Displaying 3 results from an estimated 3 matches for "gggfdwsscvo".
2016 Jun 26
2
Need IP on failed logins in logfile
I used to also get related log messages of the form:
auth_check_password_send: Checking password for unmapped user [HPRS]\[mark]@[ROVER]
auth_check_password_send: mapped user is: [HPRS]\[mark]@[ROVER]
but now all I get is the auth_check_password_recv in the log. Perhaps the change is due to an
upgrade to Samba, or perhaps a change I made to my smb.conf log options? (see log config in
my
2016 Jun 26
0
Need IP on failed logins in logfile
...t, I remembered that you can set up logging for
each machine, so I added 'log file = /usr/local/samba/var/log.%m' to my
DCs smb.conf and restarted samba.
I then tried to connect to the share with smbclient as a none existing user:
rowland at devstation:~$ smbclient \\\\dc1\\data -U derf%gggfdwsscvo
When I examined the resulting logfile on the DC:
root at dc1:~# nano /usr/local/samba/var/log.192.168.0.180
I found this:
[2016/06/26 09:11:28.226254, 2]
../source4/auth/ntlm/auth.c:430(auth_check_password_recv)
auth_check_password_recv: sam_ignoredomain authentication for user
[SAMDOM\de...
2016 Jun 26
1
Need IP on failed logins in logfile
...set up logging for
> each machine, so I added 'log file = /usr/local/samba/var/log.%m' to my
> DCs smb.conf and restarted samba.
>
> I then tried to connect to the share with smbclient as a none existing user:
>
> rowland at devstation:~$ smbclient \\\\dc1\\data -U derf%gggfdwsscvo
>
> When I examined the resulting logfile on the DC:
>
> root at dc1:~# nano /usr/local/samba/var/log.192.168.0.180
>
> I found this:
>
> [2016/06/26 09:11:28.226254, 2]
> ../source4/auth/ntlm/auth.c:430(auth_check_password_recv)
> auth_check_password_recv: sam_ig...