[2013/08/15 09:33:15.749173, 3] auth/auth.c:219(check_ntlm_password)
check_ntlm_password: Checking password for unmapped user [IAF-GROUP]\[flesch]@[TEST] with the new password interface
[2013/08/15 09:33:15.749206, 3] auth/auth.c:222(check_ntlm_password)
check_ntlm_password: mapped user is: [IAF-GROUP]\[flesch]@[TEST]
[2013/08/15 09:33:15.751315, 3] passdb/lookup_sid.c:1754(get_primary_group_sid)
Forcing Primary Group to 'Domain Users' for flesch
[2013/08/15 09:33:15.752108, 3] auth/auth.c:268(check_ntlm_password)
check_ntlm_password: sam authentication for user [flesch] succeeded
[2013/08/15 09:33:15.753653, 2] auth/auth.c:309(check_ntlm_password)
check_ntlm_password: authentication for user [flesch] -> [flesch] -> [flesch] succeeded
[2013/08/15 09:33:15.756355, 3] groupdb/mapping.c:772(pdb_create_builtin_alias)
pdb_create_builtin_alias: Could not get a gid out of winbind
[2013/08/15 09:33:15.756442, 2] auth/token_util.c:455(finalize_local_nt_token)
WARNING: Failed to create BUILTIN\Administrators group! Can Winbind allocate gids?
[2013/08/15 09:33:15.757954, 3] groupdb/mapping.c:772(pdb_create_builtin_alias)
pdb_create_builtin_alias: Could not get a gid out of winbind
[2013/08/15 09:33:15.758038, 2] auth/token_util.c:479(finalize_local_nt_token)
WARNING: Failed to create BUILTIN\Users group! Can Winbind allocate gids?
[2013/08/15 09:33:15.759968, 3] ../libcli/auth/ntlmssp_sign.c:535(ntlmssp_sign_init)
NTLMSSP Sign/Seal - Initialising with flags:
[2013/08/15 09:33:15.760005, 3] ../libcli/auth/ntlmssp.c:34(debug_ntlmssp_flags)
Got NTLMSSP neg_flags=0xe2088215
[2013/08/15 09:33:15.760038, 3] smbd/password.c:298(register_existing_vuid)
register_existing_vuid: User name: flesch Real name:
[2013/08/15 09:33:15.760060, 3] smbd/password.c:308(register_existing_vuid)
register_existing_vuid: UNIX uid 1019 is UNIX user flesch, and will be vuid 100
[2013/08/15 09:33:15.761496, 3] smbd/password.c:238(register_homes_share)
Adding homes service for user 'flesch' using home directory: '/home/flesch'
[2013/08/15 09:33:15.761576, 3] param/loadparm.c:6582(lp_add_home)
adding home's share [flesch] for user 'flesch' at '/home/flesch'
[2013/08/15 09:33:15.762362, 3] smbd/process.c:1609(process_smb)
Transaction 3 of length 76 (0 toread)
[2013/08/15 09:33:15.762472, 3] smbd/process.c:1414(switch_message)
switch message SMBtconX (pid 1871) conn 0x0
[2013/08/15 09:33:15.762526, 3] lib/access.c:338(allow_access)
Allowed connection from 192.168.30.21 (192.168.30.21)
[2013/08/15 09:33:15.762568, 3] smbd/service.c:872(make_connection_snum)
Connect path is '/tmp' for service [IPC$]
[2013/08/15 09:33:15.762611, 3] smbd/vfs.c:102(vfs_init_default)
Initialising default vfs hooks
[2013/08/15 09:33:15.762637, 3] smbd/vfs.c:128(vfs_init_custom)
Initialising custom vfs hooks from [/[Default VFS]/]
[2013/08/15 09:33:15.762708, 3] ../libcli/security/dom_sid.c:208(dom_sid_parse_endp)
string_to_sid: SID root is not in a valid format
[2013/08/15 09:33:15.762837, 3] passdb/lookup_sid.c:1754(get_primary_group_sid)
Forcing Primary Group to 'Domain Users' for root
[2013/08/15 09:33:15.762894, 3] ../libcli/security/dom_sid.c:208(dom_sid_parse_endp)
string_to_sid: SID miko is not in a valid format
[2013/08/15 09:33:15.763009, 3] passdb/lookup_sid.c:1754(get_primary_group_sid)
Forcing Primary Group to 'Domain Users' for miko
[2013/08/15 09:33:15.763055, 3] ../libcli/security/dom_sid.c:208(dom_sid_parse_endp)
string_to_sid: SID franke is not in a valid format
[2013/08/15 09:33:15.763721, 3] passdb/lookup_sid.c:1754(get_primary_group_sid)
Forcing Primary Group to 'Domain Users' for franke
[2013/08/15 09:33:15.763869, 3] smbd/service.c:1114(make_connection_snum)
test (192.168.30.21) connect to service IPC$ initially as user flesch (uid=1019, gid=1019) (pid 1871)
[2013/08/15 09:33:15.763898, 3] smbd/reply.c:871(reply_tcon_and_X)
tconX service=IPC$
[2013/08/15 09:33:17.067510, 3] smbd/process.c:1609(process_smb)
Transaction 4 of length 104 (0 toread)
[2013/08/15 09:33:17.067588, 3] smbd/process.c:1414(switch_message)
switch message SMBntcreateX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.068262, 3] smbd/process.c:1609(process_smb)
Transaction 5 of length 76 (0 toread)
[2013/08/15 09:33:17.068339, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans2 (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.068980, 3] smbd/process.c:1609(process_smb)
Transaction 6 of length 184 (0 toread)
[2013/08/15 09:33:17.069057, 3] smbd/process.c:1414(switch_message)
switch message SMBwriteX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.069105, 3] rpc_server/srv_pipe.c:889(api_pipe_bind_req)
api_pipe_bind_req: \PIPE\lsarpc -> \PIPE\lsarpc
[2013/08/15 09:33:17.069129, 3] rpc_server/srv_pipe.c:339(check_bind_req)
check_bind_req for \lsarpc
[2013/08/15 09:33:17.069152, 3] rpc_server/srv_pipe.c:346(check_bind_req)
check_bind_req: \PIPE\lsarpc -> \PIPE\lsarpc
[2013/08/15 09:33:17.069192, 3] smbd/pipes.c:361(pipe_write_andx_done)
writeX-IPC nwritten=116
[2013/08/15 09:33:17.069627, 3] smbd/process.c:1609(process_smb)
Transaction 7 of length 63 (0 toread)
[2013/08/15 09:33:17.069703, 3] smbd/process.c:1414(switch_message)
switch message SMBreadX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.069733, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 28
[2013/08/15 09:33:17.069763, 3] smbd/pipes.c:485(pipe_read_andx_done)
readX-IPC min=1024 max=1024 nread=68
[2013/08/15 09:33:17.070330, 3] smbd/process.c:1609(process_smb)
Transaction 8 of length 164 (0 toread)
[2013/08/15 09:33:17.070408, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.070438, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=76 params=0 setup=2
[2013/08/15 09:33:17.070486, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:17.070506, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1372)
[2013/08/15 09:33:17.070538, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_OPENPOLICY2
[2013/08/15 09:33:17.070593, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 1112
[2013/08/15 09:33:17.071173, 3] smbd/process.c:1609(process_smb)
Transaction 9 of length 134 (0 toread)
[2013/08/15 09:33:17.071250, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.071278, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=46 params=0 setup=2
[2013/08/15 09:33:17.071299, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:17.071319, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1372)
[2013/08/15 09:33:17.071351, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY2
[2013/08/15 09:33:17.071392, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 32
[2013/08/15 09:33:17.072141, 3] smbd/process.c:1609(process_smb)
Transaction 10 of length 134 (0 toread)
[2013/08/15 09:33:17.072218, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.072246, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=46 params=0 setup=2
[2013/08/15 09:33:17.072267, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:17.072287, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1372)
[2013/08/15 09:33:17.072318, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY
[2013/08/15 09:33:17.072366, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 168
[2013/08/15 09:33:17.072942, 3] smbd/process.c:1609(process_smb)
Transaction 11 of length 132 (0 toread)
[2013/08/15 09:33:17.073019, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.073055, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=44 params=0 setup=2
[2013/08/15 09:33:17.073078, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:17.073098, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1372)
[2013/08/15 09:33:17.073130, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_CLOSE
[2013/08/15 09:33:17.073156, 3] rpc_server/rpc_handles.c:281(close_policy_hnd)
Closed policy
[2013/08/15 09:33:17.073194, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 28
[2013/08/15 09:33:17.073508, 3] smbd/process.c:1609(process_smb)
Transaction 12 of length 45 (0 toread)
[2013/08/15 09:33:17.073584, 3] smbd/process.c:1414(switch_message)
switch message SMBclose (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:17.073608, 3] smbd/reply.c:4858(reply_close)
close fd=-1 fnum=4978 (numopen=1)
[2013/08/15 09:33:18.697448, 3] smbd/process.c:1609(process_smb)
Transaction 13 of length 104 (0 toread)
[2013/08/15 09:33:18.697543, 3] smbd/process.c:1414(switch_message)
switch message SMBntcreateX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.698163, 3] smbd/process.c:1609(process_smb)
Transaction 14 of length 76 (0 toread)
[2013/08/15 09:33:18.698261, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans2 (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.698926, 3] smbd/process.c:1609(process_smb)
Transaction 15 of length 184 (0 toread)
[2013/08/15 09:33:18.699012, 3] smbd/process.c:1414(switch_message)
switch message SMBwriteX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.699048, 3] rpc_server/srv_pipe.c:889(api_pipe_bind_req)
api_pipe_bind_req: \PIPE\lsarpc -> \PIPE\lsarpc
[2013/08/15 09:33:18.699069, 3] rpc_server/srv_pipe.c:339(check_bind_req)
check_bind_req for \lsarpc
[2013/08/15 09:33:18.699091, 3] rpc_server/srv_pipe.c:346(check_bind_req)
check_bind_req: \PIPE\lsarpc -> \PIPE\lsarpc
[2013/08/15 09:33:18.699126, 3] smbd/pipes.c:361(pipe_write_andx_done)
writeX-IPC nwritten=116
[2013/08/15 09:33:18.699433, 3] smbd/process.c:1609(process_smb)
Transaction 16 of length 63 (0 toread)
[2013/08/15 09:33:18.699510, 3] smbd/process.c:1414(switch_message)
switch message SMBreadX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.699538, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 28
[2013/08/15 09:33:18.699568, 3] smbd/pipes.c:485(pipe_read_andx_done)
readX-IPC min=1024 max=1024 nread=68
[2013/08/15 09:33:18.700141, 3] smbd/process.c:1609(process_smb)
Transaction 17 of length 164 (0 toread)
[2013/08/15 09:33:18.700219, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.700246, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=76 params=0 setup=2
[2013/08/15 09:33:18.700268, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.700288, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1373)
[2013/08/15 09:33:18.700320, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_OPENPOLICY2
[2013/08/15 09:33:18.700364, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 1112
[2013/08/15 09:33:18.700942, 3] smbd/process.c:1609(process_smb)
Transaction 18 of length 134 (0 toread)
[2013/08/15 09:33:18.701020, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.701047, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=46 params=0 setup=2
[2013/08/15 09:33:18.701069, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.701089, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1373)
[2013/08/15 09:33:18.701121, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY2
[2013/08/15 09:33:18.701164, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 32
[2013/08/15 09:33:18.701868, 3] smbd/process.c:1609(process_smb)
Transaction 19 of length 134 (0 toread)
[2013/08/15 09:33:18.701945, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.701973, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=46 params=0 setup=2
[2013/08/15 09:33:18.701994, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.702014, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1373)
[2013/08/15 09:33:18.702046, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_QUERYINFOPOLICY
[2013/08/15 09:33:18.702086, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 168
[2013/08/15 09:33:18.702667, 3] smbd/process.c:1609(process_smb)
Transaction 20 of length 132 (0 toread)
[2013/08/15 09:33:18.702745, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.702773, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=44 params=0 setup=2
[2013/08/15 09:33:18.702795, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.702815, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "lsarpc" (pnum 1373)
[2013/08/15 09:33:18.702846, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: LSA_CLOSE
[2013/08/15 09:33:18.702869, 3] rpc_server/rpc_handles.c:281(close_policy_hnd)
Closed policy
[2013/08/15 09:33:18.702903, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 28
[2013/08/15 09:33:18.703244, 3] smbd/process.c:1609(process_smb)
Transaction 21 of length 45 (0 toread)
[2013/08/15 09:33:18.703321, 3] smbd/process.c:1414(switch_message)
switch message SMBclose (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.703344, 3] smbd/reply.c:4858(reply_close)
close fd=-1 fnum=4979 (numopen=1)
[2013/08/15 09:33:18.706967, 3] smbd/process.c:1609(process_smb)
Transaction 22 of length 100 (0 toread)
[2013/08/15 09:33:18.707045, 3] smbd/process.c:1414(switch_message)
switch message SMBntcreateX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.707683, 3] smbd/process.c:1609(process_smb)
Transaction 23 of length 76 (0 toread)
[2013/08/15 09:33:18.707761, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans2 (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.708398, 3] smbd/process.c:1609(process_smb)
Transaction 24 of length 184 (0 toread)
[2013/08/15 09:33:18.708476, 3] smbd/process.c:1414(switch_message)
switch message SMBwriteX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.708512, 3] rpc_server/srv_pipe.c:889(api_pipe_bind_req)
api_pipe_bind_req: \PIPE\samr -> \PIPE\samr
[2013/08/15 09:33:18.708532, 3] rpc_server/srv_pipe.c:339(check_bind_req)
check_bind_req for \samr
[2013/08/15 09:33:18.708554, 3] rpc_server/srv_pipe.c:346(check_bind_req)
check_bind_req: \PIPE\samr -> \PIPE\samr
[2013/08/15 09:33:18.708589, 3] smbd/pipes.c:361(pipe_write_andx_done)
writeX-IPC nwritten=116
[2013/08/15 09:33:18.708905, 3] smbd/process.c:1609(process_smb)
Transaction 25 of length 63 (0 toread)
[2013/08/15 09:33:18.708983, 3] smbd/process.c:1414(switch_message)
switch message SMBreadX (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.709011, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 26
[2013/08/15 09:33:18.709041, 3] smbd/pipes.c:485(pipe_read_andx_done)
readX-IPC min=1024 max=1024 nread=68
[2013/08/15 09:33:18.709578, 3] smbd/process.c:1609(process_smb)
Transaction 26 of length 156 (0 toread)
[2013/08/15 09:33:18.709656, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.709683, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=68 params=0 setup=2
[2013/08/15 09:33:18.709712, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.709732, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.709764, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_CONNECT5
[2013/08/15 09:33:18.709818, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 1042
[2013/08/15 09:33:18.710380, 3] smbd/process.c:1609(process_smb)
Transaction 27 of length 140 (0 toread)
[2013/08/15 09:33:18.710479, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.710507, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=52 params=0 setup=2
[2013/08/15 09:33:18.710528, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.710548, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.710580, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_ENUMDOMAINS
[2013/08/15 09:33:18.710633, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 90
[2013/08/15 09:33:18.711223, 3] smbd/process.c:1609(process_smb)
Transaction 28 of length 170 (0 toread)
[2013/08/15 09:33:18.711301, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.711328, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=82 params=0 setup=2
[2013/08/15 09:33:18.711350, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.711370, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.711401, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_LOOKUPDOMAIN
[2013/08/15 09:33:18.711442, 2] rpc_server/samr/srv_samr_nt.c:4071(_samr_LookupDomain)
Returning domain sid for domain IAF-GROUP -> S-1-5-21-1051412616-1339249864-1463584228
[2013/08/15 09:33:18.711481, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 94
[2013/08/15 09:33:18.712022, 3] smbd/process.c:1609(process_smb)
Transaction 29 of length 164 (0 toread)
[2013/08/15 09:33:18.712099, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.712126, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=76 params=0 setup=2
[2013/08/15 09:33:18.712148, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.712167, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.712199, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_OPENDOMAIN
[2013/08/15 09:33:18.712248, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 1042
[2013/08/15 09:33:18.712823, 3] smbd/process.c:1609(process_smb)
Transaction 30 of length 172 (0 toread)
[2013/08/15 09:33:18.712901, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.712928, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=84 params=0 setup=2
[2013/08/15 09:33:18.712950, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.712970, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.713002, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_CREATEUSER2
[2013/08/15 09:33:18.713173, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 26
[2013/08/15 09:33:18.713499, 3] smbd/process.c:1609(process_smb)
Transaction 31 of length 132 (0 toread)
[2013/08/15 09:33:18.713577, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.713611, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=44 params=0 setup=2
[2013/08/15 09:33:18.713637, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.713657, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.713689, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_CLOSE
[2013/08/15 09:33:18.713714, 3] rpc_server/rpc_handles.c:281(close_policy_hnd)
Closed policy
[2013/08/15 09:33:18.713749, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 26
[2013/08/15 09:33:18.714298, 3] smbd/process.c:1609(process_smb)
Transaction 32 of length 132 (0 toread)
[2013/08/15 09:33:18.714377, 3] smbd/process.c:1414(switch_message)
switch message SMBtrans (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.714404, 3] smbd/ipc.c:560(handle_trans)
trans <\PIPE\> data=44 params=0 setup=2
[2013/08/15 09:33:18.714426, 3] smbd/ipc.c:511(named_pipe)
named pipe command on <> name
[2013/08/15 09:33:18.714480, 3] smbd/ipc.c:475(api_fd_reply)
Got API command 0x26 on pipe "samr" (pnum 1374)
[2013/08/15 09:33:18.714512, 3] rpc_server/srv_pipe.c:1626(api_rpcTNP)
api_rpcTNP: rpc command: SAMR_CLOSE
[2013/08/15 09:33:18.714535, 3] rpc_server/rpc_handles.c:281(close_policy_hnd)
Closed policy
[2013/08/15 09:33:18.714569, 3] rpc_server/srv_pipe_hnd.c:121(free_pipe_context)
free_pipe_context: destroying talloc pool of size 26
[2013/08/15 09:33:18.714893, 3] smbd/process.c:1609(process_smb)
Transaction 33 of length 45 (0 toread)
[2013/08/15 09:33:18.714969, 3] smbd/process.c:1414(switch_message)
switch message SMBclose (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:18.714993, 3] smbd/reply.c:4858(reply_close)
close fd=-1 fnum=4980 (numopen=1)
[2013/08/15 09:33:32.676816, 3] smbd/process.c:1609(process_smb)
Transaction 34 of length 39 (0 toread)
[2013/08/15 09:33:32.676898, 3] smbd/process.c:1414(switch_message)
switch message SMBtdis (pid 1871) conn 0x7f418adb4730
[2013/08/15 09:33:32.676938, 3] smbd/service.c:1378(close_cnum)
test (192.168.30.21) closed connection to service IPC$
[2013/08/15 09:33:32.676965, 3] smbd/connection.c:35(yield_connection)
Yielding connection to IPC$
[2013/08/15 09:33:32.677314, 3] smbd/process.c:1609(process_smb)
Transaction 35 of length 43 (0 toread)
[2013/08/15 09:33:32.677391, 3] smbd/process.c:1414(switch_message)
switch message SMBulogoffX (pid 1871) conn 0x0
[2013/08/15 09:33:32.678817, 3] smbd/reply.c:2096(reply_ulogoffX)
ulogoffX vuid=100
[2013/08/15 09:33:32.679489, 1] smbd/process.c:457(receive_smb_talloc)
receive_smb_raw_talloc failed for client 192.168.30.21 read error = NT_STATUS_CONNECTION_RESET.
[2013/08/15 09:33:32.679637, 3] smbd/server_exit.c:181(exit_server_common)
Server exit (failed to receive smb request)