Turns out I should not have tried changing
#define DEFAULT_SSPI_PACKAGE to "NEGOTIATE" (errors out on win2k3 server talking to Firefox client; works okay with IE clients though)
reverting to
+#define DEFAULT_SSPI_PACKAGE "NTLM"
per original sources.
Also added a check for NULL conentLen, just to be safe.
fixes bug introduced by IE patch