hash ---

PreauthSession.SessionId 0x100000000025

Current

PreauthSession.PreauthIntegrityHashValue

A5E8AB87E2ADB8FA5F4545D20F1FD2019D66CCD0F4DFD1F762F1DFC8DCB15B98D0BD1F1450F6A0AF

C70F80B353C2D959217681949CF22DF35F31257A281C6A80

SessionSetup response packet

FE534D4240000100160000C00100010001000000000000000100000000000000FFFE000000000000

250000000010000000000000000000000000000000000000090000004800B300A181B03081ADA003

0A0101A10C060A2B06010401823702020AA281970481944E544C4D53535000020000000C000C0038

00000015828AE25FC0CB7F886E93D6000000000000000050005000440000000A0092270000000F53

005500540033003100310002000C0053005500540033003100310001000C00530055005400330031

00310004000C0053005500540033003100310003000C005300550054003300310031000700080024

8D5C6CCDAED00100000000

SessionSetup response header signature 0x00000000000000000000000000000000

Concatenate PreauthSession.PreauthIntegrityHashValue and Session Setup response packet

SHA-512 Input Hash Data

A5E8AB87E2ADB8FA5F4545D20F1FD2019D66CCD0F4DFD1F762F1DFC8DCB15B98D0BD1F1450F6A0AF

C70F80B353C2D959217681949CF22DF35F31257A281C6A80FE534D4240000100160000C001000100

01000000000000000100000000000000FFFE00000000000025000000001000000000000000000000

0000000000000000090000004800B300A181B03081ADA0030A0101A10C060A2B0601040182370202

0AA281970481944E544C4D53535000020000000C000C003800000015828AE25FC0CB7F886E93D600

0000000000000050005000440000000A0092270000000F53005500540033003100310002000C0053

005500540033003100310001000C0053005500540033003100310004000C00530055005400330031

00310003000C0053005500540033003100310007000800248D5C6CCDAED00100000000

PreauthSession.PreauthIntegrityHashValue

9A095455244172898902B0FBDF5FEFAFD8435BB66A47EB55CB7542732A423F58B12B3ED698BEF387

8D8A346FD9F5CC882DA37AAF2A939290E98B935FC72B3944

SESSION SETUP Request

PreauthSession.SessionId 0x100000000025

Current

PreauthSession.PreauthIntegrityHashValue

9A095455244172898902B0FBDF5FEFAFD8435BB66A47EB55CB7542732A423F58B12B3ED698BEF387

8D8A346FD9F5CC882DA37AAF2A939290E98B935FC72B3944

SessionSetup request packet

FE534D4240000100000000000100800000000000000000000200000000000000FFFE000000000000

2500000000100000000000000000000000000000000000001900000101000000000000005800CF01

0000000000000000A18201CB308201C7A0030A0101A28201AA048201A64E544C4D53535000030000

001800180090000000EE00EE00A80000000C000C00580000001A001A0064000000120012007E0000

001000100096010000158288E2060380250000000FA5E34268EF143BE5816251D02C564E9B530055

005400330031003100610064006D0069006E006900730074007200610074006F0072004400520049

005600450052003300310031000000000000000000000000000000000000000000000000002C263D

A5C2D54785E8EDA0552472D3A30101000000000000248D5C6CCDAED001BEA7A53E2DC098EB000000

0002000C0053005500540033003100310001000C0053005500540033003100310004000C00530055

00540033003100310003000C0053005500540033003100310007000800248D5C6CCDAED001060004

00020000000800300030000000000000000000000000300000B61FEFCAA857EA57BF1EDCEBF8974B

8E0EBA5A6DFD9D07A31D11B548F8C9D0CC0A00100000000000000000000000000000000000090016

0063006900660073002F00530055005400330031003100000000000000000000000000133FA6EA15

4880BB44576C6E2490BDE7A31204100100000067890BD408F5680D00000000

Concatenate PreauthSession.PreauthIntegrityHashValue and Session Setup request packet

SHA-512 Input Hash Data

9A095455244172898902B0FBDF5FEFAFD8435BB66A47EB55CB7542732A423F58B12B3ED698BEF387

8D8A346FD9F5CC882DA37AAF2A939290E98B935FC72B3944FE534D42400001000000000001008000

00000000000000000200000000000000FFFE00000000000025000000001000000000000000000000

00000000000000001900000101000000000000005800CF010000000000000000A18201CB308201C7

A0030A0101A28201AA048201A64E544C4D53535000030000001800180090000000EE00EE00A80000

000C000C00580000001A001A0064000000120012007E0000001000100096010000158288E2060380

250000000FA5E34268EF143BE5816251D02C564E9B530055005400330031003100610064006D0069

006E006900730074007200610074006F007200440052004900560045005200330031003100000000

0000000000000000000000000000000000000000002C263DA5C2D54785E8EDA0552472D3A3010100

0000000000248D5C6CCDAED001BEA7A53E2DC098EB0000000002000C005300550054003300310031

0001000C0053005500540033003100310004000C0053005500540033003100310003000C00530055

00540033003100310007000800248D5C6CCDAED00106000400020000000800300030000000000000

000000000000300000B61FEFCAA857EA57BF1EDCEBF8974B8E0EBA5A6DFD9D07A31D11B548F8C9D0

CC0A001000000000000000000000000000000000000900160063006900660073002F005300550054

00330031003100000000000000000000000000133FA6EA154880BB44576C6E2490BDE7A312041001

00000067890BD408F5680D00000000

PreauthSession.PreauthIntegrityHashValue

B23F3CBFD69487D9832B79B1594A367CDD950909B774C3A4C412B4FCEA9EDDDBA7DB256BA2EA30E9

77F11F9B113247578E0E915C6D2A513B8F2FCA5707DC8770

SESSION SETUP Response

SessionId 0x100000000025 COMPLETED

SessionSetup response packet

FE534D4240000100000000000100800009000000000000000200000000000000FFFE000000000000

25000000001000006B85A4519A0F3EEA35BA946DD3AFE6B80900000048001D00A11B3019A0030A01

00A3120410010000003932A87523AB660100000000

SessionSetup response header signature 0x6B85A4519A0F3EEA35BA946DD3AFE6B8

PreauthSession.PreauthIntegrityHashValue

B23F3CBFD69487D9832B79B1594A367CDD950909B774C3A4C412B4FCEA9EDDDBA7DB256BA2EA30E9

77F11F9B113247578E0E915C6D2A513B8F2FCA5707DC8770

Input cryptographicKey (SessionKey) 0x419FDDF34C1E001909D362AE7FB6AF79

(queried from GSS authenticated context)

--- Dialect 0x0311 ---

preauthIntegrityHashValue

B23F3CBFD69487D9832B79B1594A367CDD950909B774C3A4C412B4FCEA9EDDDBA7DB256BA2EA30E9

77F11F9B113247578E0E915C6D2A513B8F2FCA5707DC8770

CypherId 0x0002

SessionKey 0x419FDDF34C1E001909D362AE7FB6AF79

SigningKey 0x8765949DFEAEE105CE9118B45BE988F0

EncryptionKey 0xA2F5E80E5D59103034F32E52F698E5EC

DecryptionKey 0x748C50868C90F302962A5C35F5F9A8BF

ApplicationKey 0x099D610789FBE82055B313601C3E8CC4

--- Encryption ---

SessionId 0x100000000025

SessionKey 0x419FDDF34C1E001909D362AE7FB6AF79

SigningKey 0x8765949DFEAEE105CE9118B45BE988F0

EncryptionKey 0xA2F5E80E5D59103034F32E52F698E5EC

DecryptionKey 0x748C50868C90F302962A5C35F5F9A8BF

ApplicationKey 0x099D610789FBE82055B313601C3E8CC4

Header.Command 0x0009 WRITE

Encryption of the request ---

Key 0xA2F5E80E5D59103034F32E52F698E5EC

Nonce Length 0xc

AES-128-GCM nonce 0xC7D6822D269CAF48904C664C

SMB2 packet

FE534D4240000100000000000900010008000000000000000500000000000000FFFE000001000000

25000000001000000000000000000000000000000000000031007000170000000000000000000000

0600000004000000010000000400000000000000000000007000000000000000536D623320656E63

72797074696F6E2074657374696E67

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0xBD73D97D2BC9001BCAFAC0FDFF5FEEBC

transform_header.Nonce 0xC7D6822D269CAF48904C664C00000000

transform_header.OriginalMessageSize 0x87

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000025

Encrypted message

6ECDD2A7AFC7B47763057A041B8FD4DAFFE990B70C9E09D36C084E02D14EF247F8BDE38ACF6256F8

B1D3B56F77FBDEB312FEA5E92CBCC1ED8FB2EBBFAA75E49A4A394BB44576545567C24D4C014D47C9

FBDFDAFD2C4F9B72F8D256452620A299F48E29E53D6B61D1C13A19E91AF013F00D17E3ABC2FC3D36

C8C1B6B93973253852DBD442E46EE8

Transformed message

FD534D42BD73D97D2BC9001BCAFAC0FDFF5FEEBCC7D6822D269CAF48904C664C0000000087000000

0000010025000000001000006ECDD2A7AFC7B47763057A041B8FD4DAFFE990B70C9E09D36C084E02

D14EF247F8BDE38ACF6256F8B1D3B56F77FBDEB312FEA5E92CBCC1ED8FB2EBBFAA75E49A4A394BB4

4576545567C24D4C014D47C9FBDFDAFD2C4F9B72F8D256452620A299F48E29E53D6B61D1C13A19E9

1AF013F00D17E3ABC2FC3D36C8C1B6B93973253852DBD442E46EE8

Decryption of the response ---

Transformed message

FD534D42ACBE1CB7ED343ADF1725EF144D90D4B0E06831DD2E8EB7B4000000000000000050000000

00000100250000000010000026BBBF949983A6C1C796559D0F2C510CB651D1F7B6AC8DED32A2A0B8

F2D793A815C6F6B848D69767A215841A42D400AE6DDB5F0B44173A014973321FDD7950DA6179159B

82E03C9E18A050FF0EA1C967

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0xACBE1CB7ED343ADF1725EF144D90D4B0

transform_header.Nonce 0xE06831DD2E8EB7B40000000000000000

transform_header.OriginalMessageSize 0x50

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000025

Key 0x748C50868C90F302962A5C35F5F9A8BF

Nonce Length 0xc

AES-128-GCM nonce 0xE06831DD2E8EB7B400000000

Decrypted SMB2 packet

FE534D4240000100000000000900010001000000000000000500000000000000FFFE000001000000

25000000001000000000000000000000000000000000000011000000170000000000000000000000

Header.Command 0x0008 READ

Encryption of the request ---

Key 0xA2F5E80E5D59103034F32E52F698E5EC

Nonce Length 0xc

AES-128-GCM nonce 0xD7AA8C6D36859243B715E0A6

SMB2 packet

FE534D4240000100000000000800010008000000000000000600000000000000FFFE000001000000

25000000001000000000000000000000000000000000000031000000170000000000000000000000

060000000400000001000000040000000000000000000000000000000000000000

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0x6DAC0B6FD85A3ED42BB917DA38FE0386

transform_header.Nonce 0xD7AA8C6D36859243B715E0A600000000

transform_header.OriginalMessageSize 0x71

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000025

Encrypted message

88A47BF09CA3C3141CDD7306BE9D9475AB24FCCB833D77461C041F8FB983D0C188F0729272B31D9D

3D0DC6B687C069EEE0CC8EACA2C536D019ACC9E185D1EB630E0FCB793EEECEB06D82A1D77706E700

DBEBFB4FEB54D7AD2D97E7288804F90757FE4D08D6A84A3FF433E7451E768E4699

Transformed message

FD534D426DAC0B6FD85A3ED42BB917DA38FE0386D7AA8C6D36859243B715E0A60000000071000000

00000100250000000010000088A47BF09CA3C3141CDD7306BE9D9475AB24FCCB833D77461C041F8F

B983D0C188F0729272B31D9D3D0DC6B687C069EEE0CC8EACA2C536D019ACC9E185D1EB630E0FCB79

3EEECEB06D82A1D77706E700DBEBFB4FEB54D7AD2D97E7288804F90757FE4D08D6A84A3FF433E745

1E768E4699

Decryption of the response ---

Transformed message

FD534D427F714B3B9D8FA1198584E71C2BAA1CB6E16831DD2E8EB7B4000000000000000067000000

000001002500000000100000FECEDF4D03BB11A6CC5D8A53BE33D6D8701986342B4197D306E16F9C

BB218E92F7F8281F51CE68BB85A20D87DE90EBBF80538066D1C37513C0A58D70936D537B624F5500

202A612B6CD30D448A82791A0B2E049ED512AFAEFB06E98AB3D6F931D7D50DB2DBD36A

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0x7F714B3B9D8FA1198584E71C2BAA1CB6

transform_header.Nonce 0xE16831DD2E8EB7B40000000000000000

transform_header.OriginalMessageSize 0x67

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000025

Key 0x748C50868C90F302962A5C35F5F9A8BF

Nonce Length 0xc

AES-128-GCM nonce 0xE16831DD2E8EB7B400000000

Decrypted SMB2 packet

FE534D4240000100000000000800010001000000000000000600000000000000FFFE000001000000

25000000001000000000000000000000000000000000000011005000170000000000000000000000

536D623320656E6372797074696F6E2074657374696E67

Appendix A.2 Test vector with AES-CCM

--- Key derivation ---

Header.Command 0x0000 NEGOTIATE

Preauth integrity hash ---

PreauthIntegrityCaps.HashAlgorithmCount 0x1

PreauthIntegrityCaps.SaltLength 0x20

PreauthIntegrityCaps.HashAlgorithms 0x0001

PreauthIntegrityCaps.Salt

1A05A92392E1554C072AE7B186EE7DC02CB90BEF2E639CCC94B7A9DC7B393442

Encryption capabilites ---

EncryptionCaps.CipherCount 0x2

EncryptionCaps.Ciphers[0] 0x0001

EncryptionCaps.Ciphers[1] 0x0002

Connection.PreauthIntegrityHashId 0x0001

NEGOTIATE Request

Preauth integrity hash ---

Current

Connection.PreauthIntegrityHashValue

00000000000000000000000000000000000000000000000000000000000000000000000000000000

000000000000000000000000000000000000000000000000

Negotiate request packet

FE534D4240000100000000000000010000000000000000000000000000000000FFFE000000000000

00000000000000000000000000000000000000000000000024000500010000006600000078EA16AC

6877C34A95F7160F73EA377270000000020000000202100200030203110300000100260000000000

0100200001001A05A92392E1554C072AE7B186EE7DC02CB90BEF2E639CCC94B7A9DC7B3934420000

0200060000000000020001000200

Concatenate Connection.PreauthIntegrityHashValue and Negotiate request packet

SHA-512 Input Hash Data

00000000000000000000000000000000000000000000000000000000000000000000000000000000

000000000000000000000000000000000000000000000000FE534D42400001000000000000000100

00000000000000000000000000000000FFFE00000000000000000000000000000000000000000000

000000000000000024000500010000006600000078EA16AC6877C34A95F7160F73EA377270000000

0200000002021002000302031103000001002600000000000100200001001A05A92392E1554C072A

E7B186EE7DC02CB90BEF2E639CCC94B7A9DC7B39344200000200060000000000020001000200

New

Connection.PreauthIntegrityHashValue

A3A8A769FEA693B3D037406EF945E115D2B7A4A9318564D2CAAA4B1FE0EC36D8D92A4802619EDCF2

9E2410534D2D3749E71F76ADF5212F959210D291097A6355

NEGOTIATE Response

Updating Preauth integrity hash ---

Current

Connection.PreauthIntegrityHashValue

A3A8A769FEA693B3D037406EF945E115D2B7A4A9318564D2CAAA4B1FE0EC36D8D92A4802619EDCF2

9E2410534D2D3749E71F76ADF5212F959210D291097A6355

Negotiate response packet

FE534D4240000100000000000000010001000000000000000000000000000000FFFE000000000000

000000000000000000000000000000000000000000000000410001001103020039CBCAF329714942

BDCE5D60F09AB3FB27000000000080000000800000008000D04C8443CCAED00109094AB095AED001

80004001C00100006082013C06062B0601050502A08201303082012CA01A3018060A2B0601040182

3702021E060A2B06010401823702020AA282010C048201084E45474F455854530100000000000000

60000000700000007F7CC0FD06D6362D02DDE1CF343BFE2973007DCF55CA793E082B7A257DEFE6E8

E18291ABF112C0599108C772F55CBB2A000000000000000060000000010000000000000000000000

5C33530DEAF90D4DB2EC4AE3786EC3084E45474F4558545303000000010000004000000098000000

7F7CC0FD06D6362D02DDE1CF343BFE295C33530DEAF90D4DB2EC4AE3786EC3084000000058000000

3056A05430523027802530233121301F06035504031318546F6B656E205369676E696E6720507562

6C6963204B65793027802530233121301F06035504031318546F6B656E205369676E696E67205075

626C6963204B6579010026000000000001002000010088AFA422ECC239CB16F30BA641AE4B6EE79F

5A4AF74FE18A301E9790515D07F70000020004000000000001000100

Concatenate Connection.PreauthIntegrityHashValue and Negotiate response packet

SHA-512 Input Hash Data

A3A8A769FEA693B3D037406EF945E115D2B7A4A9318564D2CAAA4B1FE0EC36D8D92A4802619EDCF2

9E2410534D2D3749E71F76ADF5212F959210D291097A6355FE534D42400001000000000000000100

01000000000000000000000000000000FFFE00000000000000000000000000000000000000000000

0000000000000000410001001103020039CBCAF329714942BDCE5D60F09AB3FB2700000000008000

0000800000008000D04C8443CCAED00109094AB095AED00180004001C00100006082013C06062B06

01050502A08201303082012CA01A3018060A2B06010401823702021E060A2B06010401823702020A

A282010C048201084E45474F45585453010000000000000060000000700000007F7CC0FD06D6362D

02DDE1CF343BFE2973007DCF55CA793E082B7A257DEFE6E8E18291ABF112C0599108C772F55CBB2A

0000000000000000600000000100000000000000000000005C33530DEAF90D4DB2EC4AE3786EC308

4E45474F45585453030000000100000040000000980000007F7CC0FD06D6362D02DDE1CF343BFE29

5C33530DEAF90D4DB2EC4AE3786EC30840000000580000003056A05430523027802530233121301F

06035504031318546F6B656E205369676E696E67205075626C6963204B6579302780253023312130

1F06035504031318546F6B656E205369676E696E67205075626C6963204B65790100260000000000

01002000010088AFA422ECC239CB16F30BA641AE4B6EE79F5A4AF74FE18A301E9790515D07F70000

020004000000000001000100

New

Connection.PreauthIntegrityHashValue

A21419AD43D5A4975326E07142734EADA33D0927738F3C1B05A65B003CCAAAE225B547045260356C

2014A21E0A3DFA9EF7B192C375BFFC5F5E766AC3261F0457

Add NEW SessionId 0x100000000021 to Preauth Integrity hash table with value

Connection.PreauthIntegrityHashValue

A21419AD43D5A4975326E07142734EADA33D0927738F3C1B05A65B003CCAAAE225B547045260356C

2014A21E0A3DFA9EF7B192C375BFFC5F5E766AC3261F0457

SESSION SETUP Request

PreauthSession.SessionId 0x100000000021

Current

PreauthSession.PreauthIntegrityHashValue

A21419AD43D5A4975326E07142734EADA33D0927738F3C1B05A65B003CCAAAE225B547045260356C

2014A21E0A3DFA9EF7B192C375BFFC5F5E766AC3261F0457

SessionSetup request packet

FE534D4240000100000000000100800000000000000000000100000000000000FFFE000000000000

00000000000000000000000000000000000000000000000019000001010000000000000058004A00

0000000000000000604806062B0601050502A03E303CA00E300C060A2B06010401823702020AA22A

04284E544C4D5353500001000000978208E200000000000000000000000000000000060380250000

000F

Concatenate PreauthSession.PreauthIntegrityHashValue and Session Setup request packet

SHA-512 Input Hash Data

A21419AD43D5A4975326E07142734EADA33D0927738F3C1B05A65B003CCAAAE225B547045260356C

2014A21E0A3DFA9EF7B192C375BFFC5F5E766AC3261F0457FE534D42400001000000000001008000

00000000000000000100000000000000FFFE00000000000000000000000000000000000000000000

000000000000000019000001010000000000000058004A000000000000000000604806062B060105

0502A03E303CA00E300C060A2B06010401823702020AA22A04284E544C4D53535000010000009782

08E200000000000000000000000000000000060380250000000F

PreauthSession.PreauthIntegrityHashValue

FD10D68FFBB5D94DD483DE14DC8AF92B4D2D8517A5D245FE091C93050AC56239B3B829F74CB25451

276248F12279DCC027C9B53841A67052A617C32C93CBA8C2

SESSION SETUP Response

--- STATUS_MORE_PROCESSING_REQUIRED - Updating Preauth integrity hash ---

PreauthSession.SessionId 0x100000000021

Current

PreauthSession.PreauthIntegrityHashValue

FD10D68FFBB5D94DD483DE14DC8AF92B4D2D8517A5D245FE091C93050AC56239B3B829F74CB25451

276248F12279DCC027C9B53841A67052A617C32C93CBA8C2

SessionSetup response packet

FE534D4240000100160000C00100010001000000000000000100000000000000FFFE000000000000

210000000010000000000000000000000000000000000000090000004800B300A181B03081ADA003

0A0101A10C060A2B06010401823702020AA281970481944E544C4D53535000020000000C000C0038

00000015828AE29296836B33F712E0000000000000000050005000440000000A0092270000000F53

005500540033003100310002000C0053005500540033003100310001000C00530055005400330031

00310004000C0053005500540033003100310003000C005300550054003300310031000700080019

C69C43CCAED00100000000

SessionSetup response header signature 0x00000000000000000000000000000000

Concatenate PreauthSession.PreauthIntegrityHashValue and Session Setup response packet

SHA-512 Input Hash Data

FD10D68FFBB5D94DD483DE14DC8AF92B4D2D8517A5D245FE091C93050AC56239B3B829F74CB25451

276248F12279DCC027C9B53841A67052A617C32C93CBA8C2FE534D4240000100160000C001000100

01000000000000000100000000000000FFFE00000000000021000000001000000000000000000000

0000000000000000090000004800B300A181B03081ADA0030A0101A10C060A2B0601040182370202

0AA281970481944E544C4D53535000020000000C000C003800000015828AE29296836B33F712E000

0000000000000050005000440000000A0092270000000F53005500540033003100310002000C0053

005500540033003100310001000C0053005500540033003100310004000C00530055005400330031

00310003000C005300550054003300310031000700080019C69C43CCAED00100000000

PreauthSession.PreauthIntegrityHashValue

2AA0A0D736D4A3BE4A2FA06B20EEBF02635543C0310F72595ACEAF9893BBE647D9C753175215BB24

71DF365D4FC77AB8D168ECC91ABC02C4611D2AAC33181967

SESSION SETUP Request

PreauthSession.SessionId 0x100000000021

Current

PreauthSession.PreauthIntegrityHashValue

2AA0A0D736D4A3BE4A2FA06B20EEBF02635543C0310F72595ACEAF9893BBE647D9C753175215BB24

71DF365D4FC77AB8D168ECC91ABC02C4611D2AAC33181967

SessionSetup request packet

FE534D4240000100000000000100800000000000000000000200000000000000FFFE000000000000

2100000000100000000000000000000000000000000000001900000101000000000000005800CF01

0000000000000000A18201CB308201C7A0030A0101A28201AA048201A64E544C4D53535000030000

001800180090000000EE00EE00A80000000C000C00580000001A001A0064000000120012007E0000

001000100096010000158288E2060380250000000F3E492B87B2606D263031D0D12B6AD267530055

005400330031003100610064006D0069006E006900730074007200610074006F0072004400520049

005600450052003300310031000000000000000000000000000000000000000000000000009AEF57

4DBD2E8A323B017ED361EEA14B010100000000000019C69C43CCAED00176AC9CBD38378531000000

0002000C0053005500540033003100310001000C0053005500540033003100310004000C00530055

00540033003100310003000C005300550054003300310031000700080019C69C43CCAED001060004

00020000000800300030000000000000000000000000300000B61FEFCAA857EA57BF1EDCEBF8974B

8E0EBA5A6DFD9D07A31D11B548F8C9D0CC0A00100000000000000000000000000000000000090016

0063006900660073002F005300550054003300310031000000000000000000000000005E621187A7

5CC18E3982494ECC4793B7A3120410010000005C661B9E6BE0F1E500000000

Concatenate PreauthSession.PreauthIntegrityHashValue and Session Setup request packet

SHA-512 Input Hash Data

2AA0A0D736D4A3BE4A2FA06B20EEBF02635543C0310F72595ACEAF9893BBE647D9C753175215BB24

71DF365D4FC77AB8D168ECC91ABC02C4611D2AAC33181967FE534D42400001000000000001008000

00000000000000000200000000000000FFFE00000000000021000000001000000000000000000000

00000000000000001900000101000000000000005800CF010000000000000000A18201CB308201C7

A0030A0101A28201AA048201A64E544C4D53535000030000001800180090000000EE00EE00A80000

000C000C00580000001A001A0064000000120012007E0000001000100096010000158288E2060380

250000000F3E492B87B2606D263031D0D12B6AD267530055005400330031003100610064006D0069

006E006900730074007200610074006F007200440052004900560045005200330031003100000000

0000000000000000000000000000000000000000009AEF574DBD2E8A323B017ED361EEA14B010100

000000000019C69C43CCAED00176AC9CBD383785310000000002000C005300550054003300310031

0001000C0053005500540033003100310004000C0053005500540033003100310003000C00530055

0054003300310031000700080019C69C43CCAED00106000400020000000800300030000000000000

000000000000300000B61FEFCAA857EA57BF1EDCEBF8974B8E0EBA5A6DFD9D07A31D11B548F8C9D0

CC0A001000000000000000000000000000000000000900160063006900660073002F005300550054

003300310031000000000000000000000000005E621187A75CC18E3982494ECC4793B7A312041001

0000005C661B9E6BE0F1E500000000

PreauthSession.PreauthIntegrityHashValue

DECF98A420718718F22090D3580FCC5E484BD310FA1268210C6E86335A8891E767F5BCD99FA5A785

9D665AD07A73EA94E1BCDB7CFA69A6962A28A244138340B1

SESSION SETUP Response

SessionId 0x100000000021 COMPLETED

SessionSetup response packet

FE534D4240000100000000000100800009000000000000000200000000000000FFFE000000000000

21000000001000003676196AEE8CA17E5D50A53642EF2BE40900000048001D00A11B3019A0030A01

00A3120410010000000F57444342A2717E00000000

SessionSetup response header signature 0x3676196AEE8CA17E5D50A53642EF2BE4

PreauthSession.PreauthIntegrityHashValue

DECF98A420718718F22090D3580FCC5E484BD310FA1268210C6E86335A8891E767F5BCD99FA5A785

9D665AD07A73EA94E1BCDB7CFA69A6962A28A244138340B1

Input cryptographicKey (SessionKey) 0x07B7F69C1E2581662DF6987E88F9E891

(queried from GSS authenticated context)

--- Dialect 0x0311 ---

preauthIntegrityHashValue

DECF98A420718718F22090D3580FCC5E484BD310FA1268210C6E86335A8891E767F5BCD99FA5A785

9D665AD07A73EA94E1BCDB7CFA69A6962A28A244138340B1

CypherId 0x0001

SessionKey 0x07B7F69C1E2581662DF6987E88F9E891

SigningKey 0x3DCC82C5795AE27F383242761078C59B

EncryptionKey 0xDFAAA31AAE40A2485D47AC4DF09FDA1D

DecryptionKey 0x95C544AEF6072680DA1CE49A68A97FA6

ApplicationKey 0x7A2F0F73EC2D530879B2913BBFCE242F

--- Encryption ---

SessionId 0x100000000021

SessionKey 0x07B7F69C1E2581662DF6987E88F9E891

SigningKey 0x3DCC82C5795AE27F383242761078C59B

EncryptionKey 0xDFAAA31AAE40A2485D47AC4DF09FDA1D

DecryptionKey 0x95C544AEF6072680DA1CE49A68A97FA6

ApplicationKey 0x7A2F0F73EC2D530879B2913BBFCE242F

Header.Command 0x0009 WRITE

Encryption of the request ---

Key 0xDFAAA31AAE40A2485D47AC4DF09FDA1D

Nonce Length 0xb

AES-128-CCM nonce 0x9F6F1EAAD7E9F24AACD38F

SMB2 packet

FE534D4240000100000000000900010008000000000000000500000000000000FFFE000001000000

21000000001000000000000000000000000000000000000031007000170000000000000000000000

0500000004000000010000000400000000000000000000007000000000000000536D623320656E63

72797074696F6E2074657374696E67

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0xE89551D666DAB8993488F5A97103116C

transform_header.Nonce 0x9F6F1EAAD7E9F24AACD38F0000000000

transform_header.OriginalMessageSize 0x87

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000021

Encrypted message

56A74778199A9D2B6E9C3A376FD88D27680694FED253A313BEB07381AE8689F973ACDB8D716E4477

803BCE53A92E1B81FA3E965AD9AF2C89C08CE66A344664453B8FC88118EDC9814CF58E92AA465E6E

FB09958A9FDAD96FBD55B36A710C30D5E7C64AD7B9449F9F17EDD024FE8BA79154F340A82740D1D5

180C69B0A2DE6A4BA893BD55D3210E

Transformed message

FD534D42E89551D666DAB8993488F5A97103116C9F6F1EAAD7E9F24AACD38F000000000087000000

00000100210000000010000056A74778199A9D2B6E9C3A376FD88D27680694FED253A313BEB07381

AE8689F973ACDB8D716E4477803BCE53A92E1B81FA3E965AD9AF2C89C08CE66A344664453B8FC881

18EDC9814CF58E92AA465E6EFB09958A9FDAD96FBD55B36A710C30D5E7C64AD7B9449F9F17EDD024

FE8BA79154F340A82740D1D5180C69B0A2DE6A4BA893BD55D3210E

Decryption of the response ---

Transformed message

FD534D42DD33EC41A927DD51476FE887C2D3C136D96831DD2E8EB7B4000000000000000050000000

000001002100000000100000F783157E0F6F1C055D746753CA16D20C21088E2A67564E056C2F68A7

F14F226C3BD809B7A2D52E5FE4ECF49821BC6001733430CF174E2764B3CCB213AAD8BB9FBAF6C15E

13D9120965390E004A96A3F7

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0xDD33EC41A927DD51476FE887C2D3C136

transform_header.Nonce 0xD96831DD2E8EB7B40000000000000000

transform_header.OriginalMessageSize 0x50

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000021

Key 0x95C544AEF6072680DA1CE49A68A97FA6

Nonce Length 0xb

AES-128-CCM nonce 0xD96831DD2E8EB7B4000000

Decrypted SMB2 packet

FE534D4240000100000000000900010001000000000000000500000000000000FFFE000001000000

21000000001000000000000000000000000000000000000011000000170000000000000000000000

Header.Command 0x0008 READ

Encryption of the request ---

Key 0xDFAAA31AAE40A2485D47AC4DF09FDA1D

Nonce Length 0xb

AES-128-CCM nonce 0xA0F92E964EDC3049B86E19

SMB2 packet

FE534D4240000100000000000800010008000000000000000600000000000000FFFE000001000000

21000000001000000000000000000000000000000000000031000000170000000000000000000000

050000000400000001000000040000000000000000000000000000000000000000

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0x35BF9600C841F0CDA9BD1BC3727B7E36

transform_header.Nonce 0xA0F92E964EDC3049B86E190000000000

transform_header.OriginalMessageSize 0x71

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000021

Encrypted message

C4CCD3EB483A0638E69C99E391E7F64BCC10D6BEE46FEEA258C4BCAF792CB5A6E69283924081806D

AB64827E9D14A5345D5221AB6DAFCB0E89FC2606B63D92163F4F6C93D1213D86ABF123B93EAD3AEF

9A3471EFD68A423A00A6E0064D9AE3C842EFFFAD236A3BF25D37F4CD054C97DE18

Transformed message

FD534D4235BF9600C841F0CDA9BD1BC3727B7E36A0F92E964EDC3049B86E19000000000071000000

000001002100000000100000C4CCD3EB483A0638E69C99E391E7F64BCC10D6BEE46FEEA258C4BCAF

792CB5A6E69283924081806DAB64827E9D14A5345D5221AB6DAFCB0E89FC2606B63D92163F4F6C93

D1213D86ABF123B93EAD3AEF9A3471EFD68A423A00A6E0064D9AE3C842EFFFAD236A3BF25D37F4CD

054C97DE18

Decryption of the response ---

Transformed message

FD534D42E241A13C7E1EE42ECF1FD69F3B8668C6DA6831DD2E8EB7B4000000000000000067000000

00000100210000000010000015D67234FC8358D7BA1BF037ABC8EFD41A0A8F9BB04B16DEB1E85606

BD8C2770823FE6239A286CB3E3D5762ABBD53FD8DE11ED491FE905E146A8FFCE09414AB741103D63

7E28B19C6BA759B399DCC21FAE24CF2A455A13B215FC2857ABB513927F9F271D1C208B

transform_header.ProtocolId 0x424d53fd

transform_header.Signature 0xE241A13C7E1EE42ECF1FD69F3B8668C6

transform_header.Nonce 0xDA6831DD2E8EB7B40000000000000000

transform_header.OriginalMessageSize 0x67

transform_header.Reserved 0x0

transform_header.Flags 0x0001

transform_header.SessionId 0x100000000021

Key 0x95C544AEF6072680DA1CE49A68A97FA6

Nonce Length 0xb

AES-128-CCM nonce 0xDA6831DD2E8EB7B4000000

Decrypted SMB2 packet

FE534D4240000100000000000800010001000000000000000600000000000000FFFE000001000000

21000000001000000000000000000000000000000000000011005000170000000000000000000000

536D623320656E6372797074696F6E2074657374696E67

Appendix B. How to disable SMB1 on Windows

In Windows 8.1 / Server 2012 R2:

?To remove SMB1, use the following PowerShell cmdlet:

Remove-WindowsFeature FS-SMB1

?To add SMB1 feature:

Add-WindowsFeature FS-SMB1

Windows Client

?To disable SMBv1 on the SMB client, run the following commands:

sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi

sc.exe config mrxsmb10 start= disabled

?To enable SMBv1 on the SMB client, run the following commands:

sc.exe config lanmanworkstation depend= bowser/mrxsmb10/mrxsmb20/nsi

sc.exe config mrxsmb10 start= auto

Windows Server

In Windows Server 2012 R2:

Get-SmbServerConfiguration | Select EnableSMB1Protocol, EnableSMB2Protocol

?To disable SMBv1 on the SMB server, run the following cmdlet:

Set-SmbServerConfiguration -EnableSMB1Protocol $false

?To enable SMBv1 on the SMB server, run the following cmdlet:

Set-SmbServerConfiguration -EnableSMB1Protocol $true

In older server versions:

?To disable SMBv1 on the SMB server, run the following cmdlet:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 0 –Force

?To enable SMBv1 on the SMB server, run the following cmdlet:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 1 –Force

[References]

[MS-SMB2]: Server Message Block (SMB) Protocol Versions 2 and 3 Specification

[SP800-108] National Institute of Standards and Technology. "Special Publication 800-108, Recommendation for Key Derivation Using Pseudorandom Functions", October 2009, http://csrc.nist.gov/publications/nistpubs/800-108/sp800-108.pdf

[RFC5084] Housley, R., "Using AES-CCM and AES-GCM Authenticated Encryption in the Cryptographic Message Syntax (CMS)", RFC 5084, November 2007, http://www.ietf.org/rfc/rfc5084.txt

How to enable and disable SMBv1, SMBv2, and SMBv3 in Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012

https://support.microsoft.com/en-us/kb/2696547

總結

以上是生活随笔為你收集整理的signature=095ed28e83b68620637b3a67436b0f8f,SMB 3.1.1 Encryption in Windows 10的全部內容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網站內容還不錯,歡迎將生活随笔推薦給好友。

欧美成人影音 | 久久久高清一区二区三区 | 亚洲欧美乱综合图片区小说区 | 超碰97网站 | 国产精品中文字幕在线 | 国产小视频免费在线观看 | 久久黄色a级片 | 99精品久久久久久久 | 国产在线视频一区二区三区 | 久久综合九色欧美综合狠狠 | 亚洲国产黄色片 | 久久精品美女视频网站 | 日本黄色片一区二区 | 亚洲激情视频 | 亚洲精品资源在线观看 | 91高清视频免费 | 成人黄色电影在线观看 | 日本中文字幕在线观看 | 66av99精品福利视频在线 | 日韩欧美视频在线观看免费 | 亚洲最大av | 精品久久久久国产 | 五月天久久狠狠 | 久久久久久久久久久久久影院 | 免费激情在线电影 | 国产黄色免费观看 | 久久精品99久久久久久2456 | 日韩一二三在线 | 国产剧情一区 | 国产成人精品一区二区三区福利 | 中文字幕av最新更新 | 精品视频在线免费 | 精品国产中文字幕 | 国产精品久久久久9999 | 五月婷婷电影网 | 成人av亚洲| 99精品国产在热久久下载 | 日韩欧美精品免费 | 久久国产精品久久w女人spa | 免费视频三区 | 91桃色在线播放 | 成人在线视频一区 | 激情电影影院 | 色插综合 | 黄色网址a | 久久99精品久久久久久久久久久久 | 国产亚洲精品久久久久久大师 | 国产亚洲精品综合一区91 | 有码中文字幕在线观看 | 国产高清在线 | 国产成人久久精品亚洲 | 欧美日韩午夜在线 | 十八岁以下禁止观看的1000个网站 | 91手机视频在线 | 日本少妇久久久 | 狠狠干 狠狠操 | 久久免费视频在线观看6 | 日韩精品在线观看av | 亚州国产视频 | 久久久久国产一区二区 | 99久久99 | 免费在线a| 一区二区三区在线看 | 中国一级片在线观看 | 国产亚洲在线 | 欧美一级免费高清 | 亚洲综合成人av | 99国产精品久久久久久久久久 | 人人搞人人干 | 91精品久久香蕉国产线看观看 | 永久免费精品视频网站 | 亚洲国产网址 | 久久国内精品 | 最近日本字幕mv免费观看在线 | 午夜国产一区 | 免费无遮挡动漫网站 | www久久com| 国产特级毛片aaaaaaa高清 | 精品亚洲视频在线观看 | 99久久久成人国产精品 | 久久久久久久久久久久国产精品 | 五月天婷婷在线观看视频 | 亚洲国产精品成人精品 | 国产精品区在线观看 | 免费91麻豆精品国产自产在线观看 | 九七视频在线观看 | 玖操 | 日韩免费在线观看 | 欧美日韩精品在线免费观看 | 91桃色免费视频 | 91av在线免费播放 | 综合久久一本 | 狠狠色伊人亚洲综合成人 | 国产精品美女久久久久久久久 | 91高清视频 | 国产韩国精品一区二区三区 | 久久99热久久99精品 | 在线观看你懂的网站 | 久久电影中文字幕视频 | 亚洲最大成人免费网站 | 亚洲精品看片 | 亚洲欧美日韩在线一区二区 | 久久在线免费视频 | 五月天色丁香 | 欧美日韩性 | 日韩 精品 一区 国产 麻豆 | 成人在线视 | 日韩视频中文字幕在线观看 | 婷婷丁香激情网 | 色婷婷欧美 | 欧美亚洲精品一区 | 激情图片区 | 久久综合之合合综合久久 | 色夜影院 | 国内精品国产三级国产aⅴ久 | 国产999在线观看 | 91在线免费看片 | 亚洲视频免费视频 | 午夜久久久影院 | 国产黄在线 | 国产精品免费观看久久 | 99热国产在线 | 中文字幕免费观看视频 | 中文字幕精 | 亚洲不卡在线 | 激情av网址 | 午夜久久久久久久久久影院 | 国产中文字幕在线 | 成人va天堂 | 99热精品免费观看 | 超碰在线9| 福利二区视频 | 国产视频丨精品|在线观看 国产精品久久久久久久久久久久午夜 | 日本黄色a级大片 | 久久久久草 | 天堂视频中文在线 | 免费亚洲成人 | 久久久久黄 | 91在线免费观看网站 | 免费精品在线观看 | 成人在线播放免费观看 | 九精品| 中文字幕中文中文字幕 | 激情视频在线观看网址 | 一区二区欧美激情 | 免费在线观看日韩视频 | 亚洲成人国产精品 | 欧美精品久久久久久久 | 91视频啊啊啊 | 国产精久久久久久久 | 福利av影院 | 久久99久久99精品中文字幕 | 成人三级黄色 | av手机版 | 久久美女电影 | 香蕉视频在线看 | 精品国精品自拍自在线 | 91麻豆免费视频 | 久艹在线观看视频 | 免费在线观看中文字幕 | 在线探花| av在线免费观看不卡 | 夜夜爽88888免费视频4848 | 毛片网站免费 | 韩国三级一区 | 久久国产热 | 免费一级片在线 | 在线观看一级 | 一区二区三区四区不卡 | 91在线精品观看 | 成人丝袜 | 久久 精品一区 | 久久久99精品免费观看 | 亚洲一级免费观看 | 欧美极度另类性三渗透 | 欧美a级片网站 | 国产丝袜美腿在线 | 黄网站免费看 | 国产99一区| 狠狠色婷婷丁香六月 | 免费在线观看黄网站 | 99精品黄色片免费大全 | 黄色动态图xx | 人人干在线观看 | 久久视频99| 亚洲撸撸 | 一级一级一片免费 | 97色视频在线 | 久久久.com | 成人在线观看资源 | 欧美一区二区在线免费看 | 三级在线国产 | 国产高清av免费在线观看 | 99精品视频免费在线观看 | 亚洲综合欧美激情 | 99久久精品日本一区二区免费 | 国产精品欧美一区二区三区不卡 | 免费日韩一区二区 | 日b视频在线观看网址 | 中文字幕一区二区三 | 欧美久久精品 | av日韩中文| 日韩理论影院 | av观看免费在线 | 深爱激情站 | 中文字幕亚洲欧美日韩2019 | 精品国产三级a∨在线欧美 免费一级片在线观看 | 精品美女久久久久 | 日韩av资源站| 亚洲天堂色婷婷 | 中文字幕综合在线 | 久久免费视频在线观看 | 亚洲成免费| 亚洲一区二区精品3399 | 9色在线视频 | 热久久视久久精品18亚洲精品 | 天天色天天色 | 久久久久成人精品免费播放动漫 | 丁香亚洲| 成人av免费网站 | 中文字幕不卡在线88 | 久久久999免费视频 日韩网站在线 | 亚洲狠狠操| 日本黄区免费视频观看 | 欧美最新另类人妖 | 97超碰总站 | 日韩久久一区 | 久久久国产精品人人片99精片欧美一 | 日韩美女免费线视频 | 最近2019中文免费高清视频观看www99 | 久草在线视频网 | 日韩在线| 久久精品国产一区二区三区 | 亚洲成人中文在线 | 免费黄色小网站 | 韩国av免费在线观看 | 国产成人在线网站 | 午夜国产一区二区 | 精品一区电影 | 色丁香色婷婷 | 日韩久久精品一区二区 | 亚洲aⅴ在线 | 一本色道久久精品 | 久久久一本精品99久久精品66 | 2021国产视频| 91精品视频播放 | 久久艹精品 | 黄色在线免费观看网址 | 视频二区在线 | 久久一及片| 97色在线观看免费视频 | 亚洲黄色成人av | 国产高清在线a视频大全 | 亚洲日本欧美 | 国产无套精品久久久久久 | 久久成人在线 | 激情视频二区 | 日韩欧美综合视频 | 国产在线观看午夜 | 深夜免费福利视频 | 亚洲精品玖玖玖av在线看 | 国产不卡网站 | 综合网成人 | 久久精品—区二区三区 | 国内精品美女在线观看 | 色偷偷88欧美精品久久久 | 中文字幕五区 | 日韩精品久久久久久中文字幕8 | a久久久久 | 国产成人性色生活片 | 国产精品午夜av | 国产资源站 | 91麻豆精品国产自产在线游戏 | 中文字幕在线一区二区三区 | 欧美伦理一区二区 | 9999亚洲 | 黄色a视频免费 | 日韩精品不卡在线 | 婷婷深爱激情 | 在线免费高清一区二区三区 | av黄色影院 | 在线观看麻豆av | 国产第一福利 | 亚洲影视九九影院在线观看 | 丁香六月婷婷激情 | 又黄又爽的免费高潮视频 | 日韩精品视频在线免费观看 | 99视频精品视频高清免费 | 超碰97成人 | 操操日| 欧美日韩三级在线观看 | 亚洲欧洲av| 国产午夜三级一区二区三桃花影视 | 日韩av在线网站 | 日韩久久一区二区 | 91成人短视频在线观看 | 97精品欧美91久久久久久 | 久久久www免费电影网 | 国语对白少妇爽91 | 久爱综合| 美女久久网站 | 国产成人一区二区三区电影 | 午夜免费福利视频 | 欧美日韩在线免费视频 | 色综合久久久 | 91污在线 | 亚洲欧美成aⅴ人在线观看 四虎在线观看 | 成人中文字幕av | 欧美国产一区在线 | 久久91网| 成人永久在线 | 日韩动漫免费观看高清完整版在线观看 | 精品在线视频播放 | 亚洲精品国产精品久久99热 | 国产亚洲在线视频 | 97香蕉久久国产在线观看 | 97激情影院 | 日韩高清成人 | 亚洲国产成人精品在线 | 国产日产精品久久久久快鸭 | 日韩精品久久久免费观看夜色 | 国产免费大片 | 天天天天综合 | 亚洲二区精品 | 丁香视频全集免费观看 | 91九色精品 | 亚洲春色奇米影视 | 99精品一区二区三区 | 日韩免费电影一区二区三区 | 日韩欧美在线观看 | av网站在线观看免费 | 日日操天天操狠狠操 | 在线免费看黄网站 | 欧美精品二区 | 丰满少妇久久久 | 天天射天天干天天插 | 在线看岛国av | 日韩在线观看三区 | 久久综合中文色婷婷 | 91精品在线免费 | 91精品国产91| 免费高清国产 | 奇米网在线观看 | 欧美在线久久 | 国产亚洲精品久久久久久久久久久久 | 黄色三级av | 少妇性aaaaaaaaa视频 | 天天操天天操天天操天天操天天操 | 久久精品电影院 | 香蕉91视频 | 国产精品高潮久久av | 在线观看免费色 | 中文字幕亚洲精品日韩 | 久久一区91 | 欧美精品一区二区蜜臀亚洲 | 国产又粗又硬又长又爽的视频 | 亚洲免费永久精品国产 | 精品久久网| av在线等 | 国产精品黄色影片导航在线观看 | 国产日产在线观看 | 日韩在线视频线视频免费网站 | www.玖玖玖 | 久久精品日韩 | 国产精品久久久久久久久久免费 | 欧美国产亚洲精品久久久8v | 五月激情婷婷丁香 | 亚洲另类久久 | 国产清纯在线 | 国产一区视频免费在线观看 | 欧美成人va| 在线观看www. | 久久成年人| 久久精品视频18 | 99精品偷拍视频一区二区三区 | 天天干夜夜想 | 天天干,天天射,天天操,天天摸 | 欧美日韩在线第一页 | 日本在线观看黄色 | 97夜夜澡人人双人人人喊 | av大全在线看| 欧美日韩aa | 丁香五婷 | 成人av日韩 | 亚洲午夜精品一区二区三区电影院 | 国产亚洲精品久久久久久久久久久久 | 正在播放日韩 | 精品在线亚洲视频 | 成人精品影视 | 在线观看 国产 | 中文字幕视频网 | 国产精品男女 | 黄色国产在线观看 | 国产精品欧美久久久久天天影视 | 久久久久这里只有精品 | 亚洲无在线 | 久久视频在线观看中文字幕 | 免费成人黄色 | 亚洲乱码精品久久久 | 亚洲精品激情 | av久久久| 国产在线美女 | 黄色一级在线视频 | 日韩二区三区 | 亚洲国产精品500在线观看 | 亚洲资源网| adn—256中文在线观看 | 在线观看韩日电影免费 | 成人avav | 91麻豆精品国产91久久久无需广告 | 欧美激情综合五月色丁香 | 久久这里只有精品视频99 | 国产精品video爽爽爽爽 | 国产精品久久久久久久久久东京 | 成年人视频在线免费 | 五月婷婷综合在线观看 | 岛国av在线不卡 | 91最新在线 | 毛片无卡免费无播放器 | 国产精品自产拍在线观看中文 | 午夜精品久久久久久久久久久久 | 午夜日b视频 | 国产在线久久久 | 精品少妇一区二区三区在线 | 91精品国产欧美一区二区 | 日韩美精品视频 | 日日干日日操 | 欧洲一区二区在线观看 | 国产一区二区三区黄 | 99久久爱 | 国产一区在线免费观看视频 | 久久国产精品99久久人人澡 | 日韩激情一二三区 | 欧美一级电影在线观看 | 国产精品视频在线观看 | 亚洲aⅴ久久精品 | 91在线视频观看 | 国产 一区二区三区 在线 | 国产99久久久精品 | 国产传媒中文字幕 | 美女一二三区 | 97夜夜澡人人爽人人免费 | 成人免费视频播放 | 久精品一区 | 久久91网| 狠狠狠狠狠狠干 | 草久久影院 | 91最新视频| 亚洲片在线观看 | 999久久久免费精品国产 | 天天射天天色天天干 | 成人av教育 | 亚洲国产一区二区精品专区 | 天天干天天干天天干 | av线上看 | 97国产小视频 | 久久爱导航 | 精品久久久久久久久中文字幕 | 欧美一级片在线播放 | 久久看毛片 | 久久视频网 | 亚洲成a人片77777潘金莲 | 久久伦理视频 | 四虎成人精品永久免费av九九 | 日韩av手机在线看 | 欧美性受极品xxxx喷水 | 久久手机在线视频 | 超碰在线成人 | 久久精品国产精品亚洲 | 日韩一区在线播放 | 国产免费观看视频 | 五月婷激情 | 91av在线看 | 国产一级电影网 | 亚洲欧洲av| 日韩理论电影在线 | 国产精品v欧美精品v日韩 | 久久99亚洲网美利坚合众国 | 久久综合色综合88 | 在线观看亚洲专区 | 欧美中文字幕久久 | 视频在线观看入口黄最新永久免费国产 | 亚洲精品字幕在线 | 中文字幕电影网 | h动漫中文字幕 | 久久久精品免费观看 | 久久精品这里都是精品 | 免费色av| 国产3p视频 | 99免费视频 | 韩国精品一区二区三区六区色诱 | 91av在线免费 | 碰天天操天天 | 国产在线精品福利 | 精品视频国产 | 人人爽人人爽人人片av免 | av成人在线网站 | 正在播放 久久 | 日日夜夜操av | 国产又粗又猛又爽 | 婷婷在线综合 | 久久精彩免费视频 | 亚洲专区在线 | 亚洲精品中文在线资源 | 国产黄色精品 | 一级精品视频在线观看宜春院 | 色一级片| 国内精品久久影院 | 五月激情五月激情 | 中文字幕视频一区 | 91av资源网 | 色综合五月 | 在线视频区 | 丁香视频全集免费观看 | 久久久精品国产免费观看一区二区 | 国产精品久久一区二区无卡 | 亚洲天堂网站 | av在线超碰 | 又污又黄的网站 | 一区在线观看 | 久草在线综合网 | 亚洲三级黄色 | 日韩日韩日韩日韩 | 国产大陆亚洲精品国产 | 色婷五月| 国产精品久久久久久久久久久久午夜片 | 久久99欧美 | 久草视频免费在线观看 | 色综合天天爱 | 亚洲影视九九影院在线观看 | 精品高清视频 | 日韩高清三区 | 免费看污的网站 | 99久久国产免费,99久久国产免费大片 | av资源免费看| 毛片在线网 | 欧美日韩国产一区 | 夜夜操夜夜干 | 888av| 亚洲精品在线视频观看 | www.久久成人 | 中文字幕一区二区三区乱码在线 | 久草视频免费在线播放 | av电影在线播放 | 久章草在线观看 | 一区二区三区免费在线观看 | 亚洲国产中文字幕 | 色偷偷88888欧美精品久久久 | 久草在线观看视频免费 | 成人黄色在线 | 免费中文字幕 | 国产在线视频一区二区三区 | 97超碰成人 | 91视频黄色 | 99热这里精品 | 成人精品999| 国产三级香港三韩国三级 | 日韩国产精品一区 | 欧美射射射 | 一区二区不卡在线观看 | 久久综合五月婷婷 | 亚洲综合狠狠干 | 青青草视频精品 | 激情视频免费在线 | 国产视频一区在线播放 | 免费观看v片在线观看 | 久久久久久久久久久久影院 | 亚洲精品短视频 | 久久人人97超碰com | 久久久久久久看片 | 午夜资源站 | 天天干,天天射,天天操,天天摸 | 国产精品亚洲片夜色在线 | 久久久久久久综合色一本 | 久久成 | 国产精品99精品 | 亚洲视频久久久久 | 欧美精品色 | 欧美在线观看视频免费 | 99精品视频免费观看视频 | 四虎免费在线观看 | www.天天干 | 亚洲视屏| av中文字幕免费在线观看 | 日韩电影精品 | 国产成人亚洲在线观看 | 国产涩涩在线观看 | 久久电影色 | 日韩成人在线免费观看 | 欧美色图一区 | av天天干| 五月天色丁香 | 久久调教视频 | 97超碰精品| 激情五月激情综合网 | 日韩精品在线免费播放 | 黄色aaa级片 | 免费国产一区二区 | 91大神精品视频在线观看 | 国产人成精品一区二区三 | 韩国在线视频一区 | 久久久精品久久日韩一区综合 | 免费观看日韩 | 久久久www成人免费精品 | 美女国产在线 | 免费91麻豆精品国产自产在线观看 | 久久久福利 | 贫乳av女优大全 | 午夜婷婷在线播放 | 婷婷在线播放 | 中文字幕在线观看免费 | 国产色视频网站 | 99精品视频免费观看视频 | 中文字幕精| 国产亚洲精品成人av久久ww | 91中文字幕在线视频 | 中文字幕在线看视频国产 | 中文字幕91视频 | 日韩免费看视频 | av中文字幕在线播放 | 欧美九九九| www.天天色.com | 国产成人精品不卡 | 麻豆久久久 | 三级黄色大片在线观看 | av网站在线免费观看 | 国产精品va在线播放 | 午夜精品久久久久99热app | 天堂网一区二区三区 | 免费高清在线观看电视网站 | 国产乱对白刺激视频在线观看女王 | 国产精品人成电影在线观看 | 国产日韩精品久久 | 欧美国产日韩久久 | 天天射天天爱天天干 | 免费av网址在线观看 | 色噜噜在线观看 | 日本午夜在线亚洲.国产 | 久久99精品一区二区三区三区 | 黄色大片视频网站 | 97在线视频免费观看 | 丁香婷婷自拍 | 波多野结衣视频一区二区三区 | 国产免费一区二区三区最新 | 国产日韩欧美在线影视 | 国产中文字幕av | 国产精品一区二区三区视频免费 | 亚洲人成精品久久久久 | 日韩高清精品一区二区 | 亚洲人毛片 | 91超级碰| 成人在线视频在线观看 | 亚洲女在线 | 精品一二三区 | 天天干天天干天天操 | av观看网站 | 日批在线观看 | 亚洲a资源 | 欧美日韩视频在线播放 | 欧美精品一区二区免费 | 亚洲成a人片77777kkkk1在线观看 | 欧美不卡在线 | 91中文字幕永久在线 | 中文字幕91在线 | 久久老司机精品视频 | 中文资源在线观看 | 久久综合狠狠综合 | 欧亚久久 | 色婷婷在线观看视频 | 99日韩精品 | 黄色在线观看免费 | 日韩在线视频二区 | 日本三级不卡视频 | 欧美精品乱码久久久久久按摩 | a色视频 | 国产传媒一区在线 | 在线观看视频三级 | 久久99久久99免费视频 | 国产成人精品一区二区三区在线观看 | 在线观看日本高清mv视频 | 日韩超碰 | 亚洲精品玖玖玖av在线看 | 欧美国产日韩在线观看 | 免费精品视频在线 | 国产成人精品免高潮在线观看 | 91福利社区在线观看 | 97超碰精品 | 天天干,狠狠干 | 蜜臀av麻豆| 在线成人国产 | 国产女v资源在线观看 | 久草在线手机观看 | 国产成人精品一区二区三区福利 | 国产精品国产三级国产 | 久久久国产精品电影 | 91亚洲精品久久久久图片蜜桃 | 91麻豆精品91久久久久同性 | 亚洲日本色 | 手机成人在线电影 | 亚洲专区在线播放 | 国产精品99久久99久久久二8 | www.午夜视频 | 麻豆视频免费入口 | 久久久午夜精品理论片中文字幕 | 国产精品一区二区三区久久久 | 国产91精品一区二区麻豆网站 | 国产中文字幕在线视频 | 国产经典 欧美精品 | 成人h动漫精品一区二 | 亚洲精品免费在线观看视频 | 国产视频高清 | 91在线免费观看国产 | 日韩在线观看精品 | 日韩在线观看视频在线 | 国产亚洲欧美日韩高清 | 二区中文字幕 | 又污又黄的网站 | 国产看片免费 | 国产日韩精品一区二区 | 国产精品中文字幕在线观看 | av免费网站 | 人人爽网站 | 日韩av电影一区 | 亚洲人视频在线 | 国产又粗又硬又爽视频 | 久久精品国产成人精品 | 免费中文字幕 | www.99热精品 | 欧美福利精品 | 亚洲少妇天堂 | 久久九九影视网 | 久久久久高清毛片一级 | 国产精品综合在线 | 99久久精品免费看国产四区 | 精品久久久久一区二区国产 | 国产三级午夜理伦三级 | 成人免费观看在线视频 | 欧美日韩国产一二三区 | 免费看一级一片 | 国产日韩精品欧美 | 玖玖视频 | 久久精品2| 色.www| 最近免费中文字幕大全高清10 | 成人a视频片观看免费 | 久久久久久久久久久免费av | 91视频啊啊啊| 免费看一及片 | 成人h视频 | 开心色激情网 | 天天操夜操 | 久久99精品久久只有精品 | 亚洲综合在线视频 | 亚洲永久免费av | 久久婷婷一区二区三区 | 日韩av高清在线观看 | 久久99久国产精品黄毛片入口 | 中文字幕在线观看完整 | 亚洲高清在线 | 天天综合网久久综合网 | 日韩美女免费线视频 | 国产日韩精品一区二区三区在线 | 亚洲视频1区2区 | 伊人精品在线 | 久久天天躁狠狠躁夜夜不卡公司 | 免费视频99 | 91精品爽啪蜜夜国产在线播放 | 麻豆 videos | 六月激情婷婷 | 99免费在线视频观看 | 成人毛片在线观看视频 | 日本黄色一级电影 | 丁香综合av | 国产精品都在这里 | 久久艹国产视频 | 精品欧美在线视频 | 国产日产精品久久久久快鸭 | 日韩在线观看一区二区 | 亚洲色图激情文学 | 在线国产能看的 | 亚洲人成影院在线 | 久久亚洲私人国产精品 | 黄色软件视频大全免费下载 | 日韩啪视频 | 国产又粗又硬又爽视频 | 97人人视频 | 中文字幕电影一区 | 五月婷在线观看 | 人人要人人澡人人爽人人dvd | 看污网站 | 精品毛片在线 | 日本一区二区不卡高清 | av在线播放不卡 | 国产成人三级一区二区在线观看一 | 色就干| www.狠狠色.com | 成人免费在线视频 | 免费国产亚洲视频 | 久久视屏网 | 麻豆免费视频观看 | 免费日韩 | 亚洲精品乱码白浆高清久久久久久 | 国产精品久久久久久久久软件 | 最近中文字幕大全 | 久久精品最新 | 亚洲三级性片 | 在线看中文字幕 | 国产破处在线视频 | 99国产精品视频免费观看一公开 | 在线看片91 | 四虎在线免费视频 | 亚洲精品国产综合久久 | 久草免费手机视频 | 99在线视频观看 | 最新国产精品久久精品 | 国产精品第10页 | 精品国产1区2区3区 国产欧美精品在线观看 | 在线观看的av | 在线免费观看涩涩 | 国产97在线视频 | 在线免费91 | 精品在线播放 | www·22com天天操 | 97超碰在线久草超碰在线观看 | 日本一区二区免费在线观看 | 久久久免费看 | 久久综合九色欧美综合狠狠 | 黄色高清视频在线观看 | 精品一区二区在线看 | 在线免费观看一区二区三区 | av东方在线| 亚洲精品一区二区网址 | 久久久精品综合 | 亚洲男模gay裸体gay | 视频在线精品 | 黄色一级在线免费观看 | 色偷偷88欧美精品久久久 | 日本xxxx裸体xxxx17 | 国产成人精品久久亚洲高清不卡 | 九九热在线观看 | 99精品国产高清在线观看 | 亚洲午夜精品在线观看 | 国产 成人 久久 | 青青五月天 | 亚洲国产精品电影 | 婷婷视频在线 | 日韩久久电影 | 亚洲成人黄色 | 日韩精品一区二区三区在线视频 | 日韩精品一区二区在线观看视频 | 久久公开视频 | 中文字幕一区二 | 在线观看成人国产 | 天天精品视频 | 黄色亚洲在线 | 日韩免费大片 | 亚洲成av人片 | 中文字幕人成乱码在线观看 | 一级做a爱片性色毛片www | 精品一区 在线 | 精品美女在线视频 | 久久久精品国产一区二区 | 日韩综合在线观看 | 四虎永久免费 | 一本之道乱码区 | 国产精品成人一区二区三区吃奶 | 婷婷爱五月天 | 有码中文字幕在线观看 | 91精品视频免费看 | 亚洲黄色片在线 | 国产精品露脸在线 | 天天操天天添天天吹 | 久久96国产精品久久99漫画 | 亚洲国产日韩精品 | 91在线免费视频 | 国产一区在线视频 | av在线免费网 | 亚洲精品国偷拍自产在线观看蜜桃 | 97人人模人人爽人人喊中文字 | 精品一区二区免费 | 亚洲乱亚洲乱亚洲 | 欧美一级在线 | 亚洲精品视频在线观看免费视频 | 福利在线看片 | 这里只有精品视频在线 | 色综合咪咪久久网 | 九七在线视频 | 国产综合精品久久 | 91亚洲精品久久久蜜桃 | www.五月天激情 | 久久国产精品偷 | 精品1区二区 | 国产黄影院色大全免费 | 激情综合站 | 99视频免费在线观看 | 国产喷水在线 | 欧美久草视频 | 亚州日韩中文字幕 | 亚洲精品视频在线观看网站 | 国产精品99久久久久久大便 | 日韩av在线高清 | 欧美va电影 | 操操操人人人 | 色综合久久88色综合天天6 | 日韩1级片| 国产精品一区二区视频 | 少妇bbb搡bbbb搡bbbb | 另类五月激情 | 亚洲伊人成综合网 | 丁香激情网 | 亚洲美女视频在线观看 | 国产精品国产三级国产不产一地 | 91精品国产成人www | 玖玖爱在线观看 | 午夜在线看 | 美女免费av | 午夜在线看片 | 97人人添人澡人人爽超碰动图 | 色丁香色婷婷 | 91av视频在线免费观看 | 日韩免费视频一区二区 | 又黄又爽的视频在线观看网站 | 三级黄色a | 91手机在线看片 | 久久网站最新地址 | 在线视频久 | 亚洲va在线va天堂va偷拍 | 亚洲成人频道 | 在线免费91 | 日韩午夜电影院 | 91| 9在线观看免费 | 激情久久五月 | 在线免费av网 | 99精品国产视频 | 欧美成a人片在线观看久 | 国产欧美日韩精品一区二区免费 | 香蕉影院在线观看 | 激情亚洲综合在线 | 久久精品视频播放 | 久久tv| 成人免费在线播放视频 | 91福利社在线观看 | 99久久精品午夜一区二区小说 | 亚洲精品乱码白浆高清久久久久久 | 日本中文在线播放 | 黄色.com| 91福利视频免费观看 | 日韩精品一区在线播放 | 黄色a在线| 亚洲天天 | 在线观看的av | 91桃色国产在线播放 | 国产精品99久久久久久宅男 | 日韩a欧美 | 日本精品一区二区三区在线播放视频 | 日韩免费电影网站 | 一区二区三区视频网站 | 亚洲91精品在线观看 | 久久精品一二区 | 成人国产精品久久久 | 91av网站在线观看 | 91污污 | 亚洲涩涩网站 | 爱爱一区 | 欧美日韩国产亚洲乱码字幕 | 在线免费高清视频 | 久久久久福利视频 | 91亚洲精品乱码久久久久久蜜桃 | 国产中文欧美日韩在线 | 国产黄色av影视 | 精品在线观看一区二区三区 | 免费a网址 | 成人免费影院 | 久久这里只有精品首页 | 国产成人一区二区精品非洲 | 中文国产字幕 | 成人高清在线观看 | 色婷在线 | 99久久综合国产精品二区 | 在线视频你懂 | 五月婷激情 | av丝袜美腿| 日韩色在线| 一级黄色a视频 | www.com.日本一级 | 日韩 在线观看 | 99精品在线免费在线观看 | 国产不卡视频在线播放 | 欧美作爱视频 | 欧美性极品xxxx娇小 | 国产精品女主播一区二区三区 | 久草在线中文888 | 在线观看亚洲a | 91看片在线| 成人免费网站视频 | 国产高清视频在线观看 | 亚洲黄色在线播放 |