First email was rejected due to size so the log files are inline in the msg
now..
I have NEVER had so much trouble with a
samba PDC before. I need to turn in my unix admin license, this is
pathetic...
Anyway, I am here. When trying to join a domain with the administrator
account I get "no mapping between account name and security ID's was
done"
And the joining fails...
All the needed files are attached, from the ldap log. to the samba.conf
to the ldifs of the machine, root and admin account.
Trying with the root account nets me the same error
in smbusers I noticed an entry i never made
root = administrator
software versions:
[root@vnpdc01 openldap-data]# rpm -qa |grep samba
samba-3.0.11-1
samba-swat-3.0.11-1
samba-client-3.0.11-1
samba-common-3.0.11-1
I am assumine the rpm or something else made that mapping. I dunno...
I have really about had it here, it's been well over a week, we are
working on close to two. I need to get this resolved or move on to a
Windows PDC. I have a deadline to meet with a domain controller (that is
no one problem here, i realize this)
If more information is needed please ask. I will be happy to provide
anything but passwords..
If anyone has any insite, advice, or whatever I would very much
appreciate it
net groupmap list
Engineering (S-1-5-21-1391849139-953726148-1374988380-9005) -> Engineering
Staff (S-1-5-21-1391849139-953726148-1374988380-9003) -> Staff
Sales (S-1-5-21-1391849139-953726148-1374988380-9007) -> Sales
Administration (S-1-5-21-1391849139-953726148-1374988380-9009) ->
Administration
Domain Admins (S-1-5-21-3107161993-1039155829-3332455197-512) -> Domain
Admins
Domain Users (S-1-5-21-3107161993-1039155829-3332455197-513) -> Domain Users
Domain Guests (S-1-5-21-3107161993-1039155829-3332455197-514) -> Domain
Guests
Domain Computers (S-1-5-21-3107161993-1039155829-3332455197-515) -> Domain
Computers
Administrators (S-1-5-32-544) -> Administrators
Print Operators (S-1-5-32-550) -> Print Operators
Backup Operators (S-1-5-32-551) -> Backup Operators
Replicators (S-1-5-32-552) -> Replicators
smb.conf
[global]
workgroup = VENTUS_OFFICE
netbios name = vnpdc01
server string = Ventus File Server
hosts allow = 172.28.0. 192.168.1 127.
printcap name = /etc/printcap
load printers = yes
log file = /var/log/samba/%m.log
max log size = 50
ldap passwd sync = Yes
passdb backend = ldapsam:ldap://192.168.1.242/
ldap suffix = o=ventusnetworks.com,dc=na
ldap filter = (&(uid=%u)(objectclass=sambaSamAccount))
ldap machine suffix = ou=Computers
ldap user suffix = ou=Staff
ldap group suffix = ou=Groups
ldap admin dn = "cn=Manager,dc=na"
ldap delete dn = no
#ldap ssl = ssl
security = user
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
log level = 10
local master = yes
os level = 255
domain master = yes
preferred master = yes
domain logons = yes
# logon script = netlogon.bat
logon path = \\%L\Profiles\%U
# logon drive = U:
name resolve order = wins lmhosts bcast
wins support = yes
dns proxy = no
#delete user script = /usr/local/sbin/smbldap-userdel "%u"
add machine script = /opt/IDEALX/sbin/smbldap-useradd -w "%u"
-H W
add group script = /opt/IDEALX/sbin/smbldap-groupadd -p "%g"
#delete group script = /usr/local/sbin/smbldap-groupdel "%g"
add user to group script = /opt/IDEALX/sbin/smbldap-groupmod -m
"%u" "%g"
delete user from group script = /opt/IDEALX/sbin/smbldap-groupmod -x
"%u" "%g"
set primary group script = /opt/IDEALX/sbin/smbldap-usermod -g
"%g" "%u"
admin ldif
dn: uid=administrator, ou=Staff, o=ventusnetworks.com, dc=na
sambaLMPassword:
sambaPrimaryGroupSID: S-1-5-21-3107161993-1039155829-3332455197-512
objectClass: inetOrgPerson
objectClass: sambaSamAccount
objectClass: posixAccount
objectClass: shadowAccount
userPassword::
sambaLogonTime: 0
sambaHomeDrive: H:
uid: administrator
uidNumber: 0
cn: administrator
sambaLogoffTime: 2147483647
sambaPwdLastSet: 1111419696
loginShell: /bin/bash
sambaAcctFlags: [U ]
sambaProfilePath: \\vnpdc01\profiles\administrator\
gidNumber: 512
sambaPwdMustChange: 2147483647
sambaNTPassword:
sambaPwdCanChange: 1111419696
gecos: Netbios Domain Administrator
sambaSID: S-1-5-21-3107161993-1039155829-3332455197-2996
homeDirectory: /home/administrator
sambaKickoffTime: 2147483647
sn: administrator
sambaHomePath: \\vnpdc01\home\administrator
sambaPasswordHistory: 0000000000000000000000000000000000000000000000000000000
000000000
computer ldif
dn: uid=ibm-zus90725eca$, ou=Computers, o=ventusnetworks.com, dc=na
sambaPwdLastSet: 1111418025
sn: ibm-zus90725eca$
sambaAcctFlags: [W ]
userPassword:: e1NNRDV9cHVjZlRnck5MWVFmaENjcjFJQUp6RHdZbHBBPQ=uidNumber: 1023
gidNumber: 515
sambaPwdMustChange: 2147483647
uid: ibm-zus90725eca$
objectClass: inetOrgPerson
objectClass: organizationalPerson
objectClass: posixAccount
objectClass: sambaSamAccount
objectClass: person
objectClass: top
sambaSID: S-1-5-21-3107161993-1036545829-3332455197
cn: ibm-zus90725eca$
homeDirectory: /dev/null
sambaPasswordHistory: 0000000000000000000000000000000000000000000000000000000
000000000
sambaPwdCanChange: 1111418025
sambaNTPassword: 4143428EA74C32CCF1AED23B88F1C64C
sambaLMPassword: 205A06C82DD819D1AAD3B435B51404EE
domain ldif
dn: sambaDomainName=VENTUS_OFFICE, o=ventusnetworks.com, dc=na
sambaNextUserRid: 67109862
sambaSID: S-1-5-21-3107161993-1039155829-3332455197
sambaNextGroupRid: 67109863
objectClass: sambaDomain
sambaAlgorithmicRidBase: 1000
sambaDomainName: VENTUS_OFFICE
log of attempt to join (i am adding the computer accounts before trying)
smb_bcc=61
[2005/03/21 11:41:52, 10] lib/util.c:dump_data(1990)
[000] 00 5C 00 50 00 49 00 50 00 45 00 5C 00 00 00 00 .\.P.I.P .E.\....
[010] 00 05 00 00 03 10 00 00 00 2C 00 00 00 04 00 00 ........ .,......
[020] 00 14 00 00 00 00 00 01 00 00 00 00 00 07 00 00 ........ ........
[030] 00 00 00 00 00 4F F9 3E 42 4C 5A 00 00 .....O.> BLZ..
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBtrans (pid 23116) conn 0x9c99a28
[2005/03/21 11:41:52, 4] smbd/uid.c:change_to_user(194)
change_to_user: Skipping user change - already user
[2005/03/21 11:41:52, 3] smbd/ipc.c:reply_trans(539)
trans <\PIPE\> data=44 params=0 setup=2
[2005/03/21 11:41:52, 5] smbd/ipc.c:reply_trans(560)
calling named_pipe
[2005/03/21 11:41:52, 3] smbd/ipc.c:named_pipe(334)
named pipe command on <> name
[2005/03/21 11:41:52, 5] smbd/ipc.c:api_fd_reply(265)
api_fd_reply
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1168)
search for pipe pnum=7307
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name samr pnum=7307 (pipes_open=2)
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name lsarpc pnum=7302 (pipes_open=2)
[2005/03/21 11:41:52, 3] smbd/ipc.c:api_fd_reply(294)
Got API command 0x26 on pipe "samr" (pnum 7307)
[2005/03/21 11:41:52, 10] smbd/ipc.c:api_fd_reply(299)
api_fd_reply: p:0x9ca1360 max_trans_reply: 1024
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe_hnd.c:write_to_pipe(852)
write_to_pipe: 7307 name: samr open: Yes len: 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 0, pdu_needed_len = 0,
incoming data = 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:fill_rpc_header(399)
fill_rpc_header: data_to_copy = 44, len_needed_to_complete_hdr = 16,
receive_len = 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 16
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 16, pdu_needed_len = 0,
incoming data = 28
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0000 major : 05
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0001 minor : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0002 pkt_type : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0003 flags : 03
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0004 pack_type0: 10
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0005 pack_type1: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0006 pack_type2: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0007 pack_type3: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 frag_len : 002c
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a auth_len : 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
000c call_id : 00000004
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(486)
unmarshall_rpc_header: using little-endian RPC
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(515)
unmarshall_rpc_header: type = 0, flags = 3
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 0, pdu_needed_len = 28,
incoming data = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_complete_pdu(720)
process_complete_pdu: processing packet type 0
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr_req req
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 alloc_hint: 00000014
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0004 context_id: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0006 opnum : 0001
[2005/03/21 11:41:52, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(542)
free_pipe_context: destroying talloc pool of size 0
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe.c:api_pipe_request(1497)
Requested \PIPE\samr
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe.c:api_rpcTNP(1531)
api_rpcTNP: samr op 0x1 - api_rpcTNP: rpc command: SAMR_CLOSE_HND
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe.c:api_rpcTNP(1557)
api_rpc_cmds[0].fn == 0x813d91a
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 samr_io_q_close_hnd
[2005/03/21 11:41:52, 6] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_pol_hnd pol
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 data1: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0004 data2: 00000007
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 data3: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a data4: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8s(729)
000c data5: 4f f9 3e 42 4c 5a 00 00
[2005/03/21 11:41:52, 4]
rpc_server/srv_lsa_hnd.c:find_policy_by_hnd_internal(162)
Found policy hnd[0] [000] 00 00 00 00 07 00 00 00 00 00 00 00 4F F9 3E 42
........ ....O.>B
[010] 4C 5A 00 00 LZ..
[2005/03/21 11:41:52, 3] rpc_server/srv_lsa_hnd.c:close_policy_hnd(200)
Closed policy
[2005/03/21 11:41:52, 5] rpc_server/srv_samr_nt.c:_samr_close_hnd(591)
samr_reply_close_hnd: 591
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 samr_io_r_close_hnd
[2005/03/21 11:41:52, 6] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_pol_hnd pol
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 data1: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0004 data2: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 data3: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a data4: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8s(729)
000c data5: 00 00 00 00 00 00 00 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_ntstatus(672)
0014 status: NT_STATUS_OK
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe.c:api_rpcTNP(1578)
api_rpcTNP: called samr successfully
[2005/03/21 11:41:52, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(542)
free_pipe_context: destroying talloc pool of size 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 28
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe_hnd.c:read_from_pipe(909)
read_from_pipe: 7307 name: samr len: 1024
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:read_from_internal_pipe(982)
read_from_pipe: samr: fault_state = 0 : data_sent_length = 0,
prs_offset(&p->out_data.rdata) = 24.
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr hdr
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0000 major : 05
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0001 minor : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0002 pkt_type : 02
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0003 flags : 03
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0004 pack_type0: 10
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0005 pack_type1: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0006 pack_type2: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0007 pack_type3: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 frag_len : 0030
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a auth_len : 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
000c call_id : 00000004
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000010 smb_io_rpc_hdr_resp resp
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0010 alloc_hint: 00000018
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0014 context_id: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0016 cancel_ct : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0017 reserved : 00
[2005/03/21 11:41:52, 5] smbd/ipc.c:copy_trans_params_and_data(60)
copy_trans_params_and_data: params[0..0] data[0..48]
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=104
smb_com=0x25
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=1
smb_pid=904
smb_uid=100
smb_mid=2944
smt_wct=10
smb_vwv[ 0]= 0 (0x0)
smb_vwv[ 1]= 48 (0x30)
smb_vwv[ 2]= 0 (0x0)
smb_vwv[ 3]= 0 (0x0)
smb_vwv[ 4]= 56 (0x38)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 48 (0x30)
smb_vwv[ 7]= 56 (0x38)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_bcc=49
[2005/03/21 11:41:52, 10] lib/util.c:dump_data(1990)
[000] 00 05 00 02 03 10 00 00 00 30 00 00 00 04 00 00 ........ .0......
[010] 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[020] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[030] 00 .
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,108)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,108) wrote 108
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_smb_length_return_keepalive(505)
got smb length of 128
[2005/03/21 11:41:52, 6] smbd/process.c:process_smb(1090)
got message type 0x0 of len 0x80
[2005/03/21 11:41:52, 3] smbd/process.c:process_smb(1091)
Transaction 48 of length 132
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=128
smb_com=0x25
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=1
smb_pid=904
smb_uid=100
smb_mid=3008
smt_wct=16
smb_vwv[ 0]= 0 (0x0)
smb_vwv[ 1]= 44 (0x2C)
smb_vwv[ 2]= 0 (0x0)
smb_vwv[ 3]= 1024 (0x400)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 0 (0x0)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 84 (0x54)
smb_vwv[11]= 44 (0x2C)
smb_vwv[12]= 84 (0x54)
smb_vwv[13]= 2 (0x2)
smb_vwv[14]= 38 (0x26)
smb_vwv[15]=29447 (0x7307)
smb_bcc=61
[2005/03/21 11:41:52, 10] lib/util.c:dump_data(1990)
[000] 00 5C 00 50 00 49 00 50 00 45 00 5C 00 00 00 00 .\.P.I.P .E.\....
[010] 00 05 00 00 03 10 00 00 00 2C 00 00 00 05 00 00 ........ .,......
[020] 00 14 00 00 00 00 00 01 00 00 00 00 00 06 00 00 ........ ........
[030] 00 00 00 00 00 4F F9 3E 42 4C 5A 00 00 .....O.> BLZ..
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBtrans (pid 23116) conn 0x9c99a28
[2005/03/21 11:41:52, 4] smbd/uid.c:change_to_user(194)
change_to_user: Skipping user change - already user
[2005/03/21 11:41:52, 3] smbd/ipc.c:reply_trans(539)
trans <\PIPE\> data=44 params=0 setup=2
[2005/03/21 11:41:52, 5] smbd/ipc.c:reply_trans(560)
calling named_pipe
[2005/03/21 11:41:52, 3] smbd/ipc.c:named_pipe(334)
named pipe command on <> name
[2005/03/21 11:41:52, 5] smbd/ipc.c:api_fd_reply(265)
api_fd_reply
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1168)
search for pipe pnum=7307
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name samr pnum=7307 (pipes_open=2)
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name lsarpc pnum=7302 (pipes_open=2)
[2005/03/21 11:41:52, 3] smbd/ipc.c:api_fd_reply(294)
Got API command 0x26 on pipe "samr" (pnum 7307)
[2005/03/21 11:41:52, 10] smbd/ipc.c:api_fd_reply(299)
api_fd_reply: p:0x9ca1360 max_trans_reply: 1024
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe_hnd.c:write_to_pipe(852)
write_to_pipe: 7307 name: samr open: Yes len: 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 0, pdu_needed_len = 0,
incoming data = 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:fill_rpc_header(399)
fill_rpc_header: data_to_copy = 44, len_needed_to_complete_hdr = 16,
receive_len = 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 16
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 16, pdu_needed_len = 0,
incoming data = 28
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0000 major : 05
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0001 minor : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0002 pkt_type : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0003 flags : 03
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0004 pack_type0: 10
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0005 pack_type1: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0006 pack_type2: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0007 pack_type3: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 frag_len : 002c
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a auth_len : 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
000c call_id : 00000005
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(486)
unmarshall_rpc_header: using little-endian RPC
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(515)
unmarshall_rpc_header: type = 0, flags = 3
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 0, pdu_needed_len = 28,
incoming data = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_complete_pdu(720)
process_complete_pdu: processing packet type 0
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr_req req
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 alloc_hint: 00000014
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0004 context_id: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0006 opnum : 0001
[2005/03/21 11:41:52, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(542)
free_pipe_context: destroying talloc pool of size 0
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe.c:api_pipe_request(1497)
Requested \PIPE\samr
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe.c:api_rpcTNP(1531)
api_rpcTNP: samr op 0x1 - api_rpcTNP: rpc command: SAMR_CLOSE_HND
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe.c:api_rpcTNP(1557)
api_rpc_cmds[0].fn == 0x813d91a
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 samr_io_q_close_hnd
[2005/03/21 11:41:52, 6] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_pol_hnd pol
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 data1: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0004 data2: 00000006
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 data3: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a data4: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8s(729)
000c data5: 4f f9 3e 42 4c 5a 00 00
[2005/03/21 11:41:52, 4]
rpc_server/srv_lsa_hnd.c:find_policy_by_hnd_internal(162)
Found policy hnd[0] [000] 00 00 00 00 06 00 00 00 00 00 00 00 4F F9 3E 42
........ ....O.>B
[010] 4C 5A 00 00 LZ..
[2005/03/21 11:41:52, 3] rpc_server/srv_lsa_hnd.c:close_policy_hnd(200)
Closed policy
[2005/03/21 11:41:52, 5] rpc_server/srv_samr_nt.c:_samr_close_hnd(591)
samr_reply_close_hnd: 591
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 samr_io_r_close_hnd
[2005/03/21 11:41:52, 6] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_pol_hnd pol
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 data1: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0004 data2: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 data3: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a data4: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8s(729)
000c data5: 00 00 00 00 00 00 00 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_ntstatus(672)
0014 status: NT_STATUS_OK
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe.c:api_rpcTNP(1578)
api_rpcTNP: called samr successfully
[2005/03/21 11:41:52, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(542)
free_pipe_context: destroying talloc pool of size 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 28
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe_hnd.c:read_from_pipe(909)
read_from_pipe: 7307 name: samr len: 1024
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:read_from_internal_pipe(982)
read_from_pipe: samr: fault_state = 0 : data_sent_length = 0,
prs_offset(&p->out_data.rdata) = 24.
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr hdr
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0000 major : 05
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0001 minor : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0002 pkt_type : 02
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0003 flags : 03
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0004 pack_type0: 10
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0005 pack_type1: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0006 pack_type2: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0007 pack_type3: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 frag_len : 0030
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a auth_len : 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
000c call_id : 00000005
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000010 smb_io_rpc_hdr_resp resp
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0010 alloc_hint: 00000018
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0014 context_id: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0016 cancel_ct : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0017 reserved : 00
[2005/03/21 11:41:52, 5] smbd/ipc.c:copy_trans_params_and_data(60)
copy_trans_params_and_data: params[0..0] data[0..48]
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=104
smb_com=0x25
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=1
smb_pid=904
smb_uid=100
smb_mid=3008
smt_wct=10
smb_vwv[ 0]= 0 (0x0)
smb_vwv[ 1]= 48 (0x30)
smb_vwv[ 2]= 0 (0x0)
smb_vwv[ 3]= 0 (0x0)
smb_vwv[ 4]= 56 (0x38)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 48 (0x30)
smb_vwv[ 7]= 56 (0x38)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_bcc=49
[2005/03/21 11:41:52, 10] lib/util.c:dump_data(1990)
[000] 00 05 00 02 03 10 00 00 00 30 00 00 00 05 00 00 ........ .0......
[010] 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[020] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[030] 00 .
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,108)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,108) wrote 108
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_smb_length_return_keepalive(505)
got smb length of 41
[2005/03/21 11:41:52, 6] smbd/process.c:process_smb(1090)
got message type 0x0 of len 0x29
[2005/03/21 11:41:52, 3] smbd/process.c:process_smb(1091)
Transaction 49 of length 45
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=41
smb_com=0x4
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=1
smb_pid=65279
smb_uid=100
smb_mid=3072
smt_wct=3
smb_vwv[ 0]=29447 (0x7307)
smb_vwv[ 1]=65535 (0xFFFF)
smb_vwv[ 2]=65535 (0xFFFF)
smb_bcc=0
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBclose (pid 23116) conn 0x9c99a28
[2005/03/21 11:41:52, 4] smbd/uid.c:change_to_user(194)
change_to_user: Skipping user change - already user
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1168)
search for pipe pnum=7307
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name samr pnum=7307 (pipes_open=2)
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name lsarpc pnum=7302 (pipes_open=2)
[2005/03/21 11:41:52, 5] smbd/pipes.c:reply_pipe_close(260)
reply_pipe_close: pnum:7307
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:close_rpc_pipe_hnd(1081)
closed pipe name samr pnum=7307 (pipes_open=1)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=35
smb_com=0x4
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=1
smb_pid=65279
smb_uid=100
smb_mid=3072
smt_wct=0
smb_bcc=0
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,39)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,39) wrote 39
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_smb_length_return_keepalive(505)
got smb length of 128
[2005/03/21 11:41:52, 6] smbd/process.c:process_smb(1090)
got message type 0x0 of len 0x80
[2005/03/21 11:41:52, 3] smbd/process.c:process_smb(1091)
Transaction 50 of length 132
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=128
smb_com=0x25
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=1
smb_pid=904
smb_uid=100
smb_mid=3136
smt_wct=16
smb_vwv[ 0]= 0 (0x0)
smb_vwv[ 1]= 44 (0x2C)
smb_vwv[ 2]= 0 (0x0)
smb_vwv[ 3]= 1024 (0x400)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 0 (0x0)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 84 (0x54)
smb_vwv[11]= 44 (0x2C)
smb_vwv[12]= 84 (0x54)
smb_vwv[13]= 2 (0x2)
smb_vwv[14]= 38 (0x26)
smb_vwv[15]=29442 (0x7302)
smb_bcc=61
[2005/03/21 11:41:52, 10] lib/util.c:dump_data(1990)
[000] 00 5C 00 50 00 49 00 50 00 45 00 5C 00 00 00 00 .\.P.I.P .E.\....
[010] 00 05 00 00 03 10 00 00 00 2C 00 00 00 04 00 00 ........ .,......
[020] 00 14 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ........ ........
[030] 00 00 00 00 00 4E F9 3E 42 4C 5A 00 00 .....N.> BLZ..
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBtrans (pid 23116) conn 0x9c99a28
[2005/03/21 11:41:52, 4] smbd/uid.c:change_to_user(194)
change_to_user: Skipping user change - already user
[2005/03/21 11:41:52, 3] smbd/ipc.c:reply_trans(539)
trans <\PIPE\> data=44 params=0 setup=2
[2005/03/21 11:41:52, 5] smbd/ipc.c:reply_trans(560)
calling named_pipe
[2005/03/21 11:41:52, 3] smbd/ipc.c:named_pipe(334)
named pipe command on <> name
[2005/03/21 11:41:52, 5] smbd/ipc.c:api_fd_reply(265)
api_fd_reply
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1168)
search for pipe pnum=7302
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name lsarpc pnum=7302 (pipes_open=1)
[2005/03/21 11:41:52, 3] smbd/ipc.c:api_fd_reply(294)
Got API command 0x26 on pipe "lsarpc" (pnum 7302)
[2005/03/21 11:41:52, 10] smbd/ipc.c:api_fd_reply(299)
api_fd_reply: p:0x9c966c8 max_trans_reply: 1024
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe_hnd.c:write_to_pipe(852)
write_to_pipe: 7302 name: lsarpc open: Yes len: 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 0, pdu_needed_len = 0,
incoming data = 44
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:fill_rpc_header(399)
fill_rpc_header: data_to_copy = 44, len_needed_to_complete_hdr = 16,
receive_len = 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 16
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 16, pdu_needed_len = 0,
incoming data = 28
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0000 major : 05
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0001 minor : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0002 pkt_type : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0003 flags : 03
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0004 pack_type0: 10
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0005 pack_type1: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0006 pack_type2: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0007 pack_type3: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 frag_len : 002c
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a auth_len : 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
000c call_id : 00000004
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(486)
unmarshall_rpc_header: using little-endian RPC
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:unmarshall_rpc_header(515)
unmarshall_rpc_header: type = 0, flags = 3
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(874)
write_to_pipe: data_left = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_incoming_data(777)
process_incoming_data: Start: pdu_received_len = 0, pdu_needed_len = 28,
incoming data = 28
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:process_complete_pdu(720)
process_complete_pdu: processing packet type 0
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr_req req
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 alloc_hint: 00000014
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0004 context_id: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0006 opnum : 0000
[2005/03/21 11:41:52, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(542)
free_pipe_context: destroying talloc pool of size 0
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe.c:api_pipe_request(1497)
Requested \PIPE\lsarpc
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe.c:api_rpcTNP(1531)
api_rpcTNP: lsarpc op 0x0 - api_rpcTNP: rpc command: LSA_CLOSE
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe.c:api_rpcTNP(1557)
api_rpc_cmds[4].fn == 0x8111a60
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 lsa_io_q_close
[2005/03/21 11:41:52, 6] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_pol_hnd
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 data1: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0004 data2: 00000001
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 data3: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a data4: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8s(729)
000c data5: 4e f9 3e 42 4c 5a 00 00
[2005/03/21 11:41:52, 4]
rpc_server/srv_lsa_hnd.c:find_policy_by_hnd_internal(162)
Found policy hnd[0] [000] 00 00 00 00 01 00 00 00 00 00 00 00 4E F9 3E 42
........ ....N.>B
[010] 4C 5A 00 00 LZ..
[2005/03/21 11:41:52, 4]
rpc_server/srv_lsa_hnd.c:find_policy_by_hnd_internal(162)
Found policy hnd[0] [000] 00 00 00 00 01 00 00 00 00 00 00 00 4E F9 3E 42
........ ....N.>B
[010] 4C 5A 00 00 LZ..
[2005/03/21 11:41:52, 3] rpc_server/srv_lsa_hnd.c:close_policy_hnd(200)
Closed policy
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 lsa_io_r_close
[2005/03/21 11:41:52, 6] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_pol_hnd
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0000 data1: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0004 data2: 00000000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 data3: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a data4: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8s(729)
000c data5: 00 00 00 00 00 00 00 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_ntstatus(672)
0014 status: NT_STATUS_OK
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe.c:api_rpcTNP(1578)
api_rpcTNP: called lsarpc successfully
[2005/03/21 11:41:52, 3] rpc_server/srv_pipe_hnd.c:free_pipe_context(542)
free_pipe_context: destroying talloc pool of size 0
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:write_to_internal_pipe(878)
write_to_pipe: data_used = 28
[2005/03/21 11:41:52, 6] rpc_server/srv_pipe_hnd.c:read_from_pipe(909)
read_from_pipe: 7302 name: lsarpc len: 1024
[2005/03/21 11:41:52, 10] rpc_server/srv_pipe_hnd.c:read_from_internal_pipe(982)
read_from_pipe: lsarpc: fault_state = 0 : data_sent_length = 0,
prs_offset(&p->out_data.rdata) = 24.
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000000 smb_io_rpc_hdr hdr
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0000 major : 05
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0001 minor : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0002 pkt_type : 02
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0003 flags : 03
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0004 pack_type0: 10
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0005 pack_type1: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0006 pack_type2: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0007 pack_type3: 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0008 frag_len : 0030
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
000a auth_len : 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
000c call_id : 00000004
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_debug(82)
000010 smb_io_rpc_hdr_resp resp
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint32(642)
0010 alloc_hint: 00000018
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint16(613)
0014 context_id: 0000
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0016 cancel_ct : 00
[2005/03/21 11:41:52, 5] rpc_parse/parse_prs.c:prs_uint8(584)
0017 reserved : 00
[2005/03/21 11:41:52, 5] smbd/ipc.c:copy_trans_params_and_data(60)
copy_trans_params_and_data: params[0..0] data[0..48]
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=104
smb_com=0x25
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=1
smb_pid=904
smb_uid=100
smb_mid=3136
smt_wct=10
smb_vwv[ 0]= 0 (0x0)
smb_vwv[ 1]= 48 (0x30)
smb_vwv[ 2]= 0 (0x0)
smb_vwv[ 3]= 0 (0x0)
smb_vwv[ 4]= 56 (0x38)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 48 (0x30)
smb_vwv[ 7]= 56 (0x38)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_bcc=49
[2005/03/21 11:41:52, 10] lib/util.c:dump_data(1990)
[000] 00 05 00 02 03 10 00 00 00 30 00 00 00 04 00 00 ........ .0......
[010] 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[020] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[030] 00 .
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,108)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,108) wrote 108
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_smb_length_return_keepalive(505)
got smb length of 41
[2005/03/21 11:41:52, 6] smbd/process.c:process_smb(1090)
got message type 0x0 of len 0x29
[2005/03/21 11:41:52, 3] smbd/process.c:process_smb(1091)
Transaction 51 of length 45
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=41
smb_com=0x4
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=1
smb_pid=65279
smb_uid=100
smb_mid=3200
smt_wct=3
smb_vwv[ 0]=29442 (0x7302)
smb_vwv[ 1]=65535 (0xFFFF)
smb_vwv[ 2]=65535 (0xFFFF)
smb_bcc=0
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBclose (pid 23116) conn 0x9c99a28
[2005/03/21 11:41:52, 4] smbd/uid.c:change_to_user(194)
change_to_user: Skipping user change - already user
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1168)
search for pipe pnum=7302
[2005/03/21 11:41:52, 5] rpc_server/srv_pipe_hnd.c:get_rpc_pipe(1172)
pipe name lsarpc pnum=7302 (pipes_open=1)
[2005/03/21 11:41:52, 5] smbd/pipes.c:reply_pipe_close(260)
reply_pipe_close: pnum:7302
[2005/03/21 11:41:52, 10] rpc_server/srv_lsa_hnd.c:close_policy_by_pipe(235)
close_policy_by_pipe: deleted handle list for pipe lsarpc
[2005/03/21 11:41:52, 4] rpc_server/srv_pipe_hnd.c:close_rpc_pipe_hnd(1081)
closed pipe name lsarpc pnum=7302 (pipes_open=0)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=35
smb_com=0x4
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=1
smb_pid=65279
smb_uid=100
smb_mid=3200
smt_wct=0
smb_bcc=0
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,39)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,39) wrote 39
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_smb_length_return_keepalive(505)
got smb length of 39
[2005/03/21 11:41:52, 6] smbd/process.c:process_smb(1090)
got message type 0x0 of len 0x27
[2005/03/21 11:41:52, 3] smbd/process.c:process_smb(1091)
Transaction 52 of length 43
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=39
smb_com=0x74
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=100
smb_mid=3264
smt_wct=2
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 0 (0x0)
smb_bcc=0
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBulogoffX (pid 23116) conn 0x0
[2005/03/21 11:41:52, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_nt_user_token(486)
NT user token: (NULL)
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_unix_user_token(507)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2005/03/21 11:41:52, 5] smbd/uid.c:change_to_root_user(296)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2005/03/21 11:41:52, 5] auth/auth_util.c:free_server_info(1374)
attempting to free (and zero) a server_info structure
[2005/03/21 11:41:52, 3] smbd/reply.c:reply_ulogoffX(1248)
ulogoffX vuid=100
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=39
smb_com=0x74
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=0
smb_pid=65279
smb_uid=100
smb_mid=3264
smt_wct=2
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 0 (0x0)
smb_bcc=0
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,43)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,43) wrote 43
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_smb_length_return_keepalive(505)
got smb length of 35
[2005/03/21 11:41:52, 6] smbd/process.c:process_smb(1090)
got message type 0x0 of len 0x23
[2005/03/21 11:41:52, 3] smbd/process.c:process_smb(1091)
Transaction 53 of length 39
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=35
smb_com=0x71
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=1
smb_pid=65279
smb_uid=100
smb_mid=3328
smt_wct=0
smb_bcc=0
[2005/03/21 11:41:52, 3] smbd/process.c:switch_message(886)
switch message SMBtdis (pid 23116) conn 0x9c99a28
[2005/03/21 11:41:52, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_nt_user_token(486)
NT user token: (NULL)
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_unix_user_token(507)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2005/03/21 11:41:52, 5] smbd/uid.c:change_to_root_user(296)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2005/03/21 11:41:52, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_nt_user_token(486)
NT user token: (NULL)
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_unix_user_token(507)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2005/03/21 11:41:52, 5] smbd/uid.c:change_to_root_user(296)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2005/03/21 11:41:52, 3] smbd/service.c:close_cnum(833)
ibm-zus90725eca (172.28.0.64) closed connection to service IPC$
[2005/03/21 11:41:52, 3] smbd/connection.c:yield_connection(69)
Yielding connection to IPC$
[2005/03/21 11:41:52, 4] smbd/vfs.c:vfs_ChDir(657)
vfs_ChDir to /
[2005/03/21 11:41:52, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_nt_user_token(486)
NT user token: (NULL)
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_unix_user_token(507)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2005/03/21 11:41:52, 5] smbd/uid.c:change_to_root_user(296)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(464)
[2005/03/21 11:41:52, 5] lib/util.c:show_msg(474)
size=35
smb_com=0x71
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51201
smb_tid=1
smb_pid=65279
smb_uid=100
smb_mid=3328
smt_wct=0
smb_bcc=0
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(449)
write_socket(25,39)
[2005/03/21 11:41:52, 6] lib/util_sock.c:write_socket(452)
write_socket(25,39) wrote 39
[2005/03/21 11:41:52, 10] lib/util_sock.c:read_socket_data(378)
read_socket_data: recv of 4 returned 0. Error = Success
[2005/03/21 11:41:52, 10] lib/util_sock.c:receive_smb_raw(556)
receive_smb_raw: length < 0!
[2005/03/21 11:41:52, 3] smbd/process.c:timeout_processing(1334)
timeout_processing: End of file from client (client has disconnected).
[2005/03/21 11:41:52, 5] lib/gencache.c:gencache_shutdown(88)
Closing cache file
[2005/03/21 11:41:52, 5] libsmb/namecache.c:namecache_shutdown(79)
namecache_shutdown: netbios namecache closed successfully.
[2005/03/21 11:41:52, 3] smbd/sec_ctx.c:set_sec_ctx(288)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_nt_user_token(486)
NT user token: (NULL)
[2005/03/21 11:41:52, 5] auth/auth_util.c:debug_unix_user_token(507)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2005/03/21 11:41:52, 5] smbd/uid.c:change_to_root_user(296)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2005/03/21 11:41:52, 2] smbd/server.c:exit_server(609)
Closing connections
[2005/03/21 11:41:52, 3] smbd/connection.c:yield_connection(69)
Yielding connection to
[2005/03/21 11:41:52, 5] smbd/oplock.c:receive_local_message(107)
receive_local_message: doing select with timeout of 1 ms
[2005/03/21 11:41:52, 3] smbd/server.c:exit_server(652)
Server exit (normal exit)
--
John Zakhar <jzakhar@ventusnetworks.com>
Systems Administrator.
Ventus Networks
800 Connecticut Ave
Norwalk, CT. 06854
Work 1-(203)-642-2800
Home 1-(860)-318-0276
Cell 1-(203)-257-4165