The Samba-Bugzilla – Attachment 2172 Details for
Bug 4150
samba (ldap) don't allow login for users if he exists in many groups
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
debug 5 from win machine tryes to login with testing user
g-marchenko.smb (text/plain), 70.78 KB, created by
Gennady G. Marchenko
on 2006-10-04 07:22:51 UTC
(
hide
)
Description:
debug 5 from win machine tryes to login with testing user
Filename:
MIME Type:
Creator:
Gennady G. Marchenko
Created:
2006-10-04 07:22:51 UTC
Size:
70.78 KB
patch
obsolete
>[2006/10/04 16:00:49, 3] smbd/process.c:process_smb(1110) > Transaction 5312 of length 43 >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(478) >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(488) > size=39 > smb_com=0x74 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=0 > smb_pid=65279 > smb_uid=171 > smb_mid=38082 > smt_wct=2 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:00:49, 3] smbd/process.c:switch_message(914) > switch message SMBulogoffX (pid 285) conn 0x0 >[2006/10/04 16:00:49, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:00:49, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:00:49, 3] smbd/reply.c:reply_ulogoffX(1618) > ulogoffX vuid=171 >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(478) >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(488) > size=39 > smb_com=0x74 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=0 > smb_pid=65279 > smb_uid=171 > smb_mid=38082 > smt_wct=2 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:00:49, 3] smbd/process.c:process_smb(1110) > Transaction 5313 of length 39 >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(478) >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(488) > size=35 > smb_com=0x71 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=2 > smb_pid=65279 > smb_uid=171 > smb_mid=38146 > smt_wct=0 > smb_bcc=0 >[2006/10/04 16:00:49, 3] smbd/process.c:switch_message(914) > switch message SMBtdis (pid 285) conn 0x8411030 >[2006/10/04 16:00:49, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:00:49, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:00:49, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:00:49, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:00:49, 3] smbd/service.c:close_cnum(1141) > g-marchenko (10.0.0.167) closed connection to service IPC$ >[2006/10/04 16:00:49, 3] smbd/connection.c:yield_connection(69) > Yielding connection to IPC$ >[2006/10/04 16:00:49, 4] smbd/vfs.c:vfs_ChDir(741) > vfs_ChDir to / >[2006/10/04 16:00:49, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:00:49, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:00:49, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(478) >[2006/10/04 16:00:49, 5] lib/util.c:show_msg(488) > size=35 > smb_com=0x71 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=2 > smb_pid=65279 > smb_uid=171 > smb_mid=38146 > smt_wct=0 > smb_bcc=0 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5314 of length 240 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=236 > smb_com=0x73 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=0 > smb_pid=65279 > smb_uid=0 > smb_mid=38210 > smt_wct=12 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 236 (0xEC) > smb_vwv[ 2]=16644 (0x4104) > smb_vwv[ 3]= 50 (0x32) > smb_vwv[ 4]= 1 (0x1) > smb_vwv[ 5]= 0 (0x0) > smb_vwv[ 6]= 0 (0x0) > smb_vwv[ 7]= 74 (0x4A) > smb_vwv[ 8]= 0 (0x0) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 212 (0xD4) > smb_vwv[11]=40960 (0xA000) > smb_bcc=177 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBsesssetupX (pid 285) conn 0x0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_sesssetup_and_X(849) > wct=12 flg2=0xc807 >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(660) > Doing spnego session setup >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(691) > NativeOS=[Windows 2002 Service Pack 2 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[] >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_spnego_negotiate(551) > Got OID 1 3 6 1 4 1 311 2 2 10 >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_spnego_negotiate(554) > Got secblob of size 40 >[2006/10/04 16:01:03, 5] auth/auth.c:make_auth_context_subsystem(484) > Making default auth method list for DC, security=user, encrypt passwords = yes >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match guest >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method guest has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match sam >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method sam has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match winbind:trustdomain >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match trustdomain >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method trustdomain has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method winbind has a valid init >[2006/10/04 16:01:03, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(63) > Got NTLMSSP neg_flags=0xe2088297 > NTLMSSP_NEGOTIATE_UNICODE > NTLMSSP_NEGOTIATE_OEM > NTLMSSP_REQUEST_TARGET > NTLMSSP_NEGOTIATE_SIGN > NTLMSSP_NEGOTIATE_LM_KEY > NTLMSSP_NEGOTIATE_NTLM > NTLMSSP_NEGOTIATE_ALWAYS_SIGN > NTLMSSP_NEGOTIATE_NTLM2 > NTLMSSP_NEGOTIATE_128 > NTLMSSP_NEGOTIATE_KEY_EXCH > NTLMSSP_NEGOTIATE_56 >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(97) > auth_get_challenge: module guest did not want to specify a challenge >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(97) > auth_get_challenge: module sam did not want to specify a challenge >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(97) > auth_get_challenge: module winbind did not want to specify a challenge >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(137) > auth_context challenge created by random >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(138) > challenge is: >[2006/10/04 16:01:03, 5] lib/util.c:dump_data(2215) > [000] 18 D6 9A 51 E7 52 2D 43 ...Q.R-C >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=312 > smb_com=0x73 > smb_rcls=22 > smb_reh=0 > smb_err=49152 > smb_flg=136 > smb_flg2=51201 > smb_tid=0 > smb_pid=65279 > smb_uid=172 > smb_mid=38210 > smt_wct=4 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 0 (0x0) > smb_vwv[ 3]= 205 (0xCD) > smb_bcc=269 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5315 of length 284 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=280 > smb_com=0x73 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=0 > smb_pid=65279 > smb_uid=172 > smb_mid=38274 > smt_wct=12 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 280 (0x118) > smb_vwv[ 2]=16644 (0x4104) > smb_vwv[ 3]= 50 (0x32) > smb_vwv[ 4]= 1 (0x1) > smb_vwv[ 5]= 0 (0x0) > smb_vwv[ 6]= 0 (0x0) > smb_vwv[ 7]= 119 (0x77) > smb_vwv[ 8]= 0 (0x0) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 212 (0xD4) > smb_vwv[11]=40960 (0xA000) > smb_bcc=221 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBsesssetupX (pid 285) conn 0x0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_sesssetup_and_X(849) > wct=12 flg2=0xc807 >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(660) > Doing spnego session setup >[2006/10/04 16:01:03, 3] smbd/sesssetup.c:reply_sesssetup_and_X_spnego(691) > NativeOS=[Windows 2002 Service Pack 2 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[] >[2006/10/04 16:01:03, 3] libsmb/ntlmssp.c:ntlmssp_server_auth(672) > Got user=[] domain=[] workstation=[G-MARCHENKO] len1=1 len2=0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info_map(161) > make_user_info_map: Mapping user []\[] from workstation [G-MARCHENKO] >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(0) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] auth/auth_util.c:is_trusted_domain(2019) > is_trusted_domain: Checking for domain trust with [ITVGROUP.CXM] >[2006/10/04 16:01:03, 5] passdb/secrets.c:secrets_fetch_trusted_domain_password(340) > secrets_fetch failed! >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] libsmb/trustdom_cache.c:trustdom_cache_fetch(184) > no entry for trusted domain ITVGROUP.CXM found. >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info(75) > attempting to make a user_info for () >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info(85) > making strings for 's user_info struct >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info(117) > making blobs for 's user_info struct >[2006/10/04 16:01:03, 3] auth/auth.c:check_ntlm_password(221) > check_ntlm_password: Checking password for unmapped user []\[]@[G-MARCHENKO] with the new password interface >[2006/10/04 16:01:03, 3] auth/auth.c:check_ntlm_password(224) > check_ntlm_password: mapped user is: [ITVGROUP.CXM]\[]@[G-MARCHENKO] >[2006/10/04 16:01:03, 5] lib/util.c:dump_data(2215) > [000] 18 D6 9A 51 E7 52 2D 43 ...Q.R-C >[2006/10/04 16:01:03, 4] lib/substitute.c:automount_server(407) > Home server: msk >[2006/10/04 16:01:03, 3] passdb/lookup_sid.c:fetch_gid_from_cache(1015) > fetch gid from cache 513 -> S-1-5-21-3254449052-227629570-3895272170-513 >[2006/10/04 16:01:03, 3] auth/auth.c:check_ntlm_password(270) > check_ntlm_password: guest authentication for user [] succeeded >[2006/10/04 16:01:03, 5] auth/auth.c:check_ntlm_password(309) > check_ntlm_password: guest authentication for user [] -> [] -> [nobody] succeeded >[2006/10/04 16:01:03, 5] auth/auth_util.c:free_user_info(1866) > attempting to free (and zero) a user_info structure >[2006/10/04 16:01:03, 3] passdb/lookup_sid.c:fetch_gid_from_cache(1015) > fetch gid from cache 544 -> S-1-5-32-544 >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(sambaSID=S-1-5-32-545))], scope => [2] >[2006/10/04 16:01:03, 4] passdb/pdb_ldap.c:ldapsam_getgroup(2213) > ldapsam_getgroup: Did not find group >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(|(objectclass=sambaGroupMapping)(sambaGroupType=4))(|(sambaSIDList=S-1-5-21-3254449052-227629570-3895272170-501)(sambaSIDList=S-1-1-0)(sambaSIDList=S-1-5-2)(sambaSIDList=S-1-5-32-546)))], scope => [2] >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(|(objectclass=sambaGroupMapping)(sambaGroupType=4))(|(sambaSIDList=S-1-5-21-3254449052-227629570-3895272170-501)(sambaSIDList=S-1-1-0)(sambaSIDList=S-1-5-2)(sambaSIDList=S-1-5-32-546)))], scope => [2] >[2006/10/04 16:01:03, 3] lib/privileges.c:get_privileges(261) > get_privileges: No privileges assigned to SID [S-1-5-21-3254449052-227629570-3895272170-501] >[2006/10/04 16:01:03, 5] lib/privileges.c:get_privileges_for_sids(459) > get_privileges_for_sids: sid = S-1-1-0 > Privilege set: > SE_PRIV 0x0 0x0 0x0 0x0 >[2006/10/04 16:01:03, 3] lib/privileges.c:get_privileges(261) > get_privileges: No privileges assigned to SID [S-1-5-2] >[2006/10/04 16:01:03, 3] lib/privileges.c:get_privileges(261) > get_privileges: No privileges assigned to SID [S-1-5-32-546] >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(sambaSID=S-1-1-0))], scope => [2] >[2006/10/04 16:01:03, 4] passdb/pdb_ldap.c:ldapsam_getgroup(2213) > ldapsam_getgroup: Did not find group >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(sambaSID=S-1-5-2))], scope => [2] >[2006/10/04 16:01:03, 4] passdb/pdb_ldap.c:ldapsam_getgroup(2213) > ldapsam_getgroup: Did not find group >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(sambaSID=S-1-5-32-546))], scope => [2] >[2006/10/04 16:01:03, 4] passdb/pdb_ldap.c:ldapsam_getgroup(2213) > ldapsam_getgroup: Did not find group >[2006/10/04 16:01:03, 3] libsmb/ntlmssp_sign.c:ntlmssp_sign_init(338) > NTLMSSP Sign/Seal - Initialising with flags: >[2006/10/04 16:01:03, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(63) > Got NTLMSSP neg_flags=0xe2088215 > NTLMSSP_NEGOTIATE_UNICODE > NTLMSSP_REQUEST_TARGET > NTLMSSP_NEGOTIATE_SIGN > NTLMSSP_NEGOTIATE_NTLM > NTLMSSP_NEGOTIATE_ALWAYS_SIGN > NTLMSSP_NEGOTIATE_NTLM2 > NTLMSSP_NEGOTIATE_128 > NTLMSSP_NEGOTIATE_KEY_EXCH > NTLMSSP_NEGOTIATE_56 >[2006/10/04 16:01:03, 3] smbd/password.c:register_vuid(280) > User name: nobody Real name: Unprivileged user >[2006/10/04 16:01:03, 3] smbd/password.c:register_vuid(301) > UNIX uid 65534 is UNIX user nobody, and will be vuid 173 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=116 > smb_com=0x73 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=0 > smb_pid=65279 > smb_uid=173 > smb_mid=38274 > smt_wct=4 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 0 (0x0) > smb_vwv[ 3]= 9 (0x9) > smb_bcc=73 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5316 of length 76 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=72 > smb_com=0x75 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=0 > smb_pid=65279 > smb_uid=173 > smb_mid=38338 > smt_wct=4 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 72 (0x48) > smb_vwv[ 2]= 8 (0x8) > smb_vwv[ 3]= 1 (0x1) > smb_bcc=29 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBtconX (pid 285) conn 0x0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:03, 4] smbd/reply.c:reply_tcon_and_X(668) > Client requested device type [?????] for share [IPC$] >[2006/10/04 16:01:03, 5] smbd/service.c:make_connection(1116) > making a connection to 'normal' service ipc$ >[2006/10/04 16:01:03, 3] lib/access.c:check_access(312) > check_access: no hostnames in host allow/deny list. >[2006/10/04 16:01:03, 2] lib/access.c:check_access(323) > Allowed connection from (10.0.0.167) >[2006/10/04 16:01:03, 5] lib/username.c:Get_Pwnam_alloc(131) > Finding user nobody >[2006/10/04 16:01:03, 5] lib/username.c:Get_Pwnam_internals(75) > Trying _Get_Pwnam(), username as lowercase is nobody >[2006/10/04 16:01:03, 5] lib/username.c:Get_Pwnam_internals(108) > Get_Pwnam_internals did find user [nobody]! >[2006/10/04 16:01:03, 3] smbd/service.c:make_connection_snum(752) > Connect path is '/tmp' for service [IPC$] >[2006/10/04 16:01:03, 4] lib/sharesec.c:get_share_security(130) > get_share_security: using default secdesc for IPC$ >[2006/10/04 16:01:03, 3] lib/util_seaccess.c:se_access_check(250) >[2006/10/04 16:01:03, 3] lib/util_seaccess.c:se_access_check(251) > se_access_check: user sid is S-1-5-21-3254449052-227629570-3895272170-501 > se_access_check: also S-1-1-0 > se_access_check: also S-1-5-2 > se_access_check: also S-1-5-32-546 >[2006/10/04 16:01:03, 5] lib/util_seaccess.c:se_access_check(308) > se_access_check: access (2) granted. >[2006/10/04 16:01:03, 3] smbd/vfs.c:vfs_init_default(219) > Initialising default vfs hooks >[2006/10/04 16:01:03, 5] smbd/connection.c:claim_connection(170) > claiming IPC$ 0 >[2006/10/04 16:01:03, 4] lib/sharesec.c:get_share_security(130) > get_share_security: using default secdesc for IPC$ >[2006/10/04 16:01:03, 3] lib/util_seaccess.c:se_access_check(250) >[2006/10/04 16:01:03, 3] lib/util_seaccess.c:se_access_check(251) > se_access_check: user sid is S-1-5-21-3254449052-227629570-3895272170-501 > se_access_check: also S-1-1-0 > se_access_check: also S-1-5-2 > se_access_check: also S-1-5-32-546 >[2006/10/04 16:01:03, 5] lib/util_seaccess.c:se_access_check(308) > se_access_check: access (1) granted. >[2006/10/04 16:01:03, 3] lib/util_sid.c:string_to_sid(223) > string_to_sid: Sid @wheel does not start with 'S-'. >[2006/10/04 16:01:03, 5] smbd/password.c:user_in_netgroup(427) > looking for user nobody of domain in netgroup wheel >[2006/10/04 16:01:03, 5] smbd/password.c:user_in_netgroup(443) > looking for user nobody of domain in netgroup wheel >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(0) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(|(displayName=wheel)(cn=wheel)))], scope => [2] >[2006/10/04 16:01:03, 4] passdb/pdb_ldap.c:ldapsam_getgroup(2213) > ldapsam_getgroup: Did not find group >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(454) > NT user token of user S-1-5-21-3254449052-227629570-3895272170-501 > contains 4 SIDs > SID[ 0]: S-1-5-21-3254449052-227629570-3895272170-501 > SID[ 1]: S-1-1-0 > SID[ 2]: S-1-5-2 > SID[ 3]: S-1-5-32-546 > SE_PRIV 0x0 0x0 0x0 0x0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 65534 > Primary group is 65534 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] smbd/uid.c:change_to_user(260) > change_to_user uid=(65534,65534) gid=(0,65534) >[2006/10/04 16:01:03, 3] smbd/service.c:make_connection_snum(941) > g-marchenko (10.0.0.167) connect to service IPC$ initially as user nobody (uid=65534, gid=65534) (pid 285) >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:03, 2] smbd/reply.c:reply_tcon_and_X(711) > Serving IPC$ as a Dfs root >[2006/10/04 16:01:03, 3] smbd/reply.c:reply_tcon_and_X(716) > tconX service=IPC$ >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=48 > smb_com=0x75 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38338 > smt_wct=3 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 3 (0x3) > smb_bcc=7 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5317 of length 108 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=104 > smb_com=0xa2 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=932 > smb_uid=173 > smb_mid=38402 > smt_wct=24 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]=57054 (0xDEDE) > smb_vwv[ 2]= 4608 (0x1200) > smb_vwv[ 3]= 5632 (0x1600) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 0 (0x0) > smb_vwv[ 6]= 0 (0x0) > smb_vwv[ 7]=40704 (0x9F00) > smb_vwv[ 8]= 513 (0x201) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 0 (0x0) > smb_vwv[11]= 0 (0x0) > smb_vwv[12]= 0 (0x0) > smb_vwv[13]= 0 (0x0) > smb_vwv[14]= 0 (0x0) > smb_vwv[15]= 768 (0x300) > smb_vwv[16]= 0 (0x0) > smb_vwv[17]= 256 (0x100) > smb_vwv[18]= 0 (0x0) > smb_vwv[19]=16384 (0x4000) > smb_vwv[20]=16384 (0x4000) > smb_vwv[21]= 512 (0x200) > smb_vwv[22]= 0 (0x0) > smb_vwv[23]= 256 (0x100) > smb_bcc=21 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBntcreateX (pid 285) conn 0x840a030 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(454) > NT user token of user S-1-5-21-3254449052-227629570-3895272170-501 > contains 4 SIDs > SID[ 0]: S-1-5-21-3254449052-227629570-3895272170-501 > SID[ 1]: S-1-1-0 > SID[ 2]: S-1-5-2 > SID[ 3]: S-1-5-32-546 > SE_PRIV 0x0 0x0 0x0 0x0 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 65534 > Primary group is 65534 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] smbd/uid.c:change_to_user(260) > change_to_user uid=(65534,65534) gid=(0,65534) >[2006/10/04 16:01:03, 4] smbd/vfs.c:vfs_ChDir(741) > vfs_ChDir to /tmp >[2006/10/04 16:01:03, 4] smbd/nttrans.c:nt_open_pipe(325) > nt_open_pipe: Opening pipe \NETLOGON. >[2006/10/04 16:01:03, 3] smbd/nttrans.c:nt_open_pipe(346) > nt_open_pipe: Known pipe NETLOGON opening. >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:open_rpc_pipe_p(180) > Open pipe requested NETLOGON (pipes_open=1) >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:open_rpc_pipe_p(210) > open_rpc_pipe_p: name spoolss pnum=7325 >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:make_internal_rpc_pipe_p(285) > Create pipe requested NETLOGON >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:make_internal_rpc_pipe_p(366) > Created internal pipe NETLOGON (pipes_open=1) >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:open_rpc_pipe_p(263) > Opened pipe NETLOGON with handle 7372 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:open_rpc_pipe_p(269) > open pipes: name NETLOGON pnum=7372 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:open_rpc_pipe_p(269) > open pipes: name spoolss pnum=7325 >[2006/10/04 16:01:03, 5] smbd/nttrans.c:do_ntcreate_pipe_open(395) > do_ntcreate_pipe_open: open pipe = \NETLOGON >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=103 > smb_com=0xa2 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=932 > smb_uid=173 > smb_mid=38402 > smt_wct=34 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]=29184 (0x7200) > smb_vwv[ 3]= 371 (0x173) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 0 (0x0) > smb_vwv[ 6]= 0 (0x0) > smb_vwv[ 7]= 0 (0x0) > smb_vwv[ 8]= 0 (0x0) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 0 (0x0) > smb_vwv[11]= 0 (0x0) > smb_vwv[12]= 0 (0x0) > smb_vwv[13]= 0 (0x0) > smb_vwv[14]= 0 (0x0) > smb_vwv[15]= 0 (0x0) > smb_vwv[16]= 0 (0x0) > smb_vwv[17]= 0 (0x0) > smb_vwv[18]= 0 (0x0) > smb_vwv[19]= 0 (0x0) > smb_vwv[20]= 0 (0x0) > smb_vwv[21]=32768 (0x8000) > smb_vwv[22]= 0 (0x0) > smb_vwv[23]= 0 (0x0) > smb_vwv[24]= 0 (0x0) > smb_vwv[25]= 0 (0x0) > smb_vwv[26]= 0 (0x0) > smb_vwv[27]= 0 (0x0) > smb_vwv[28]= 0 (0x0) > smb_vwv[29]= 0 (0x0) > smb_vwv[30]= 0 (0x0) > smb_vwv[31]= 512 (0x200) > smb_vwv[32]=65280 (0xFF00) > smb_vwv[33]= 5 (0x5) > smb_bcc=0 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5318 of length 194 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=190 > smb_com=0x2f > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38466 > smt_wct=14 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]=57054 (0xDEDE) > smb_vwv[ 2]=29554 (0x7372) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]=65535 (0xFFFF) > smb_vwv[ 6]=65535 (0xFFFF) > smb_vwv[ 7]= 8 (0x8) > smb_vwv[ 8]= 126 (0x7E) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 126 (0x7E) > smb_vwv[11]= 64 (0x40) > smb_vwv[12]= 0 (0x0) > smb_vwv[13]= 0 (0x0) > smb_bcc=127 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBwriteX (pid 285) conn 0x840a030 >[2006/10/04 16:01:03, 4] smbd/uid.c:change_to_user(176) > change_to_user: Skipping user change - already user >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1264) > search for pipe pnum=7372 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name NETLOGON pnum=7372 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name spoolss pnum=7325 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0000 major : 05 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0001 minor : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0002 pkt_type : 0b >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0003 flags : 07 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0004 pack_type0: 10 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0005 pack_type1: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0006 pack_type2: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0007 pack_type3: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0008 frag_len : 007e >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 000a auth_len : 002e >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000c call_id : 00000002 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(482) > unmarshall_rpc_header: using little-endian RPC >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe.c:api_pipe_bind_req(1523) > api_pipe_bind_req: decode request. 1523 >[2006/10/04 16:01:03, 3] rpc_server/srv_pipe.c:api_pipe_bind_req(1534) > api_pipe_bind_req: \PIPE\NETLOGON -> \PIPE\lsass >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr_rb >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0000 max_tsize: 10b8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0002 max_rsize: 10b8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0004 assoc_gid: 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0008 num_contexts: 01 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 000c context_id : 0000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 000e num_transfer_syntaxes: 01 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0010 data : 12345678 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0014 data : 1234 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0016 data : abcd >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0018 data : ef 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 001a data : 01 23 45 67 cf fb >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0020 version: 00000001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0024 data : 8a885d04 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0028 data : 1ceb >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 002a data : 11c9 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 002c data : 9f e8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 002e data : 08 00 2b 10 48 60 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0034 version: 00000002 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe.c:api_pipe_bind_req(1576) > api_pipe_bind_req: make response. 1576 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000038 smb_io_rpc_hdr_auth >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0038 auth_type : 44 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0039 auth_level : 06 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 003a auth_pad_len : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 003b auth_reserved: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 003c auth_context_id: 000cc668 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000040 smb_io_rpc_auth_schannel_neg >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0040 type1: 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0044 type2: 00000013 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 3] passdb/secrets.c:secrets_restore_schannel_session_info(1089) > secrets_restore_schannel_session_info: restored schannel info key SECRETS/SCHANNEL/G-MARCHENKO >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr_auth >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0000 auth_type : 44 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0001 auth_level : 06 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0002 auth_pad_len : 08 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0003 auth_reserved: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0004 auth_context_id: 00000001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000008 smb_io_rpc_schannel_verifier >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000a msg_type : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0010 flags : 00000005 >[2006/10/04 16:01:03, 3] rpc_server/srv_pipe.c:check_bind_req(985) > check_bind_req for \PIPE\NETLOGON >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr_ba >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0000 max_tsize: 10b8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0002 max_rsize: 10b8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0004 assoc_gid: 000053f0 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0008 len: 000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 000a str: \PIPE\lsass. >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0018 num_results: 01 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 001c result : 0000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 001e reason : 0000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0020 data : 8a885d04 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0024 data : 1ceb >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0026 data : 11c9 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0028 data : 9f e8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 002a data : 08 00 2b 10 48 60 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0030 version: 00000002 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0000 major : 05 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0001 minor : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0002 pkt_type : 0c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0003 flags : 03 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0004 pack_type0: 10 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0005 pack_type1: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0006 pack_type2: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0007 pack_type3: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0008 frag_len : 0058 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 000a auth_len : 000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000c call_id : 00000002 >[2006/10/04 16:01:03, 3] smbd/pipes.c:reply_pipe_write_and_X(217) > writeX-IPC pnum=7372 nwritten=126 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=47 > smb_com=0x2f > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38466 > smt_wct=6 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 126 (0x7E) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5319 of length 63 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=59 > smb_com=0x2e > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38530 > smt_wct=12 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]=57054 (0xDEDE) > smb_vwv[ 2]=29554 (0x7372) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 1024 (0x400) > smb_vwv[ 6]= 1024 (0x400) > smb_vwv[ 7]=65535 (0xFFFF) > smb_vwv[ 8]=65535 (0xFFFF) > smb_vwv[ 9]= 1024 (0x400) > smb_vwv[10]= 0 (0x0) > smb_vwv[11]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBreadX (pid 285) conn 0x840a030 >[2006/10/04 16:01:03, 4] smbd/uid.c:change_to_user(176) > change_to_user: Skipping user change - already user >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1264) > search for pipe pnum=7372 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name NETLOGON pnum=7372 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name spoolss pnum=7325 (pipes_open=2) >[2006/10/04 16:01:03, 3] smbd/pipes.c:reply_pipe_read_and_X(262) > readX-IPC pnum=7372 min=1024 max=1024 nread=88 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=147 > smb_com=0x2e > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38530 > smt_wct=12 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 0 (0x0) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 88 (0x58) > smb_vwv[ 6]= 59 (0x3B) > smb_vwv[ 7]= 0 (0x0) > smb_vwv[ 8]= 0 (0x0) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 0 (0x0) > smb_vwv[11]= 0 (0x0) > smb_bcc=88 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5320 of length 436 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=432 > smb_com=0x2f > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38594 > smt_wct=14 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]=57054 (0xDEDE) > smb_vwv[ 2]=29554 (0x7372) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]=65535 (0xFFFF) > smb_vwv[ 6]=65535 (0xFFFF) > smb_vwv[ 7]= 8 (0x8) > smb_vwv[ 8]= 368 (0x170) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 368 (0x170) > smb_vwv[11]= 64 (0x40) > smb_vwv[12]= 0 (0x0) > smb_vwv[13]= 0 (0x0) > smb_bcc=369 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBwriteX (pid 285) conn 0x840a030 >[2006/10/04 16:01:03, 4] smbd/uid.c:change_to_user(176) > change_to_user: Skipping user change - already user >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1264) > search for pipe pnum=7372 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name NETLOGON pnum=7372 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name spoolss pnum=7325 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0000 major : 05 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0001 minor : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0002 pkt_type : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0003 flags : 03 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0004 pack_type0: 10 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0005 pack_type1: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0006 pack_type2: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0007 pack_type3: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0008 frag_len : 0170 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 000a auth_len : 0020 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000c call_id : 00000002 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(482) > unmarshall_rpc_header: using little-endian RPC >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr_req req >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0000 alloc_hint: 00000124 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0004 context_id: 0000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0006 opnum : 0002 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe.c:api_pipe_schannel_process(2086) > data 304 auth 32 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000138 smb_io_rpc_hdr_auth hdr_auth >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0138 auth_type : 44 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0139 auth_level : 06 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 013a auth_pad_len : 0c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 013b auth_reserved: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 013c auth_context_id: 000cc668 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000140 smb_io_rpc_auth_schannel_chk >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0140 sig : 77 00 7a 00 ff ff 00 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0148 seq_num: 6e f7 5c 54 0e 9e 53 21 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0150 packet_digest: 24 8e b6 ee 64 f9 ad 4f >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0158 confounder: 9c 1b bb ce 47 44 95 32 >[2006/10/04 16:01:03, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(529) > free_pipe_context: destroying talloc pool of size 72 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe.c:api_pipe_request(2223) > Requested \PIPE\NETLOGON >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe.c:api_rpcTNP(2258) > api_rpcTNP: NETLOGON op 0x2 - api_rpcTNP: rpc command: NET_SAMLOGON >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 net_io_q_sam_logon >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0000 undoc_buffer : 000d34f8 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0004 uni_max_len: 00000006 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0008 offset : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000c uni_str_len: 00000006 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:dbg_rw_punival(936) > 0010 buffer : \.\.M.S.K... >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 001c undoc_buffer2: 000cfb98 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0020 uni_max_len: 0000000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0024 offset : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0028 uni_str_len: 0000000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:dbg_rw_punival(936) > 002c buffer : G.-.M.A.R.C.H.E.N.K.O... >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0044 ptr_cred: 0007f2f0 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0048 data: bc 24 89 be b9 5c e3 f5 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0050 time: 4523a0c9 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0054 ptr_rtn_cred : 0007f2fc >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0058 data: bc 09 91 7c 00 00 09 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0060 time: 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0064 logon_level : 0001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0066 switch_value : 0001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0068 ptr_id_info1: 0007f7c0 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 006c uni_str_len: 0018 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 006e uni_max_len: 0018 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0070 buffer : 000fcd84 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0074 param_ctrl: 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0078 low : 045134d5 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 007c high: 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0080 uni_str_len: 000e >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0082 uni_max_len: 000e >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0084 buffer : 000fcd74 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0088 uni_str_len: 0016 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 008a uni_max_len: 0018 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 008c buffer : 000a9ec0 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0090 data: bf 06 cf 86 69 52 17 cd 86 92 09 f1 71 0b c4 24 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 00a0 data: fb 2d 6c cd ab ed 47 89 82 9e 47 ea be c9 5f 8e >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00b0 uni_max_len: 0000000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00b4 offset : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00b8 uni_str_len: 0000000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:dbg_rw_punival(936) > 00bc buffer : I.T.V.G.R.O.U.P...C.X.M. >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00d4 uni_max_len: 00000007 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00d8 offset : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00dc uni_str_len: 00000007 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:dbg_rw_punival(936) > 00e0 buffer : t.e.s.t.i.n.g. >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00f0 uni_max_len: 0000000c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00f4 offset : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 00f8 uni_str_len: 0000000b >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:dbg_rw_punival(936) > 00fc buffer : G.-.M.A.R.C.H.E.N.K.O. >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0112 validation_level: 0003 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 3] passdb/secrets.c:secrets_restore_schannel_session_info(1089) > secrets_restore_schannel_session_info: restored schannel info key SECRETS/SCHANNEL/G-MARCHENKO >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_step(148) > sequence = 0x4523a0c9 >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_step(150) > seed: B207435864C22561 >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_step(155) > seed+seq 7BA8669D64C22561 >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_step(159) > CLIENT BC2489BEB95CE3F5 >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_step(164) > seed+seq+1 7CA8669D64C22561 >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_step(168) > SERVER B8EEAB93A1E3E40D >[2006/10/04 16:01:03, 5] libsmb/credentials.c:creds_reseed(238) > cred_reseed: seed 7CA8669D64C22561 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 3] passdb/secrets.c:secrets_store_schannel_session_info(995) > secrets_store_schannel_session_info: stored schannel info with key SECRETS/SCHANNEL/G-MARCHENKO >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] rpc_server/srv_netlog_nt.c:_net_sam_logon_internal(840) > SAM Logon (Interactive). Domain:[ITVGROUP.CXM]. User:[testing@G-MARCHENKO] Requested Domain:[ITVGROUP.CXM] >[2006/10/04 16:01:03, 5] rpc_server/srv_netlog_nt.c:_net_sam_logon_internal(862) > Attempting validation level 1 for unmapped username testing. >[2006/10/04 16:01:03, 5] auth/auth.c:make_auth_context_subsystem(484) > Making default auth method list for DC, security=user, encrypt passwords = yes >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match guest >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method guest has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match sam >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method sam has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match winbind:trustdomain >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(391) > load_auth_module: Attempting to find an auth method to match trustdomain >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method trustdomain has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:load_auth_module(416) > load_auth_module: auth method winbind has a valid init >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(97) > auth_get_challenge: module guest did not want to specify a challenge >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(97) > auth_get_challenge: module sam did not want to specify a challenge >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(97) > auth_get_challenge: module winbind did not want to specify a challenge >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(137) > auth_context challenge created by random >[2006/10/04 16:01:03, 5] auth/auth.c:get_ntlm_challenge(138) > challenge is: >[2006/10/04 16:01:03, 5] lib/util.c:dump_data(2215) > [000] D7 21 00 88 B4 45 23 E8 .!...E#. >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info_map(161) > make_user_info_map: Mapping user [ITVGROUP.CXM]\[testing] from workstation [G-MARCHENKO] >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] auth/auth_util.c:is_trusted_domain(2019) > is_trusted_domain: Checking for domain trust with [ITVGROUP.CXM] >[2006/10/04 16:01:03, 5] passdb/secrets.c:secrets_fetch_trusted_domain_password(340) > secrets_fetch failed! >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 5] libsmb/trustdom_cache.c:trustdom_cache_fetch(184) > no entry for trusted domain ITVGROUP.CXM found. >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info(75) > attempting to make a user_info for testing (testing) >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info(85) > making strings for testing's user_info struct >[2006/10/04 16:01:03, 5] auth/auth_util.c:make_user_info(117) > making blobs for testing's user_info struct >[2006/10/04 16:01:03, 3] auth/auth.c:check_ntlm_password(221) > check_ntlm_password: Checking password for unmapped user [ITVGROUP.CXM]\[testing]@[G-MARCHENKO] with the new password interface >[2006/10/04 16:01:03, 3] auth/auth.c:check_ntlm_password(224) > check_ntlm_password: mapped user is: [ITVGROUP.CXM]\[testing]@[G-MARCHENKO] >[2006/10/04 16:01:03, 5] lib/util.c:dump_data(2215) > [000] D7 21 00 88 B4 45 23 E8 .!...E#. >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [dc=itvgroup,dc=ru], filter => [(&(uid=testing)(objectclass=sambaSamAccount))], scope => [2] >[2006/10/04 16:01:03, 2] passdb/pdb_ldap.c:init_sam_from_ldap(541) > init_sam_from_ldap: Entry found for user: testing >[2006/10/04 16:01:03, 4] lib/substitute.c:automount_server(407) > Home server: msk >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(gidNumber=513))], scope => [2] >[2006/10/04 16:01:03, 2] passdb/pdb_ldap.c:init_group_from_ldap(2136) > init_group_from_ldap: Entry found for group: 513 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] passdb/pdb_interface.c:lookup_global_sam_rid(1478) > lookup_global_sam_rid: looking up RID 513. >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 2 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [dc=itvgroup,dc=ru], filter => [(&(sambaSID=S-1-5-21-3254449052-227629570-3895272170-513)(objectclass=sambaSamAccount))], scope => [2] >[2006/10/04 16:01:03, 4] passdb/pdb_ldap.c:ldapsam_getsampwsid(1491) > ldapsam_getsampwsid: Unable to locate SID [S-1-5-21-3254449052-227629570-3895272170-513] count=0 >[2006/10/04 16:01:03, 5] lib/smbldap.c:smbldap_search_ext(1179) > smbldap_search_ext: base => [ou=Groups,dc=itvgroup,dc=ru], filter => [(&(objectClass=sambaGroupMapping)(sambaSID=S-1-5-21-3254449052-227629570-3895272170-513))], scope => [2] >[2006/10/04 16:01:03, 2] passdb/pdb_ldap.c:init_group_from_ldap(2136) > init_group_from_ldap: Entry found for group: 513 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2 >[2006/10/04 16:01:03, 5] passdb/pdb_interface.c:pdb_default_lookup_rids(1599) > lookup_rids: Domain Users:2 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 4] lib/substitute.c:automount_server(407) > Home server: msk >[2006/10/04 16:01:03, 3] passdb/lookup_sid.c:fetch_gid_from_cache(1015) > fetch gid from cache 513 -> S-1-5-21-3254449052-227629570-3895272170-513 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 4] auth/auth_sam.c:sam_account_ok(138) > sam_account_ok: Checking SMB password for user testing >[2006/10/04 16:01:03, 5] auth/auth_sam.c:logon_hours_ok(120) > logon_hours_ok: user testing allowed to logon at this time (Wed Oct 4 12:01:03 2006 > ) >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:push_sec_ctx(208) > push_sec_ctx(65534, 65534) : sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 3] smbd/uid.c:push_conn_ctx(345) > push_conn_ctx(173) : conn_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1 >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:03, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:03, 0] lib/system_smbd.c:getgroups_unix_user(179) > get_user_groups: failed to get the unix group list >[2006/10/04 16:01:03, 3] smbd/sec_ctx.c:pop_sec_ctx(339) > pop_sec_ctx (65534, 65534) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:03, 0] auth/auth_sam.c:check_sam_security(352) > check_sam_security: make_server_info_sam() failed with 'NT_STATUS_NO_SUCH_USER' >[2006/10/04 16:01:03, 5] auth/auth.c:check_ntlm_password(273) > check_ntlm_password: sam authentication for user [testing] FAILED with error NT_STATUS_NO_SUCH_USER >[2006/10/04 16:01:03, 3] auth/auth_winbind.c:check_winbind_security(80) > check_winbind_security: Not using winbind, requested domain [ITVGROUP.CXM] was for this SAM. >[2006/10/04 16:01:03, 2] auth/auth.c:check_ntlm_password(319) > check_ntlm_password: Authentication for user [testing] -> [testing] FAILED with error NT_STATUS_NO_SUCH_USER >[2006/10/04 16:01:03, 5] auth/auth_util.c:free_user_info(1866) > attempting to free (and zero) a user_info structure >[2006/10/04 16:01:03, 5] rpc_server/srv_netlog_nt.c:_net_sam_logon_internal(934) > _net_sam_logon: check_password returned status NT_STATUS_NO_SUCH_USER >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 net_io_r_sam_logon >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0000 buffer_creds: 00000001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0004 data: b8 ee ab 93 a1 e3 e4 0d >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000c time: 4523a0ca >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0010 switch_value: 0003 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0014 ptr_user_info : 00000000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0018 auth_resp : 00000001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_ntstatus(763) > 001c status : NT_STATUS_NO_SUCH_USER >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe.c:api_rpcTNP(2305) > api_rpcTNP: called NETLOGON successfully >[2006/10/04 16:01:03, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(529) > free_pipe_context: destroying talloc pool of size 682 >[2006/10/04 16:01:03, 3] smbd/pipes.c:reply_pipe_write_and_X(217) > writeX-IPC pnum=7372 nwritten=368 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=47 > smb_com=0x2f > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38594 > smt_wct=6 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 368 (0x170) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:01:03, 3] smbd/process.c:process_smb(1110) > Transaction 5321 of length 63 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=59 > smb_com=0x2e > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38658 > smt_wct=12 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]=57054 (0xDEDE) > smb_vwv[ 2]=29554 (0x7372) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 1024 (0x400) > smb_vwv[ 6]= 1024 (0x400) > smb_vwv[ 7]=65535 (0xFFFF) > smb_vwv[ 8]=65535 (0xFFFF) > smb_vwv[ 9]= 1024 (0x400) > smb_vwv[10]= 0 (0x0) > smb_vwv[11]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:01:03, 3] smbd/process.c:switch_message(914) > switch message SMBreadX (pid 285) conn 0x840a030 >[2006/10/04 16:01:03, 4] smbd/uid.c:change_to_user(176) > change_to_user: Skipping user change - already user >[2006/10/04 16:01:03, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1264) > search for pipe pnum=7372 >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name NETLOGON pnum=7372 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name spoolss pnum=7325 (pipes_open=2) >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000000 smb_io_rpc_hdr hdr >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0000 major : 05 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0001 minor : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0002 pkt_type : 02 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0003 flags : 03 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0004 pack_type0: 10 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0005 pack_type1: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0006 pack_type2: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0007 pack_type3: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0008 frag_len : 0060 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 000a auth_len : 0020 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 000c call_id : 00000002 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000010 smb_io_rpc_hdr_resp resp >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 0010 alloc_hint: 00000020 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint16(675) > 0014 context_id: 0000 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0016 cancel_ct : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0017 reserved : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000038 smb_io_rpc_hdr_auth hdr_auth >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0038 auth_type : 44 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 0039 auth_level : 06 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 003a auth_pad_len : 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8(615) > 003b auth_reserved: 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint32(704) > 003c auth_context_id: 00000001 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_debug(84) > 000040 smb_io_rpc_auth_schannel_chk >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0040 sig : 77 00 7a 00 ff ff 00 00 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0048 seq_num: d0 7f 39 96 0d ac 24 0c >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0050 packet_digest: 80 a5 89 f1 de 1b 4c c3 >[2006/10/04 16:01:03, 5] rpc_parse/parse_prs.c:prs_uint8s(851) > 0058 confounder: c1 ca dd c4 5d ea 84 dd >[2006/10/04 16:01:03, 3] smbd/pipes.c:reply_pipe_read_and_X(262) > readX-IPC pnum=7372 min=1024 max=1024 nread=96 >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:03, 5] lib/util.c:show_msg(488) > size=155 > smb_com=0x2e > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38658 > smt_wct=12 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_vwv[ 2]= 0 (0x0) > smb_vwv[ 3]= 0 (0x0) > smb_vwv[ 4]= 0 (0x0) > smb_vwv[ 5]= 96 (0x60) > smb_vwv[ 6]= 59 (0x3B) > smb_vwv[ 7]= 0 (0x0) > smb_vwv[ 8]= 0 (0x0) > smb_vwv[ 9]= 0 (0x0) > smb_vwv[10]= 0 (0x0) > smb_vwv[11]= 0 (0x0) > smb_bcc=96 >[2006/10/04 16:01:17, 3] smbd/process.c:process_smb(1110) > Transaction 5322 of length 45 >[2006/10/04 16:01:17, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:17, 5] lib/util.c:show_msg(488) > size=41 > smb_com=0x4 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38722 > smt_wct=3 > smb_vwv[ 0]=29554 (0x7372) > smb_vwv[ 1]=65535 (0xFFFF) > smb_vwv[ 2]=65535 (0xFFFF) > smb_bcc=0 >[2006/10/04 16:01:17, 3] smbd/process.c:switch_message(914) > switch message SMBclose (pid 285) conn 0x840a030 >[2006/10/04 16:01:17, 4] smbd/uid.c:change_to_user(176) > change_to_user: Skipping user change - already user >[2006/10/04 16:01:17, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1264) > search for pipe pnum=7372 >[2006/10/04 16:01:17, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name NETLOGON pnum=7372 (pipes_open=2) >[2006/10/04 16:01:17, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1268) > pipe name spoolss pnum=7325 (pipes_open=2) >[2006/10/04 16:01:17, 5] smbd/pipes.c:reply_pipe_close(282) > reply_pipe_close: pnum:7372 >[2006/10/04 16:01:17, 4] rpc_server/srv_pipe_hnd.c:close_rpc_pipe_hnd(1169) > closed pipe name NETLOGON pnum=7372 (pipes_open=1) >[2006/10/04 16:01:17, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:17, 5] lib/util.c:show_msg(488) > size=35 > smb_com=0x4 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38722 > smt_wct=0 > smb_bcc=0 >[2006/10/04 16:01:28, 3] smbd/process.c:process_smb(1110) > Transaction 5323 of length 43 >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(488) > size=39 > smb_com=0x74 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=0 > smb_pid=65279 > smb_uid=173 > smb_mid=38786 > smt_wct=2 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:01:28, 3] smbd/process.c:switch_message(914) > switch message SMBulogoffX (pid 285) conn 0x0 >[2006/10/04 16:01:28, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:28, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:28, 3] smbd/reply.c:reply_ulogoffX(1618) > ulogoffX vuid=173 >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(488) > size=39 > smb_com=0x74 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=0 > smb_pid=65279 > smb_uid=173 > smb_mid=38786 > smt_wct=2 > smb_vwv[ 0]= 255 (0xFF) > smb_vwv[ 1]= 0 (0x0) > smb_bcc=0 >[2006/10/04 16:01:28, 3] smbd/process.c:process_smb(1110) > Transaction 5324 of length 39 >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(488) > size=35 > smb_com=0x71 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=24 > smb_flg2=51207 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38850 > smt_wct=0 > smb_bcc=0 >[2006/10/04 16:01:28, 3] smbd/process.c:switch_message(914) > switch message SMBtdis (pid 285) conn 0x840a030 >[2006/10/04 16:01:28, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:28, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:28, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:28, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:28, 3] smbd/service.c:close_cnum(1141) > g-marchenko (10.0.0.167) closed connection to service IPC$ >[2006/10/04 16:01:28, 3] smbd/connection.c:yield_connection(69) > Yielding connection to IPC$ >[2006/10/04 16:01:28, 4] smbd/vfs.c:vfs_ChDir(741) > vfs_ChDir to / >[2006/10/04 16:01:28, 3] smbd/sec_ctx.c:set_sec_ctx(241) > setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0 >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_nt_user_token(448) > NT user token: (NULL) >[2006/10/04 16:01:28, 5] auth/auth_util.c:debug_unix_user_token(474) > UNIX token of user 0 > Primary group is 0 and contains 0 supplementary groups >[2006/10/04 16:01:28, 5] smbd/uid.c:change_to_root_user(275) > change_to_root_user: now uid=(0,0) gid=(0,0) >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(478) >[2006/10/04 16:01:28, 5] lib/util.c:show_msg(488) > size=35 > smb_com=0x71 > smb_rcls=0 > smb_reh=0 > smb_err=0 > smb_flg=136 > smb_flg2=51201 > smb_tid=1 > smb_pid=65279 > smb_uid=173 > smb_mid=38850 > smt_wct=0 > smb_bcc=0
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 4150
: 2172 |
2173