The real prize would be the domain server and since you are using 98 machines and possibly samba the DC must answer LM authentication requests, if your 'attacker' is on the LAN with you he may as...