1. root@zalupa:~# /usr/sbin/smbd -F -S --no-process-group -d 10 | ts '[%Y-%m-%d %H:%M:%.S]'
  2. [2022-06-17 08:44:51.146317] INFO: Current debug levels:
  3. [2022-06-17 08:44:51.147949] all: 10
  4. [2022-06-17 08:44:51.153016] tdb: 10
  5. [2022-06-17 08:44:51.154825] printdrivers: 10
  6. [2022-06-17 08:44:51.156518] lanman: 10
  7. [2022-06-17 08:44:51.158171] smb: 10
  8. [2022-06-17 08:44:51.159792] rpc_parse: 10
  9. [2022-06-17 08:44:51.173388] rpc_srv: 10
  10. [2022-06-17 08:44:51.175088] rpc_cli: 10
  11. [2022-06-17 08:44:51.176737] passdb: 10
  12. [2022-06-17 08:44:51.178366] sam: 10
  13. [2022-06-17 08:44:51.179971] auth: 10
  14. [2022-06-17 08:44:51.181596] winbind: 10
  15. [2022-06-17 08:44:51.183280] vfs: 10
  16. [2022-06-17 08:44:51.184931] idmap: 10
  17. [2022-06-17 08:44:51.186552] quota: 10
  18. [2022-06-17 08:44:51.188168] acls: 10
  19. [2022-06-17 08:44:51.189778] locking: 10
  20. [2022-06-17 08:44:51.191400] msdfs: 10
  21. [2022-06-17 08:44:51.193068] dmapi: 10
  22. [2022-06-17 08:44:51.203499] registry: 10
  23. [2022-06-17 08:44:51.205277] scavenger: 10
  24. [2022-06-17 08:44:51.206944] dns: 10
  25. [2022-06-17 08:44:51.208577] ldb: 10
  26. [2022-06-17 08:44:51.210264] tevent: 10
  27. [2022-06-17 08:44:51.211900] auth_audit: 10
  28. [2022-06-17 08:44:51.213584] auth_json_audit: 10
  29. [2022-06-17 08:44:51.215224] kerberos: 10
  30. [2022-06-17 08:44:51.216841] drs_repl: 10
  31. [2022-06-17 08:44:51.218454] smb2: 10
  32. [2022-06-17 08:44:51.223532] smb2_credits: 10
  33. [2022-06-17 08:44:51.225315] dsdb_audit: 10
  34. [2022-06-17 08:44:51.226982] dsdb_json_audit: 10
  35. [2022-06-17 08:44:51.228622] dsdb_password_audit: 10
  36. [2022-06-17 08:44:51.233554] dsdb_password_json_audit: 10
  37. [2022-06-17 08:44:51.235381] dsdb_transaction_audit: 10
  38. [2022-06-17 08:44:51.237071] dsdb_transaction_json_audit: 10
  39. [2022-06-17 08:44:51.243494] dsdb_group_audit: 10
  40. [2022-06-17 08:44:51.245252] dsdb_group_json_audit: 10
  41. [2022-06-17 08:44:51.246933] smbd version 4.14.12 started.
  42. [2022-06-17 08:44:51.248595] Copyright Andrew Tridgell and the Samba Team 1992-2021
  43. [2022-06-17 08:44:51.250256] uid=0 gid=0 euid=0 egid=0
  44. [2022-06-17 08:44:51.263729]
  45. [2022-06-17 08:44:51.265621] Paths:
  46. [2022-06-17 08:44:51.267307] SBINDIR: /usr/sbin
  47. [2022-06-17 08:44:51.268959] BINDIR: /usr/bin
  48. [2022-06-17 08:44:51.270599] CONFIGFILE: /etc/samba/smb.conf
  49. [2022-06-17 08:44:51.272264] LOGFILEBASE: /var/log
  50. [2022-06-17 08:44:51.273974] LMHOSTSFILE: /etc/samba/lmhosts
  51. [2022-06-17 08:44:51.275622] LIBDIR: /usr/lib
  52. [2022-06-17 08:44:51.277239] DATADIR: /usr/share
  53. [2022-06-17 08:44:51.278879] SAMBA_DATADIR: /usr/share/samba
  54. [2022-06-17 08:44:51.280516] MODULESDIR: /usr/lib/samba
  55. [2022-06-17 08:44:51.282151] SHLIBEXT: so
  56. [2022-06-17 08:44:51.284492] LOCKDIR: /var/lock
  57. [2022-06-17 08:44:51.288498] STATEDIR: /var/lib/samba
  58. [2022-06-17 08:44:51.295200] CACHEDIR: /var/cache/samba
  59. [2022-06-17 08:44:51.303622] PIDDIR: /var/run
  60. [2022-06-17 08:44:51.305444] SMB_PASSWD_FILE: /etc/samba/smbpasswd
  61. [2022-06-17 08:44:51.307140] PRIVATE_DIR: /etc/samba
  62. [2022-06-17 08:44:51.308777] BINDDNS_DIR: /var/lib/samba/bind-dns
  63. [2022-06-17 08:44:51.310424]
  64. [2022-06-17 08:44:51.323617] System Headers:
  65. [2022-06-17 08:44:51.325488] HAVE_SYS_ACL_H
  66. [2022-06-17 08:44:51.327177] HAVE_SYS_AUXV_H
  67. [2022-06-17 08:44:51.328803] HAVE_SYS_CAPABILITY_H
  68. [2022-06-17 08:44:51.330431] HAVE_SYS_CDEFS_H
  69. [2022-06-17 08:44:51.332069] HAVE_SYS_DIR_H
  70. [2022-06-17 08:44:51.333756] HAVE_SYS_EPOLL_H
  71. [2022-06-17 08:44:51.335408] HAVE_SYS_EVENTFD_H
  72. [2022-06-17 08:44:51.337039] HAVE_SYS_FCNTL_H
  73. [2022-06-17 08:44:51.338661] HAVE_SYS_FILE_H
  74. [2022-06-17 08:44:51.340270] HAVE_SYS_INOTIFY_H
  75. [2022-06-17 08:44:51.341881] HAVE_SYS_IOCTL_H
  76. [2022-06-17 08:44:51.343540] HAVE_SYS_IPC_H
  77. [2022-06-17 08:44:51.349519] HAVE_SYS_KERNEL_PROC_CORE_PATTERN
  78. [2022-06-17 08:44:51.351435] HAVE_SYS_MMAN_H
  79. [2022-06-17 08:44:51.360891] HAVE_SYS_MOUNT_H
  80. [2022-06-17 08:44:51.373016] HAVE_SYS_PARAM_H
  81. [2022-06-17 08:44:51.375021] HAVE_SYS_PRCTL_H
  82. [2022-06-17 08:44:51.376745] HAVE_SYS_QUOTAS
  83. [2022-06-17 08:44:51.378391] HAVE_SYS_QUOTA_H
  84. [2022-06-17 08:44:51.380021] HAVE_SYS_RESOURCE_H
  85. [2022-06-17 08:44:51.381646] HAVE_SYS_SELECT_H
  86. [2022-06-17 08:44:51.392839] HAVE_SYS_SENDFILE_H
  87. [2022-06-17 08:44:51.394899] HAVE_SYS_SHM_H
  88. [2022-06-17 08:44:51.396610] HAVE_SYS_SOCKET_H
  89. [2022-06-17 08:44:51.398276] HAVE_SYS_STATFS_H
  90. [2022-06-17 08:44:51.399920] HAVE_SYS_STATVFS_H
  91. [2022-06-17 08:44:51.401547] HAVE_SYS_STAT_H
  92. [2022-06-17 08:44:51.403218] HAVE_SYS_STROPTS_H
  93. [2022-06-17 08:44:51.404868] HAVE_SYS_SYSCALL_H
  94. [2022-06-17 08:44:51.406489] HAVE_SYS_SYSLOG_H
  95. [2022-06-17 08:44:51.413020] HAVE_SYS_SYSMACROS_H
  96. [2022-06-17 08:44:51.414924] HAVE_SYS_TERMIOS_H
  97. [2022-06-17 08:44:51.416625] HAVE_SYS_TIMEB_H
  98. [2022-06-17 08:44:51.418436] HAVE_SYS_TIMES_H
  99. [2022-06-17 08:44:51.423502] HAVE_SYS_TIME_H
  100. [2022-06-17 08:44:51.426398] HAVE_SYS_TYPES_H
  101. [2022-06-17 08:44:51.428167] HAVE_SYS_UCONTEXT_H
  102. [2022-06-17 08:44:51.429845] HAVE_SYS_UIO_H
  103. [2022-06-17 08:44:51.443695] HAVE_SYS_UN_H
  104. [2022-06-17 08:44:51.445513] HAVE_SYS_UTSNAME_H
  105. [2022-06-17 08:44:51.447198] HAVE_SYS_VFS_H
  106. [2022-06-17 08:44:51.448830] HAVE_SYS_WAIT_H
  107. [2022-06-17 08:44:51.450470] HAVE_SYS_XATTR_H
  108. [2022-06-17 08:44:51.452108]
  109. [2022-06-17 08:44:51.453778] Headers:
  110. [2022-06-17 08:44:51.455404] HAVE_ACL_LIBACL_H
  111. [2022-06-17 08:44:51.457037] HAVE_ALLOCA_H
  112. [2022-06-17 08:44:51.458661] HAVE_ARPA_INET_H
  113. [2022-06-17 08:44:51.460281] HAVE_ARPA_NAMESER_H
  114. [2022-06-17 08:44:51.461775] HAVE_ASM_TYPES_H
  115. [2022-06-17 08:44:51.463581] HAVE_ASM_UNISTD_H
  116. [2022-06-17 08:44:51.473578] HAVE_ASSERT_H
  117. [2022-06-17 08:44:51.475266] HAVE_ATTR_ATTRIBUTES_H
  118. [2022-06-17 08:44:51.476787] HAVE_AVAHI_CLIENT_CLIENT_H
  119. [2022-06-17 08:44:51.478599] HAVE_AVAHI_COMMON_WATCH_H
  120. [2022-06-17 08:44:51.480251] HAVE_BSD_LIBUTIL_H
  121. [2022-06-17 08:44:51.481876] HAVE_COM_ERR_H
  122. [2022-06-17 08:44:51.483560] HAVE_CONFIG_H
  123. [2022-06-17 08:44:51.485212] HAVE_CRYPT_H
  124. [2022-06-17 08:44:51.486836] HAVE_CTYPE_H
  125. [2022-06-17 08:44:51.493519] HAVE_CURSES_H
  126. [2022-06-17 08:44:51.495165] HAVE_DIRENT_H
  127. [2022-06-17 08:44:51.496679] HAVE_DLFCN_H
  128. [2022-06-17 08:44:51.498161] HAVE_ENDIAN_H
  129. [2022-06-17 08:44:51.499656] HAVE_ERRNO_H
  130. [2022-06-17 08:44:51.501052] HAVE_ERR_H
  131. [2022-06-17 08:44:51.513527] HAVE_FCNTL_H
  132. [2022-06-17 08:44:51.515171] HAVE_FLOAT_H
  133. [2022-06-17 08:44:51.516693] HAVE_FNMATCH_H
  134. [2022-06-17 08:44:51.518363] HAVE_FTW_H
  135. [2022-06-17 08:44:51.520098] HAVE_FUSE_FUSE_LOWLEVEL_H
  136. [2022-06-17 08:44:51.521734] HAVE_GETOPT_H
  137. [2022-06-17 08:44:51.523433] HAVE_GLIB_H
  138. [2022-06-17 08:44:51.525069] HAVE_GLOB_H
  139. [2022-06-17 08:44:51.526695] HAVE_GNUTLS_GNUTLS_H
  140. [2022-06-17 08:44:51.528311] HAVE_GPFS_H
  141. [2022-06-17 08:44:51.529917] HAVE_GRP_H
  142. [2022-06-17 08:44:51.543534] HAVE_GSSAPI_GSSAPI_H
  143. [2022-06-17 08:44:51.546367] HAVE_GSSAPI_GSSAPI_KRB5_H
  144. [2022-06-17 08:44:51.548214] HAVE_GSSAPI_GSSAPI_SPNEGO_H
  145. [2022-06-17 08:44:51.549770] HAVE_ICONV_H
  146. [2022-06-17 08:44:51.551261] HAVE_IFADDRS_H
  147. [2022-06-17 08:44:51.552738] HAVE_INTTYPES_H
  148. [2022-06-17 08:44:51.554292] HAVE_KRB5_H
  149. [2022-06-17 08:44:51.555771] HAVE_KRB5_LOCATE_PLUGIN_H
  150. [2022-06-17 08:44:51.557266] HAVE_LANGINFO_H
  151. [2022-06-17 08:44:51.564176] HAVE_LASTLOG_H
  152. [2022-06-17 08:44:51.565878] HAVE_LIBGEN_H
  153. [2022-06-17 08:44:51.567414] HAVE_LIBURING_H
  154. [2022-06-17 08:44:51.568902] HAVE_LIMITS_H
  155. [2022-06-17 08:44:51.571391] HAVE_LINUX_ETHTOOL_H
  156. [2022-06-17 08:44:51.580261] HAVE_LINUX_FALLOC_H
  157. [2022-06-17 08:44:51.581948] HAVE_LINUX_FCNTL_H
  158. [2022-06-17 08:44:51.583559] HAVE_LINUX_FS_H
  159. [2022-06-17 08:44:51.585072] HAVE_LINUX_IOCTL_H
  160. [2022-06-17 08:44:51.586558] HAVE_LINUX_SOCKIOS_H
  161. [2022-06-17 08:44:51.588043] HAVE_LINUX_TYPES_H
  162. [2022-06-17 08:44:51.589515] HAVE_LOCALE_H
  163. [2022-06-17 08:44:51.594142] HAVE_MALLOC_H
  164. [2022-06-17 08:44:51.595770] HAVE_MEMORY_H
  165. [2022-06-17 08:44:51.597287] HAVE_MNTENT_H
  166. [2022-06-17 08:44:51.598775] HAVE_NETDB_H
  167. [2022-06-17 08:44:51.600250] HAVE_NETINET_IN_H
  168. [2022-06-17 08:44:51.601730] HAVE_NETINET_IN_SYSTM_H
  169. [2022-06-17 08:44:51.603247] HAVE_NETINET_IP_H
  170. [2022-06-17 08:44:51.604736] HAVE_NETINET_TCP_H
  171. [2022-06-17 08:44:51.606217] HAVE_NET_IF_H
  172. [2022-06-17 08:44:51.607904] HAVE_POLL_H
  173. [2022-06-17 08:44:51.609406] HAVE_POPT_H
  174. [2022-06-17 08:44:51.610890] HAVE_PTHREAD_H
  175. [2022-06-17 08:44:51.612367] HAVE_PTY_H
  176. [2022-06-17 08:44:51.613921] HAVE_PWD_H
  177. [2022-06-17 08:44:51.615404] HAVE_READLINE_HISTORY_H
  178. [2022-06-17 08:44:51.616871] HAVE_READLINE_READLINE_H
  179. [2022-06-17 08:44:51.618346] HAVE_RESOLV_H
  180. [2022-06-17 08:44:51.619815] HAVE_RPC_NETTYPE_H
  181. [2022-06-17 08:44:51.621287] HAVE_RPC_RPC_H
  182. [2022-06-17 08:44:51.623001] HAVE_RPC_XDR_H
  183. [2022-06-17 08:44:51.624513] HAVE_SASL_SASL_H
  184. [2022-06-17 08:44:51.626480] HAVE_SCHED_H
  185. [2022-06-17 08:44:51.628058] HAVE_SECURITY_PAM_MODULES_H
  186. [2022-06-17 08:44:51.629583] HAVE_SETJMP_H
  187. [2022-06-17 08:44:51.631078] HAVE_SHADOW_H
  188. [2022-06-17 08:44:51.632559] HAVE_SIGNAL_H
  189. [2022-06-17 08:44:51.634124] HAVE_STDARG_H
  190. [2022-06-17 08:44:51.635621] HAVE_STDATOMIC_H
  191. [2022-06-17 08:44:51.637281] HAVE_STDBOOL_H
  192. [2022-06-17 08:44:51.638783] HAVE_STDDEF_H
  193. [2022-06-17 08:44:51.640262] HAVE_STDINT_H
  194. [2022-06-17 08:44:51.641891] HAVE_STDIO_H
  195. [2022-06-17 08:44:51.643466] HAVE_STDLIB_H
  196. [2022-06-17 08:44:51.644980] HAVE_STRINGS_H
  197. [2022-06-17 08:44:51.646634] HAVE_STRING_H
  198. [2022-06-17 08:44:51.648138] HAVE_STROPTS_H
  199. [2022-06-17 08:44:51.649630] HAVE_SYSCALL_H
  200. [2022-06-17 08:44:51.651108] HAVE_SYSLOG_H
  201. [2022-06-17 08:44:51.652767] HAVE_TERMCAP_H
  202. [2022-06-17 08:44:51.654323] HAVE_TERMIOS_H
  203. [2022-06-17 08:44:51.655823] HAVE_TERM_H
  204. [2022-06-17 08:44:51.657311] HAVE_TIME_H
  205. [2022-06-17 08:44:51.658782] HAVE_UNISTD_H
  206. [2022-06-17 08:44:51.660256] HAVE_UTIME_H
  207. [2022-06-17 08:44:51.661888] HAVE_ZLIB_H
  208. [2022-06-17 08:44:51.663658]
  209. [2022-06-17 08:44:51.665311] UTMP Options:
  210. [2022-06-17 08:44:51.667340] HAVE_UTMPX_H
  211. [2022-06-17 08:44:51.669083] HAVE_UTMP_H
  212. [2022-06-17 08:44:51.670699]
  213. [2022-06-17 08:44:51.672195] HAVE_* Defines:
  214. [2022-06-17 08:44:51.673986] HAVE_ADDR_TYPE_IN_KRB5_ADDRESS
  215. [2022-06-17 08:44:51.675647] HAVE_AP_OPTS_USE_SUBKEY
  216. [2022-06-17 08:44:51.677129] HAVE_ASPRINTF
  217. [2022-06-17 08:44:51.678877] HAVE_ATEXIT
  218. [2022-06-17 08:44:51.680397] HAVE_ATOMIC_THREAD_FENCE
  219. [2022-06-17 08:44:51.682023] HAVE_ATOMIC_THREAD_FENCE_SUPPORT
  220. [2022-06-17 08:44:51.683708] HAVE_AVAHI_CLIENT_NEW
  221. [2022-06-17 08:44:51.685343] HAVE_AVAHI_STRERROR
  222. [2022-06-17 08:44:51.686952] HAVE_BASENAME
  223. [2022-06-17 08:44:51.688644] HAVE_BLKCNT_T
  224. [2022-06-17 08:44:51.690155] HAVE_BLKSIZE_T
  225. [2022-06-17 08:44:51.691798] HAVE_BOOL
  226. [2022-06-17 08:44:51.693460] HAVE_BSD_STRTOLL
  227. [2022-06-17 08:44:51.695088] HAVE_BZERO
  228. [2022-06-17 08:44:51.696686] HAVE_C99_VSNPRINTF
  229. [2022-06-17 08:44:51.698309] HAVE_CAP_GET_PROC
  230. [2022-06-17 08:44:51.699952] HAVE_CHARSET_CP850
  231. [2022-06-17 08:44:51.701561] HAVE_CHARSET_UTF_8
  232. [2022-06-17 08:44:51.703317] HAVE_CHECKSUM_IN_KRB5_CHECKSUM
  233. [2022-06-17 08:44:51.704959] HAVE_CHMOD
  234. [2022-06-17 08:44:51.706573] HAVE_CHOWN
  235. [2022-06-17 08:44:51.708073] HAVE_CHROOT
  236. [2022-06-17 08:44:51.709776] HAVE_CLEARENV
  237. [2022-06-17 08:44:51.711375] HAVE_CLOCK_GETTIME
  238. [2022-06-17 08:44:51.712910] HAVE_CLOCK_MONOTONIC
  239. [2022-06-17 08:44:51.714556] HAVE_CLOCK_PROCESS_CPUTIME_ID
  240. [2022-06-17 08:44:51.716199] HAVE_CLOCK_REALTIME
  241. [2022-06-17 08:44:51.717808] HAVE_COMPILER_WILL_OPTIMIZE_OUT_FNS
  242. [2022-06-17 08:44:51.719435] HAVE_CONNECT
  243. [2022-06-17 08:44:51.721042] HAVE_CONSTRUCTOR_ATTRIBUTE
  244. [2022-06-17 08:44:51.722657] HAVE_COPY_FILE_RANGE
  245. [2022-06-17 08:44:51.724451] HAVE_CPPFUNCTION
  246. [2022-06-17 08:44:51.725965] HAVE_CRYPT
  247. [2022-06-17 08:44:51.727922] HAVE_CRYPT_R
  248. [2022-06-17 08:44:51.729563] HAVE_DECL_ASPRINTF
  249. [2022-06-17 08:44:51.731072] HAVE_DECL_DLOPEN
  250. [2022-06-17 08:44:51.732683] HAVE_DECL_EWOULDBLOCK
  251. [2022-06-17 08:44:51.734453] HAVE_DECL_FDATASYNC
  252. [2022-06-17 08:44:51.736071] HAVE_DECL_FS_COMPR_FL
  253. [2022-06-17 08:44:51.737573] HAVE_DECL_FS_IOC_GETFLAGS
  254. [2022-06-17 08:44:51.739313] HAVE_DECL_GETTIMEOFDAY
  255. [2022-06-17 08:44:51.740817] HAVE_DECL_H_ERRNO
  256. [2022-06-17 08:44:51.742429] HAVE_DECL_KRB5_AUTH_CON_SET_REQ_CKSUMTYPE
  257. [2022-06-17 08:44:51.744368] HAVE_DECL_KRB5_GET_CREDENTIALS_FOR_USER
  258. [2022-06-17 08:44:51.745895] HAVE_DECL_MALLOC
  259. [2022-06-17 08:44:51.747510] HAVE_DECL_MEMALIGN
  260. [2022-06-17 08:44:51.749116] HAVE_DECL_PTHREAD_MUTEX_ROBUST
  261. [2022-06-17 08:44:51.750858] HAVE_DECL_READAHEAD
  262. [2022-06-17 08:44:51.752486] HAVE_DECL_RL_EVENT_HOOK
  263. [2022-06-17 08:44:51.754055] HAVE_DECL_SNPRINTF
  264. [2022-06-17 08:44:51.755791] HAVE_DECL_STRPTIME
  265. [2022-06-17 08:44:51.757294] HAVE_DECL_VASPRINTF
  266. [2022-06-17 08:44:51.759010] HAVE_DECL_VSNPRINTF
  267. [2022-06-17 08:44:51.760616] HAVE_DECL__RES
  268. [2022-06-17 08:44:51.762105] HAVE_DESTRUCTOR_ATTRIBUTE
  269. [2022-06-17 08:44:51.763781] HAVE_DES_PCBC_ENCRYPT
  270. [2022-06-17 08:44:51.765402] HAVE_DIRENT_D_OFF
  271. [2022-06-17 08:44:51.767026] HAVE_DIRFD
  272. [2022-06-17 08:44:51.768642] HAVE_DIRFD_DECL
  273. [2022-06-17 08:44:51.770354] HAVE_DIRNAME
  274. [2022-06-17 08:44:51.771853] HAVE_DISABLE_FAULT_HANDLING
  275. [2022-06-17 08:44:51.773526] HAVE_DLCLOSE
  276. [2022-06-17 08:44:51.775019] HAVE_DLERROR
  277. [2022-06-17 08:44:51.776656] HAVE_DLOPEN
  278. [2022-06-17 08:44:51.778398] HAVE_DLSYM
  279. [2022-06-17 08:44:51.779893] HAVE_DN_EXPAND
  280. [2022-06-17 08:44:51.781498] HAVE_DPRINTF
  281. [2022-06-17 08:44:51.783156] HAVE_DUP2
  282. [2022-06-17 08:44:51.784896] HAVE_ENCTYPE_AES128_CTS_HMAC_SHA1_96
  283. [2022-06-17 08:44:51.786541] HAVE_ENCTYPE_AES256_CTS_HMAC_SHA1_96
  284. [2022-06-17 08:44:51.788070] HAVE_ENCTYPE_ARCFOUR_HMAC
  285. [2022-06-17 08:44:51.793602] HAVE_ENCTYPE_ARCFOUR_HMAC_MD5
  286. [2022-06-17 08:44:51.796283] HAVE_ENCTYPE_ARCFOUR_HMAC_MD5_56
  287. [2022-06-17 08:44:51.798000] HAVE_ENDHOSTENT
  288. [2022-06-17 08:44:51.799649] HAVE_ENDMNTENT
  289. [2022-06-17 08:44:51.801283] HAVE_ENVIRON_DECL
  290. [2022-06-17 08:44:51.802945] HAVE_EPOLL
  291. [2022-06-17 08:44:51.804577] HAVE_EPOLL_CREATE
  292. [2022-06-17 08:44:51.806196] HAVE_ERR
  293. [2022-06-17 08:44:51.807801] HAVE_ERRNO_DECL
  294. [2022-06-17 08:44:51.809391] HAVE_ERRX
  295. [2022-06-17 08:44:51.810993] HAVE_ETHTOOL
  296. [2022-06-17 08:44:51.812595] HAVE_ETYPE_IN_ENCRYPTEDDATA
  297. [2022-06-17 08:44:51.814392] HAVE_EVENTFD
  298. [2022-06-17 08:44:51.815906] HAVE_EXECL
  299. [2022-06-17 08:44:51.817525] HAVE_E_DATA_POINTER_IN_KRB5_ERROR
  300. [2022-06-17 08:44:51.819158] HAVE_FALLOCATE
  301. [2022-06-17 08:44:51.820758] HAVE_FALLOC_FL_PUNCH_HOLE
  302. [2022-06-17 08:44:51.822480] HAVE_FALLTHROUGH_ATTRIBUTE
  303. [2022-06-17 08:44:51.824062] HAVE_FCHMOD
  304. [2022-06-17 08:44:51.825789] HAVE_FCHOWN
  305. [2022-06-17 08:44:51.827304] HAVE_FCNTL_LOCK
  306. [2022-06-17 08:44:51.829026] HAVE_FDATASYNC
  307. [2022-06-17 08:44:51.830526] HAVE_FDOPENDIR
  308. [2022-06-17 08:44:51.832141] HAVE_FLAGS_IN_KRB5_CREDS
  309. [2022-06-17 08:44:51.833796] HAVE_FLOCK
  310. [2022-06-17 08:44:51.835414] HAVE_FMEMOPEN
  311. [2022-06-17 08:44:51.837128] HAVE_FREEADDRINFO
  312. [2022-06-17 08:44:51.838730] HAVE_FREEIFADDRS
  313. [2022-06-17 08:44:51.840240] HAVE_FREE_CHECKSUM
  314. [2022-06-17 08:44:51.841868] HAVE_FRSIZE
  315. [2022-06-17 08:44:51.843638] HAVE_FSEEKO
  316. [2022-06-17 08:44:51.845250] HAVE_FSID_INT
  317. [2022-06-17 08:44:51.846751] HAVE_FSTATAT
  318. [2022-06-17 08:44:51.848457] HAVE_FSYNC
  319. [2022-06-17 08:44:51.849951] HAVE_FTRUNCATE
  320. [2022-06-17 08:44:51.851666] HAVE_FTRUNCATE_EXTEND
  321. [2022-06-17 08:44:51.853225] HAVE_FUNCTION_MACRO
  322. [2022-06-17 08:44:51.854982] HAVE_FUSE
  323. [2022-06-17 08:44:51.856481] HAVE_FUSE_MOUNT
  324. [2022-06-17 08:44:51.858089] HAVE_FUTIMENS
  325. [2022-06-17 08:44:51.859694] HAVE_FUTIMES
  326. [2022-06-17 08:44:51.861293] HAVE_F_OWNER_EX
  327. [2022-06-17 08:44:51.862941] HAVE_F_SETLEASE_DECL
  328. [2022-06-17 08:44:51.864680] HAVE_GAI_STRERROR
  329. [2022-06-17 08:44:51.866281] HAVE_GCC_VOLATILE_MEMORY_PROTECTION
  330. [2022-06-17 08:44:51.867907] HAVE_GETADDRINFO
  331. [2022-06-17 08:44:51.869523] HAVE_GETAUXVAL
  332. [2022-06-17 08:44:51.871011] HAVE_GETCWD
  333. [2022-06-17 08:44:51.872716] HAVE_GETGRENT
  334. [2022-06-17 08:44:51.874270] HAVE_GETGRGID_R
  335. [2022-06-17 08:44:51.875896] HAVE_GETGRNAM
  336. [2022-06-17 08:44:51.877510] HAVE_GETGRNAM_R
  337. [2022-06-17 08:44:51.878993] HAVE_GETGROUPLIST
  338. [2022-06-17 08:44:51.880448] HAVE_GETHOSTBYADDR
  339. [2022-06-17 08:44:51.882036] HAVE_GETHOSTBYNAME
  340. [2022-06-17 08:44:51.883701] HAVE_GETHOSTBYNAME_R
  341. [2022-06-17 08:44:51.885346] HAVE_GETHOSTENT
  342. [2022-06-17 08:44:51.886971] HAVE_GETHOSTNAME
  343. [2022-06-17 08:44:51.888590] HAVE_GETIFADDRS
  344. [2022-06-17 08:44:51.890206] HAVE_GETMNTENT
  345. [2022-06-17 08:44:51.892087] HAVE_GETNAMEINFO
  346. [2022-06-17 08:44:51.893799] HAVE_GETPAGESIZE
  347. [2022-06-17 08:44:51.895327] HAVE_GETPGRP
  348. [2022-06-17 08:44:51.897242] HAVE_GETPWNAM
  349. [2022-06-17 08:44:51.898766] HAVE_GETPWNAM_R
  350. [2022-06-17 08:44:51.900518] HAVE_GETPWUID_R
  351. [2022-06-17 08:44:51.902035] HAVE_GETRLIMIT
  352. [2022-06-17 08:44:51.903702] HAVE_GETSPNAM
  353. [2022-06-17 08:44:51.905321] HAVE_GETTIMEOFDAY_TZ_VOID
  354. [2022-06-17 08:44:51.907058] HAVE_GETXATTR
  355. [2022-06-17 08:44:51.908555] HAVE_GET_CURRENT_DIR_NAME
  356. [2022-06-17 08:44:51.910177] HAVE_GLIB
  357. [2022-06-17 08:44:51.911857] HAVE_GLIB_2_0
  358. [2022-06-17 08:44:51.913422] HAVE_GLOB
  359. [2022-06-17 08:44:51.915050] HAVE_GNUTLS
  360. [2022-06-17 08:44:51.916661] HAVE_GNUTLS_AEAD_CIPHER_ENCRYPTV2
  361. [2022-06-17 08:44:51.918391] HAVE_GNUTLS_AES_CFB8
  362. [2022-06-17 08:44:51.919886] HAVE_GNUTLS_AES_CMAC
  363. [2022-06-17 08:44:51.921505] HAVE_GNUTLS_CRYPTO_POLICIES
  364. [2022-06-17 08:44:51.923189] HAVE_GNUTLS_GET_SYSTEM_CONFIG_FILE
  365. [2022-06-17 08:44:51.924942] HAVE_GNUTLS_PKCS7_GET_EMBEDDED_DATA_OID
  366. [2022-06-17 08:44:51.926466] HAVE_GNUTLS_SET_DEFAULT_PRIORITY_APPEND
  367. [2022-06-17 08:44:51.928102] HAVE_GPFS
  368. [2022-06-17 08:44:51.929813] HAVE_GRANTPT
  369. [2022-06-17 08:44:51.931411] HAVE_GSSAPI
  370. [2022-06-17 08:44:51.932937] HAVE_GSSKRB5_EXTRACT_AUTHZ_DATA_FROM_SEC_CONTEXT
  371. [2022-06-17 08:44:51.934593] HAVE_GSSKRB5_GET_SUBKEY
  372. [2022-06-17 08:44:51.936217] HAVE_GSS_DISPLAY_STATUS
  373. [2022-06-17 08:44:51.937841] HAVE_GSS_EXPORT_CRED
  374. [2022-06-17 08:44:51.939453] HAVE_GSS_IMPORT_CRED
  375. [2022-06-17 08:44:51.941062] HAVE_GSS_INQUIRE_SEC_CONTEXT_BY_OID
  376. [2022-06-17 08:44:51.942787] HAVE_GSS_KRB5_CRED_NO_CI_FLAGS_X
  377. [2022-06-17 08:44:51.944455] HAVE_GSS_KRB5_EXPORT_LUCID_SEC_CONTEXT
  378. [2022-06-17 08:44:51.946087] HAVE_GSS_KRB5_IMPORT_CRED
  379. [2022-06-17 08:44:51.947610] HAVE_GSS_OID_EQUAL
  380. [2022-06-17 08:44:51.950481] HAVE_GSS_WRAP_IOV
  381. [2022-06-17 08:44:51.952106] HAVE_HISTORY_LIST
  382. [2022-06-17 08:44:51.953813] HAVE_HSTRERROR
  383. [2022-06-17 08:44:51.955453] HAVE_H_ERRNO
  384. [2022-06-17 08:44:51.957083] HAVE_ICONV_ERRNO_ILLEGAL_MULTIBYTE
  385. [2022-06-17 08:44:51.958714] HAVE_ICONV_OPEN
  386. [2022-06-17 08:44:51.960339] HAVE_IF_NAMETOINDEX
  387. [2022-06-17 08:44:51.961959] HAVE_IMMEDIATE_STRUCTURES
  388. [2022-06-17 08:44:51.964366] HAVE_INET_ATON
  389. [2022-06-17 08:44:51.966776] HAVE_INET_NTOA
  390. [2022-06-17 08:44:51.968439] HAVE_INET_NTOP
  391. [2022-06-17 08:44:51.970062] HAVE_INET_PTON
  392. [2022-06-17 08:44:51.971678] HAVE_INITGROUPS
  393. [2022-06-17 08:44:51.973374] HAVE_INITIALIZE_KRB5_ERROR_TABLE
  394. [2022-06-17 08:44:51.975033] HAVE_INOTIFY
  395. [2022-06-17 08:44:51.976842] HAVE_INOTIFY_INIT
  396. [2022-06-17 08:44:51.978508] HAVE_INO_T
  397. [2022-06-17 08:44:51.980140] HAVE_INT16_T
  398. [2022-06-17 08:44:51.981836] HAVE_INT32_T
  399. [2022-06-17 08:44:51.983385] HAVE_INT64_T
  400. [2022-06-17 08:44:51.985021] HAVE_INT8_T
  401. [2022-06-17 08:44:51.986647] HAVE_INTPTR_T
  402. [2022-06-17 08:44:51.988262] HAVE_IO_URING_RING_DONTFORK
  403. [2022-06-17 08:44:51.991063] HAVE_IPV6
  404. [2022-06-17 08:44:51.992781] HAVE_IPV6_V6ONLY
  405. [2022-06-17 08:44:51.994389] HAVE_ISATTY
  406. [2022-06-17 08:44:51.996123] HAVE_KERNEL_OPLOCKS_LINUX
  407. [2022-06-17 08:44:51.997760] HAVE_KERNEL_SHARE_MODES
  408. [2022-06-17 08:44:51.999375] HAVE_KRB5
  409. [2022-06-17 08:44:52.000977] HAVE_KRB5_ADDRESSES
  410. [2022-06-17 08:44:52.002482] HAVE_KRB5_AUTH_CON_SETKEY
  411. [2022-06-17 08:44:52.005549] HAVE_KRB5_CC_COPY_CACHE
  412. [2022-06-17 08:44:52.007422] HAVE_KRB5_CC_GET_LIFETIME
  413. [2022-06-17 08:44:52.008972] HAVE_KRB5_CONFIG_GET_BOOL_DEFAULT
  414. [2022-06-17 08:44:52.010721] HAVE_KRB5_CREATE_CHECKSUM
  415. [2022-06-17 08:44:52.012361] HAVE_KRB5_CRYPTO
  416. [2022-06-17 08:44:52.013955] HAVE_KRB5_CRYPTO_DESTROY
  417. [2022-06-17 08:44:52.015608] HAVE_KRB5_CRYPTO_INIT
  418. [2022-06-17 08:44:52.017233] HAVE_KRB5_C_VERIFY_CHECKSUM
  419. [2022-06-17 08:44:52.018864] HAVE_KRB5_DATA_COPY
  420. [2022-06-17 08:44:52.020467] HAVE_KRB5_ENCTYPE_TO_STRING
  421. [2022-06-17 08:44:52.022197] HAVE_KRB5_ENCTYPE_TO_STRING_WITH_KRB5_CONTEXT_ARG
  422. [2022-06-17 08:44:52.023755] HAVE_KRB5_FREE_ERROR_CONTENTS
  423. [2022-06-17 08:44:52.025409] HAVE_KRB5_FREE_HOST_REALM
  424. [2022-06-17 08:44:52.027010] HAVE_KRB5_FWD_TGT_CREDS
  425. [2022-06-17 08:44:52.028725] HAVE_KRB5_GET_CREDS
  426. [2022-06-17 08:44:52.030326] HAVE_KRB5_GET_CREDS_OPT_ALLOC
  427. [2022-06-17 08:44:52.031845] HAVE_KRB5_GET_CREDS_OPT_SET_IMPERSONATE
  428. [2022-06-17 08:44:52.033514] HAVE_KRB5_GET_DEFAULT_IN_TKT_ETYPES
  429. [2022-06-17 08:44:52.035152] HAVE_KRB5_GET_HOST_REALM
  430. [2022-06-17 08:44:52.036766] HAVE_KRB5_GET_INIT_CREDS_KEYBLOCK
  431. [2022-06-17 08:44:52.038499] HAVE_KRB5_GET_INIT_CREDS_OPT_ALLOC
  432. [2022-06-17 08:44:52.040022] HAVE_KRB5_GET_INIT_CREDS_OPT_FREE
  433. [2022-06-17 08:44:52.052229] HAVE_KRB5_GET_INIT_CREDS_OPT_GET_ERROR
  434. [2022-06-17 08:44:52.054276] HAVE_KRB5_GET_INIT_CREDS_OPT_SET_PAC_REQUEST
  435. [2022-06-17 08:44:52.055850] HAVE_KRB5_GET_PW_SALT
  436. [2022-06-17 08:44:52.057479] HAVE_KRB5_GET_RENEWED_CREDS
  437. [2022-06-17 08:44:52.059125] HAVE_KRB5_KEYBLOCK_INIT
  438. [2022-06-17 08:44:52.060764] HAVE_KRB5_KEYBLOCK_KEYVALUE
  439. [2022-06-17 08:44:52.062499] HAVE_KRB5_KEYTAB_ENTRY_KEYBLOCK
  440. [2022-06-17 08:44:52.064098] HAVE_KRB5_KRBHST_GET_ADDRINFO
  441. [2022-06-17 08:44:52.065862] HAVE_KRB5_KRBHST_INIT
  442. [2022-06-17 08:44:52.067359] HAVE_KRB5_KT_COMPARE
  443. [2022-06-17 08:44:52.069080] HAVE_KRB5_KT_FREE_ENTRY
  444. [2022-06-17 08:44:52.070677] HAVE_KRB5_KU_OTHER_CKSUM
  445. [2022-06-17 08:44:52.072281] HAVE_KRB5_MAKE_PRINCIPAL
  446. [2022-06-17 08:44:52.073999] HAVE_KRB5_MK_REQ_EXTENDED
  447. [2022-06-17 08:44:52.075758] HAVE_KRB5_PDU_NONE_DECL
  448. [2022-06-17 08:44:52.077266] HAVE_KRB5_PRINCIPAL_COMPARE_ANY_REALM
  449. [2022-06-17 08:44:52.078943] HAVE_KRB5_PRINCIPAL_GET_COMP_STRING
  450. [2022-06-17 08:44:52.080453] HAVE_KRB5_PRINCIPAL_GET_NUM_COMP
  451. [2022-06-17 08:44:52.082186] HAVE_KRB5_PRINCIPAL_GET_REALM
  452. [2022-06-17 08:44:52.083749] HAVE_KRB5_PRINCIPAL_GET_TYPE
  453. [2022-06-17 08:44:52.085398] HAVE_KRB5_PRINCIPAL_SET_REALM
  454. [2022-06-17 08:44:52.087038] HAVE_KRB5_PRINCIPAL_SET_TYPE
  455. [2022-06-17 08:44:52.088769] HAVE_KRB5_PROMPT_TYPE
  456. [2022-06-17 08:44:52.090262] HAVE_KRB5_REALM_TYPE
  457. [2022-06-17 08:44:52.091877] HAVE_KRB5_SET_DEFAULT_IN_TKT_ETYPES
  458. [2022-06-17 08:44:52.093558] HAVE_KRB5_SET_REAL_TIME
  459. [2022-06-17 08:44:52.095208] HAVE_KRB5_STRING_TO_KEY
  460. [2022-06-17 08:44:52.096827] HAVE_KRB5_STRING_TO_KEY_SALT
  461. [2022-06-17 08:44:52.098454] HAVE_KRB5_WARNX
  462. [2022-06-17 08:44:52.100161] HAVE_KRB_STRUCT_WINSIZE
  463. [2022-06-17 08:44:52.101775] HAVE_LARGEFILE
  464. [2022-06-17 08:44:52.103441] HAVE_LCHOWN
  465. [2022-06-17 08:44:52.104961] HAVE_LDWRAP
  466. [2022-06-17 08:44:52.112987] HAVE_LIBAVAHI_CLIENT
  467. [2022-06-17 08:44:52.114722] HAVE_LIBAVAHI_COMMON
  468. [2022-06-17 08:44:52.116430] HAVE_LIBCAP
  469. [2022-06-17 08:44:52.118069] HAVE_LIBCRYPT
  470. [2022-06-17 08:44:52.123593] HAVE_LIBCRYPTO
  471. [2022-06-17 08:44:52.125218] HAVE_LIBFUSE
  472. [2022-06-17 08:44:52.126873] HAVE_LIBGLIB_2_0
  473. [2022-06-17 08:44:52.130208] HAVE_LIBKRB5
  474. [2022-06-17 08:44:52.131753] HAVE_LIBNCURSES
  475. [2022-06-17 08:44:52.133455] HAVE_LIBPAM
  476. [2022-06-17 08:44:52.135102] HAVE_LIBPOPT
  477. [2022-06-17 08:44:52.136724] HAVE_LIBREADLINE
  478. [2022-06-17 08:44:52.138341] HAVE_LIBREPLACE
  479. [2022-06-17 08:44:52.139943] HAVE_LIBRESOLV
  480. [2022-06-17 08:44:52.141552] HAVE_LIBTASN1
  481. [2022-06-17 08:44:52.143230] HAVE_LIBURING
  482. [2022-06-17 08:44:52.144869] HAVE_LIBZ
  483. [2022-06-17 08:44:52.146504] HAVE_LINK
  484. [2022-06-17 08:44:52.148113] HAVE_LINUX_FALLOCATE
  485. [2022-06-17 08:44:52.149732] HAVE_LINUX_INOTIFY
  486. [2022-06-17 08:44:52.151337] HAVE_LINUX_IOCTL
  487. [2022-06-17 08:44:52.152995] HAVE_LINUX_READAHEAD
  488. [2022-06-17 08:44:52.154621] HAVE_LINUX_SPLICE
  489. [2022-06-17 08:44:52.156249] HAVE_LINUX_THREAD_CREDENTIALS
  490. [2022-06-17 08:44:52.158002] HAVE_LITTLE_ENDIAN
  491. [2022-06-17 08:44:52.159618] HAVE_LONGJMP
  492. [2022-06-17 08:44:52.161115] HAVE_LONG_LONG
  493. [2022-06-17 08:44:52.162830] HAVE_LSTAT
  494. [2022-06-17 08:44:52.164479] HAVE_LUTIMES
  495. [2022-06-17 08:44:52.165988] HAVE_MAKEDEV
  496. [2022-06-17 08:44:52.167716] HAVE_MEMALIGN
  497. [2022-06-17 08:44:52.169230] HAVE_MEMCPY
  498. [2022-06-17 08:44:52.170849] HAVE_MEMMEM
  499. [2022-06-17 08:44:52.172461] HAVE_MEMMOVE
  500. [2022-06-17 08:44:52.174158] HAVE_MEMSET
  501. [2022-06-17 08:44:52.175784] HAVE_MKDIR_MODE
  502. [2022-06-17 08:44:52.177498] HAVE_MKDTEMP
  503. [2022-06-17 08:44:52.178998] HAVE_MKNOD
  504. [2022-06-17 08:44:52.180611] HAVE_MKNODAT
  505. [2022-06-17 08:44:52.182339] HAVE_MKTIME
  506. [2022-06-17 08:44:52.183925] HAVE_MLOCK
  507. [2022-06-17 08:44:52.185549] HAVE_MLOCKALL
  508. [2022-06-17 08:44:52.187160] HAVE_MMAP
  509. [2022-06-17 08:44:52.188774] HAVE_MREMAP
  510. [2022-06-17 08:44:52.190382] HAVE_MUNLOCK
  511. [2022-06-17 08:44:52.191998] HAVE_MUNLOCKALL
  512. [2022-06-17 08:44:52.193664] HAVE_NATIVE_ICONV
  513. [2022-06-17 08:44:52.195285] HAVE_NEW_LIBREADLINE
  514. [2022-06-17 08:44:52.197002] HAVE_NFTW
  515. [2022-06-17 08:44:52.198491] HAVE_OPENAT
  516. [2022-06-17 08:44:52.200096] HAVE_OPENPTY
  517. [2022-06-17 08:44:52.201815] HAVE_OPEN_O_DIRECT
  518. [2022-06-17 08:44:52.203386] HAVE_PAM_START
  519. [2022-06-17 08:44:52.205118] HAVE_PATHCONF
  520. [2022-06-17 08:44:52.206725] HAVE_PEERCRED
  521. [2022-06-17 08:44:52.208324] HAVE_PIPE
  522. [2022-06-17 08:44:52.209820] HAVE_POLL
  523. [2022-06-17 08:44:52.211428] HAVE_POPT
  524. [2022-06-17 08:44:52.213079] HAVE_POPTGETCONTEXT
  525. [2022-06-17 08:44:52.214705] HAVE_POSIX_CAPABILITIES
  526. [2022-06-17 08:44:52.216448] HAVE_POSIX_FADVISE
  527. [2022-06-17 08:44:52.217953] HAVE_POSIX_FALLOCATE
  528. [2022-06-17 08:44:52.219566] HAVE_POSIX_MEMALIGN
  529. [2022-06-17 08:44:52.221170] HAVE_POSIX_OPENPT
  530. [2022-06-17 08:44:52.222910] HAVE_PRCTL
  531. [2022-06-17 08:44:52.224414] HAVE_PREAD
  532. [2022-06-17 08:44:52.226027] HAVE_PREAD_DECL
  533. [2022-06-17 08:44:52.227640] HAVE_PRINTF
  534. [2022-06-17 08:44:52.229362] HAVE_PROGRAM_INVOCATION_SHORT_NAME
  535. [2022-06-17 08:44:52.230882] HAVE_PTHREAD
  536. [2022-06-17 08:44:52.232483] HAVE_PTHREAD_ATTR_INIT
  537. [2022-06-17 08:44:52.234265] HAVE_PTHREAD_CREATE
  538. [2022-06-17 08:44:52.235779] HAVE_PTHREAD_MUTEXATTR_SETROBUST
  539. [2022-06-17 08:44:52.237517] HAVE_PTHREAD_MUTEX_CONSISTENT
  540. [2022-06-17 08:44:52.239143] HAVE_PTRDIFF_T
  541. [2022-06-17 08:44:52.240752] HAVE_PUTENV
  542. [2022-06-17 08:44:52.242352] HAVE_PWRITE
  543. [2022-06-17 08:44:52.244040] HAVE_PWRITE_DECL
  544. [2022-06-17 08:44:52.245550] HAVE_QUOTACTL_LINUX
  545. [2022-06-17 08:44:52.247170] HAVE_RAND
  546. [2022-06-17 08:44:52.248881] HAVE_RANDOM
  547. [2022-06-17 08:44:52.250485] HAVE_READAHEAD_DECL
  548. [2022-06-17 08:44:52.251982] HAVE_READLINK
  549. [2022-06-17 08:44:52.253667] HAVE_READV
  550. [2022-06-17 08:44:52.255291] HAVE_REALPATH
  551. [2022-06-17 08:44:52.257016] HAVE_RENAME
  552. [2022-06-17 08:44:52.258512] HAVE_RES_SEARCH
  553. [2022-06-17 08:44:52.260121] HAVE_RL_COMPLETION_MATCHES
  554. [2022-06-17 08:44:52.261734] HAVE_ROBUST_MUTEXES
  555. [2022-06-17 08:44:52.263506] HAVE_SA_FAMILY_T
  556. [2022-06-17 08:44:52.265020] HAVE_SA_SIGINFO_DECL
  557. [2022-06-17 08:44:52.266642] HAVE_SECURE_MKSTEMP
  558. [2022-06-17 08:44:52.268252] HAVE_SELECT
  559. [2022-06-17 08:44:52.269865] HAVE_SENDFILE
  560. [2022-06-17 08:44:52.271488] HAVE_SENDMSG
  561. [2022-06-17 08:44:52.273142] HAVE_SETBUFFER
  562. [2022-06-17 08:44:52.274779] HAVE_SETEGID
  563. [2022-06-17 08:44:52.276491] HAVE_SETENV
  564. [2022-06-17 08:44:52.277993] HAVE_SETENV_DECL
  565. [2022-06-17 08:44:52.279601] HAVE_SETEUID
  566. [2022-06-17 08:44:52.281204] HAVE_SETGID
  567. [2022-06-17 08:44:52.282811] HAVE_SETGROUPS
  568. [2022-06-17 08:44:52.284497] HAVE_SETHOSTENT
  569. [2022-06-17 08:44:52.286112] HAVE_SETITIMER
  570. [2022-06-17 08:44:52.287728] HAVE_SETLINEBUF
  571. [2022-06-17 08:44:52.289347] HAVE_SETLOCALE
  572. [2022-06-17 08:44:52.290948] HAVE_SETMNTENT
  573. [2022-06-17 08:44:52.292548] HAVE_SETPGID
  574. [2022-06-17 08:44:52.294317] HAVE_SETREGID
  575. [2022-06-17 08:44:52.295825] HAVE_SETRESGID
  576. [2022-06-17 08:44:52.297442] HAVE_SETRESGID_DECL
  577. [2022-06-17 08:44:52.299075] HAVE_SETRESUID
  578. [2022-06-17 08:44:52.300680] HAVE_SETRESUID_DECL
  579. [2022-06-17 08:44:52.302406] HAVE_SETREUID
  580. [2022-06-17 08:44:52.303978] HAVE_SETSID
  581. [2022-06-17 08:44:52.305699] HAVE_SETUID
  582. [2022-06-17 08:44:52.307201] HAVE_SHARED_MMAP
  583. [2022-06-17 08:44:52.308816] HAVE_SIGACTION
  584. [2022-06-17 08:44:52.310294] HAVE_SIGLONGJMP
  585. [2022-06-17 08:44:52.311749] HAVE_SIGPROCMASK
  586. [2022-06-17 08:44:52.313266] HAVE_SIGSET
  587. [2022-06-17 08:44:52.314917] HAVE_SIG_ATOMIC_T_TYPE
  588. [2022-06-17 08:44:52.316542] HAVE_SIMPLE_C_PROG
  589. [2022-06-17 08:44:52.318027] HAVE_SIZE_T
  590. [2022-06-17 08:44:52.319709] HAVE_SNPRINTF
  591. [2022-06-17 08:44:52.321227] HAVE_SOCKET
  592. [2022-06-17 08:44:52.322849] HAVE_SOCKETPAIR
  593. [2022-06-17 08:44:52.324535] HAVE_SOCKLEN_T
  594. [2022-06-17 08:44:52.326157] HAVE_SPLICE_DECL
  595. [2022-06-17 08:44:52.327766] HAVE_SRAND
  596. [2022-06-17 08:44:52.329491] HAVE_SRANDOM
  597. [2022-06-17 08:44:52.330985] HAVE_SSIZE_T
  598. [2022-06-17 08:44:52.332622] HAVE_SS_FAMILY
  599. [2022-06-17 08:44:52.334296] HAVE_STATFS_F_FSID
  600. [2022-06-17 08:44:52.335921] HAVE_STATVFS
  601. [2022-06-17 08:44:52.337660] HAVE_STATVFS_F_FLAG
  602. [2022-06-17 08:44:52.339164] HAVE_STAT_HIRES_TIMESTAMPS
  603. [2022-06-17 08:44:52.340887] HAVE_STAT_ST_BLKSIZE
  604. [2022-06-17 08:44:52.342383] HAVE_STAT_ST_BLOCKS
  605. [2022-06-17 08:44:52.344050] HAVE_STRCASECMP
  606. [2022-06-17 08:44:52.345760] HAVE_STRCASESTR
  607. [2022-06-17 08:44:52.347272] HAVE_STRCHR
  608. [2022-06-17 08:44:52.348888] HAVE_STRCPY
  609. [2022-06-17 08:44:52.350496] HAVE_STRDUP
  610. [2022-06-17 08:44:52.352098] HAVE_STRERROR
  611. [2022-06-17 08:44:52.353859] HAVE_STRERROR_R
  612. [2022-06-17 08:44:52.355360] HAVE_STRFTIME
  613. [2022-06-17 08:44:52.356973] HAVE_STRLCAT
  614. [2022-06-17 08:44:52.358590] HAVE_STRLCPY
  615. [2022-06-17 08:44:52.360225] HAVE_STRNCASECMP
  616. [2022-06-17 08:44:52.362080] HAVE_STRNCPY
  617. [2022-06-17 08:44:52.363784] HAVE_STRNDUP
  618. [2022-06-17 08:44:52.365313] HAVE_STRNLEN
  619. [2022-06-17 08:44:52.366942] HAVE_STRPBRK
  620. [2022-06-17 08:44:52.368676] HAVE_STRPTIME
  621. [2022-06-17 08:44:52.370195] HAVE_STRSEP
  622. [2022-06-17 08:44:52.371807] HAVE_STRSIGNAL
  623. [2022-06-17 08:44:52.373476] HAVE_STRTOK_R
  624. [2022-06-17 08:44:52.375100] HAVE_STRTOL
  625. [2022-06-17 08:44:52.376715] HAVE_STRTOLL
  626. [2022-06-17 08:44:52.378424] HAVE_STRTOULL
  627. [2022-06-17 08:44:52.379916] HAVE_STRUCT_ADDRINFO
  628. [2022-06-17 08:44:52.381536] HAVE_STRUCT_IFADDRS
  629. [2022-06-17 08:44:52.383209] HAVE_STRUCT_MSGHDR_MSG_CONTROL
  630. [2022-06-17 08:44:52.384971] HAVE_STRUCT_SIGEVENT
  631. [2022-06-17 08:44:52.386479] HAVE_STRUCT_SIGEVENT_SIGEV_VALUE_SIVAL_PTR
  632. [2022-06-17 08:44:52.388134] HAVE_STRUCT_SOCKADDR
  633. [2022-06-17 08:44:52.390233] HAVE_STRUCT_SOCKADDR_IN6
  634. [2022-06-17 08:44:52.391838] HAVE_STRUCT_SOCKADDR_STORAGE
  635. [2022-06-17 08:44:52.393530] HAVE_STRUCT_STAT_ST_MTIM_TV_NSEC
  636. [2022-06-17 08:44:52.395183] HAVE_STRUCT_STAT_ST_RDEV
  637. [2022-06-17 08:44:52.396800] HAVE_STRUCT_TIMESPEC
  638. [2022-06-17 08:44:52.398421] HAVE_STRUCT_WINSIZE
  639. [2022-06-17 08:44:52.400036] HAVE_ST_RDEV
  640. [2022-06-17 08:44:52.401635] HAVE_SWAB
  641. [2022-06-17 08:44:52.403295] HAVE_SYMLINK
  642. [2022-06-17 08:44:52.404925] HAVE_SYSCALL
  643. [2022-06-17 08:44:52.406548] HAVE_SYSCONF
  644. [2022-06-17 08:44:52.408156] HAVE_SYSLOG
  645. [2022-06-17 08:44:52.409770] HAVE_TGETENT
  646. [2022-06-17 08:44:52.411376] HAVE_TIMEGM
  647. [2022-06-17 08:44:52.413041] HAVE_TIRPC
  648. [2022-06-17 08:44:52.414673] HAVE_UCONTEXT_T
  649. [2022-06-17 08:44:52.416286] HAVE_UINT16_T
  650. [2022-06-17 08:44:52.417906] HAVE_UINT32_T
  651. [2022-06-17 08:44:52.419526] HAVE_UINT64_T
  652. [2022-06-17 08:44:52.421137] HAVE_UINT8_T
  653. [2022-06-17 08:44:52.422736] HAVE_UINTPTR_T
  654. [2022-06-17 08:44:52.424407] HAVE_UMASK
  655. [2022-06-17 08:44:52.426014] HAVE_UNAME
  656. [2022-06-17 08:44:52.427630] HAVE_UNIXSOCKET
  657. [2022-06-17 08:44:52.429240] HAVE_UNSETENV
  658. [2022-06-17 08:44:52.430847] HAVE_UNSHARE_CLONE_FS
  659. [2022-06-17 08:44:52.432467] HAVE_URING
  660. [2022-06-17 08:44:52.434166] HAVE_USLEEP
  661. [2022-06-17 08:44:52.435795] HAVE_UTIMBUF
  662. [2022-06-17 08:44:52.437412] HAVE_UTIME
  663. [2022-06-17 08:44:52.439031] HAVE_UTIMENSAT
  664. [2022-06-17 08:44:52.440651] HAVE_UTIMES
  665. [2022-06-17 08:44:52.442266] HAVE_U_CHAR
  666. [2022-06-17 08:44:52.443933] HAVE_U_INT32_T
  667. [2022-06-17 08:44:52.445551] HAVE_VASPRINTF
  668. [2022-06-17 08:44:52.447148] HAVE_VA_COPY
  669. [2022-06-17 08:44:52.448755] HAVE_VDPRINTF
  670. [2022-06-17 08:44:52.450359] HAVE_VISIBILITY_ATTR
  671. [2022-06-17 08:44:52.451970] HAVE_VOLATILE
  672. [2022-06-17 08:44:52.453654] HAVE_VSNPRINTF
  673. [2022-06-17 08:44:52.455290] HAVE_VSYSLOG
  674. [2022-06-17 08:44:52.456900] HAVE_WAIT4
  675. [2022-06-17 08:44:52.458509] HAVE_WAITPID
  676. [2022-06-17 08:44:52.460109] HAVE_WARN
  677. [2022-06-17 08:44:52.461709] HAVE_WARNX
  678. [2022-06-17 08:44:52.463358] HAVE_WNO_FORMAT_TRUNCATION
  679. [2022-06-17 08:44:52.465011] HAVE_WNO_STRICT_OVERFLOW
  680. [2022-06-17 08:44:52.466641] HAVE_WNO_UNUSED_FUNCTION
  681. [2022-06-17 08:44:52.468269] HAVE_WRITEV
  682. [2022-06-17 08:44:52.469890] HAVE_WS_XPIXEL
  683. [2022-06-17 08:44:52.471504] HAVE_WS_YPIXEL
  684. [2022-06-17 08:44:52.473174] HAVE_XATTR_SUPPORT
  685. [2022-06-17 08:44:52.474799] HAVE_XATTR_XATTR
  686. [2022-06-17 08:44:52.476405] HAVE_ZLIB
  687. [2022-06-17 08:44:52.478029] HAVE__Bool
  688. [2022-06-17 08:44:52.479642] HAVE__RES
  689. [2022-06-17 08:44:52.481261] HAVE__VA_ARGS__MACRO
  690. [2022-06-17 08:44:52.482907] HAVE___ATTRIBUTE__
  691. [2022-06-17 08:44:52.484532] HAVE___SYNC_FETCH_AND_ADD
  692. [2022-06-17 08:44:52.486153] HAVE___THREAD
  693. [2022-06-17 08:44:52.487768]
  694. [2022-06-17 08:44:52.489384] --with Options:
  695. [2022-06-17 08:44:52.490999] WITH_AVAHI_SUPPORT
  696. [2022-06-17 08:44:52.492490] WITH_PTHREADPOOL
  697. [2022-06-17 08:44:52.494300] WITH_QUOTAS
  698. [2022-06-17 08:44:52.495919] WITH_SYSLOG
  699. [2022-06-17 08:44:52.497538] WITH_TEVENT_GLIB_GLUE
  700. [2022-06-17 08:44:52.499138]
  701. [2022-06-17 08:44:52.500743] Build Options:
  702. [2022-06-17 08:44:52.502366] BOOL_DEFINED
  703. [2022-06-17 08:44:52.504065] BROKEN_NISPLUS_INCLUDE_FILES
  704. [2022-06-17 08:44:52.505692] COMPILER_SUPPORTS_LL
  705. [2022-06-17 08:44:52.507312] CONFIG_H_IS_FROM_SAMBA
  706. [2022-06-17 08:44:52.508920] DEFAULT_DOS_CHARSET
  707. [2022-06-17 08:44:52.510410] DEFAULT_UNIX_CHARSET
  708. [2022-06-17 08:44:52.511990] GETCWD_TAKES_NULL
  709. [2022-06-17 08:44:52.513794] INLINE_MACRO
  710. [2022-06-17 08:44:52.515421] KRB5_CREDS_OPT_FREE_REQUIRES_CONTEXT
  711. [2022-06-17 08:44:52.517054] KRB5_PRINC_REALM_RETURNS_REALM
  712. [2022-06-17 08:44:52.518675] LIBREPLACE_NETWORK_CHECKS
  713. [2022-06-17 08:44:52.520286] LINUX
  714. [2022-06-17 08:44:52.521888] LINUX_SENDFILE_API
  715. [2022-06-17 08:44:52.523557] REALPATH_TAKES_NULL
  716. [2022-06-17 08:44:52.525196] RETSIGTYPE
  717. [2022-06-17 08:44:52.526819] SAMBA4_USES_HEIMDAL
  718. [2022-06-17 08:44:52.528308] SEEKDIR_RETURNS_VOID
  719. [2022-06-17 08:44:52.530034] SHLIBEXT
  720. [2022-06-17 08:44:52.531647] SIZEOF_BLKCNT_T_8
  721. [2022-06-17 08:44:52.533310] SIZEOF_BOOL
  722. [2022-06-17 08:44:52.534936] SIZEOF_CHAR
  723. [2022-06-17 08:44:52.536567] SIZEOF_DEV_T
  724. [2022-06-17 08:44:52.538189] SIZEOF_INO_T
  725. [2022-06-17 08:44:52.539791] SIZEOF_INT
  726. [2022-06-17 08:44:52.541407] SIZEOF_INT16_T
  727. [2022-06-17 08:44:52.543766] SIZEOF_INT32_T
  728. [2022-06-17 08:44:52.546046] SIZEOF_INT64_T
  729. [2022-06-17 08:44:52.548876] SIZEOF_INT8_T
  730. [2022-06-17 08:44:52.551197] SIZEOF_LONG
  731. [2022-06-17 08:44:52.553299] SIZEOF_LONG_LONG
  732. [2022-06-17 08:44:52.554981] SIZEOF_OFF_T
  733. [2022-06-17 08:44:52.556619] SIZEOF_SHORT
  734. [2022-06-17 08:44:52.558242] SIZEOF_SIZE_T
  735. [2022-06-17 08:44:52.559861] SIZEOF_SSIZE_T
  736. [2022-06-17 08:44:52.561472] SIZEOF_TIME_T
  737. [2022-06-17 08:44:52.563149] SIZEOF_UINT16_T
  738. [2022-06-17 08:44:52.564793] SIZEOF_UINT32_T
  739. [2022-06-17 08:44:52.566417] SIZEOF_UINT64_T
  740. [2022-06-17 08:44:52.568038] SIZEOF_UINT8_T
  741. [2022-06-17 08:44:52.569663] SIZEOF_VOID_P
  742. [2022-06-17 08:44:52.571274] SRCDIR
  743. [2022-06-17 08:44:52.572918] STAT_STATVFS
  744. [2022-06-17 08:44:52.574538] STAT_ST_BLOCKSIZE
  745. [2022-06-17 08:44:52.576160] STDC_HEADERS
  746. [2022-06-17 08:44:52.577656] STRERROR_R_XSI_NOT_GNU
  747. [2022-06-17 08:44:52.579373] STRING_SHARED_MODULES
  748. [2022-06-17 08:44:52.580995] STRING_STATIC_MODULES
  749. [2022-06-17 08:44:52.582618] SUMMARY_PASSES
  750. [2022-06-17 08:44:52.584307] SYSCONF_SC_NGROUPS_MAX
  751. [2022-06-17 08:44:52.585947] SYSCONF_SC_NPROCESSORS_ONLN
  752. [2022-06-17 08:44:52.587591] SYSCONF_SC_PAGESIZE
  753. [2022-06-17 08:44:52.589222] SYSTEM_UNAME_MACHINE
  754. [2022-06-17 08:44:52.590842] SYSTEM_UNAME_RELEASE
  755. [2022-06-17 08:44:52.592460] SYSTEM_UNAME_SYSNAME
  756. [2022-06-17 08:44:52.594010] SYSTEM_UNAME_VERSION
  757. [2022-06-17 08:44:52.595495] TALLOC_BUILD_VERSION_MAJOR
  758. [2022-06-17 08:44:52.597204] TALLOC_BUILD_VERSION_MINOR
  759. [2022-06-17 08:44:52.598841] TALLOC_BUILD_VERSION_RELEASE
  760. [2022-06-17 08:44:52.600480] TEVENT_NUM_SIGNALS
  761. [2022-06-17 08:44:52.602095] TIME_WITH_SYS_TIME
  762. [2022-06-17 08:44:52.603775] USE_COPY_FILE_RANGE
  763. [2022-06-17 08:44:52.605402] USE_LINUX_32BIT_SYSCALLS
  764. [2022-06-17 08:44:52.607012] USE_TDB_MUTEX_LOCKING
  765. [2022-06-17 08:44:52.608619] USING_SYSTEM_ASN1_COMPILE
  766. [2022-06-17 08:44:52.610228] USING_SYSTEM_COMPILE_ET
  767. [2022-06-17 08:44:52.611852] USING_SYSTEM_POPT
  768. [2022-06-17 08:44:52.613533] VALUEOF_GNUTLS_CIPHER_AES_128_CFB8
  769. [2022-06-17 08:44:52.615182] VALUEOF_GNUTLS_MAC_AES_CMAC_128
  770. [2022-06-17 08:44:52.616813] VALUEOF_NSIG
  771. [2022-06-17 08:44:52.618429] VALUEOF_SIGRTMAX
  772. [2022-06-17 08:44:52.620023] VALUEOF_SIGRTMIN
  773. [2022-06-17 08:44:52.621627] VALUEOF__NSIG
  774. [2022-06-17 08:44:52.623330] VOID_RETSIGTYPE
  775. [2022-06-17 08:44:52.624974] WINEXE_LDFLAGS
  776. [2022-06-17 08:44:52.627152] _GNU_SOURCE
  777. [2022-06-17 08:44:52.628847] _HAVE_SENDFILE
  778. [2022-06-17 08:44:52.630483] _POSIX_FALLOCATE_CAPABLE_LIBC
  779. [2022-06-17 08:44:52.632119] _SAMBA_BUILD_
  780. [2022-06-17 08:44:52.633781] _XOPEN_SOURCE_EXTENDED
  781. [2022-06-17 08:44:52.635412] auth_script_init
  782. [2022-06-17 08:44:52.637032] loff_t
  783. [2022-06-17 08:44:52.638663] offset_t
  784. [2022-06-17 08:44:52.640268] static_decl_auth
  785. [2022-06-17 08:44:52.641876] static_decl_charset
  786. [2022-06-17 08:44:52.643507] static_decl_gpext
  787. [2022-06-17 08:44:52.645119] static_decl_idmap
  788. [2022-06-17 08:44:52.646717] static_decl_nss_info
  789. [2022-06-17 08:44:52.648329] static_decl_pdb
  790. [2022-06-17 08:44:52.649945] static_decl_perfcount
  791. [2022-06-17 08:44:52.651563] static_decl_rpc
  792. [2022-06-17 08:44:52.653238] static_decl_vfs
  793. [2022-06-17 08:44:52.654857] static_init_auth
  794. [2022-06-17 08:44:52.656476] static_init_charset
  795. [2022-06-17 08:44:52.658096] static_init_gpext
  796. [2022-06-17 08:44:52.659704] static_init_idmap
  797. [2022-06-17 08:44:52.661323] static_init_nss_info
  798. [2022-06-17 08:44:52.662819] static_init_pdb
  799. [2022-06-17 08:44:52.664478] static_init_perfcount
  800. [2022-06-17 08:44:52.666100] static_init_rpc
  801. [2022-06-17 08:44:52.667721] static_init_vfs
  802. [2022-06-17 08:44:52.669330] uint_t
  803. [2022-06-17 08:44:52.670927] vfs_btrfs_init
  804. [2022-06-17 08:44:52.672545] vfs_cap_init
  805. [2022-06-17 08:44:52.674323] vfs_catia_init
  806. [2022-06-17 08:44:52.675967] vfs_crossrename_init
  807. [2022-06-17 08:44:52.677584] vfs_default_quota_init
  808. [2022-06-17 08:44:52.679189] vfs_fake_perms_init
  809. [2022-06-17 08:44:52.680791] vfs_fruit_init
  810. [2022-06-17 08:44:52.682401] vfs_io_uring_init
  811. [2022-06-17 08:44:52.684119] vfs_offline_init
  812. [2022-06-17 08:44:52.685746] vfs_readonly_init
  813. [2022-06-17 08:44:52.687358] vfs_recycle_init
  814. [2022-06-17 08:44:52.688964] vfs_shadow_copy2_init
  815. [2022-06-17 08:44:52.690579] vfs_streams_xattr_init
  816. [2022-06-17 08:44:52.692188] vfs_widelinks_init
  817. [2022-06-17 08:44:52.693839] vfs_xattr_tdb_init
  818. [2022-06-17 08:44:52.695462]
  819. [2022-06-17 08:44:52.697077] Cluster support features:
  820. [2022-06-17 08:44:52.698696] NONE
  821. [2022-06-17 08:44:52.700299]
  822. [2022-06-17 08:44:52.701912] Type sizes:
  823. [2022-06-17 08:44:52.703568] sizeof(char): 1
  824. [2022-06-17 08:44:52.705187] sizeof(int): 4
  825. [2022-06-17 08:44:52.706793] sizeof(long): 4
  826. [2022-06-17 08:44:52.708419] sizeof(long long): 8
  827. [2022-06-17 08:44:52.710046] sizeof(uint8_t): 1
  828. [2022-06-17 08:44:52.711667] sizeof(uint16_t): 2
  829. [2022-06-17 08:44:52.713316] sizeof(uint32_t): 4
  830. [2022-06-17 08:44:52.714940] sizeof(short): 2
  831. [2022-06-17 08:44:52.716556] sizeof(void*): 4
  832. [2022-06-17 08:44:52.718167] sizeof(size_t): 4
  833. [2022-06-17 08:44:52.719785] sizeof(off_t): 8
  834. [2022-06-17 08:44:52.721401] sizeof(ino_t): 8
  835. [2022-06-17 08:44:52.723074] sizeof(dev_t): 8
  836. [2022-06-17 08:44:52.724585]
  837. [2022-06-17 08:44:52.726288] Builtin modules:
  838. [2022-06-17 08:44:52.728080] vfs_default vfs_not_implemented auth_builtin auth_sam auth_unix pdb_smbpasswd pdb_tdbsam
  839. [2022-06-17 08:44:52.729624] lp_load_ex: refreshing parameters
  840. [2022-06-17 08:44:52.731117] Initialising global parameters
  841. [2022-06-17 08:44:52.732614] rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384)
  842. [2022-06-17 08:44:52.734204] INFO: Current debug levels:
  843. [2022-06-17 08:44:52.735694] all: 10
  844. [2022-06-17 08:44:52.737162] tdb: 10
  845. [2022-06-17 08:44:52.738625] printdrivers: 10
  846. [2022-06-17 08:44:52.740088] lanman: 10
  847. [2022-06-17 08:44:52.741913] smb: 10
  848. [2022-06-17 08:44:52.743602] rpc_parse: 10
  849. [2022-06-17 08:44:52.745237] rpc_srv: 10
  850. [2022-06-17 08:44:52.746863] rpc_cli: 10
  851. [2022-06-17 08:44:52.748479] passdb: 10
  852. [2022-06-17 08:44:52.750094] sam: 10
  853. [2022-06-17 08:44:52.751709] auth: 10
  854. [2022-06-17 08:44:52.753370] winbind: 10
  855. [2022-06-17 08:44:52.755018] vfs: 10
  856. [2022-06-17 08:44:52.756642] idmap: 10
  857. [2022-06-17 08:44:52.758136] quota: 10
  858. [2022-06-17 08:44:52.759853] acls: 10
  859. [2022-06-17 08:44:52.761480] locking: 10
  860. [2022-06-17 08:44:52.763019] msdfs: 10
  861. [2022-06-17 08:44:52.764756] dmapi: 10
  862. [2022-06-17 08:44:52.766246] registry: 10
  863. [2022-06-17 08:44:52.767961] scavenger: 10
  864. [2022-06-17 08:44:52.769573] dns: 10
  865. [2022-06-17 08:44:52.771188] ldb: 10
  866. [2022-06-17 08:44:52.772788] tevent: 10
  867. [2022-06-17 08:44:52.774464] auth_audit: 10
  868. [2022-06-17 08:44:52.776077] auth_json_audit: 10
  869. [2022-06-17 08:44:52.777569] kerberos: 10
  870. [2022-06-17 08:44:52.779277] drs_repl: 10
  871. [2022-06-17 08:44:52.780894] smb2: 10
  872. [2022-06-17 08:44:52.782499] smb2_credits: 10
  873. [2022-06-17 08:44:52.784311] dsdb_audit: 10
  874. [2022-06-17 08:44:52.785932] dsdb_json_audit: 10
  875. [2022-06-17 08:44:52.787547] dsdb_password_audit: 10
  876. [2022-06-17 08:44:52.789167] dsdb_password_json_audit: 10
  877. [2022-06-17 08:44:52.790798] dsdb_transaction_audit: 10
  878. [2022-06-17 08:44:52.792435] dsdb_transaction_json_audit: 10
  879. [2022-06-17 08:44:52.794035] dsdb_group_audit: 10
  880. [2022-06-17 08:44:52.795744] dsdb_group_json_audit: 10
  881. [2022-06-17 08:44:52.797363] Processing section "[global]"
  882. [2022-06-17 08:44:52.798978] doing parameter netbios name = zalupa
  883. [2022-06-17 08:44:52.810931] doing parameter interfaces = br-lan
  884. [2022-06-17 08:44:52.812798] doing parameter server string = SASAm
  885. [2022-06-17 08:44:52.814584] doing parameter unix charset = UTF-8
  886. [2022-06-17 08:44:52.816249] doing parameter workgroup = WORKGROUP
  887. [2022-06-17 08:44:52.817899] doing parameter log level = 2
  888. [2022-06-17 08:44:52.819521] doing parameter bind interfaces only = yes
  889. [2022-06-17 08:44:52.821152] doing parameter deadtime = 15
  890. [2022-06-17 08:44:52.822785] doing parameter enable core files = no
  891. [2022-06-17 08:44:52.824486] doing parameter security = user
  892. [2022-06-17 08:44:52.826122] doing parameter debug timestamp = yes
  893. [2022-06-17 08:44:52.827759] doing parameter invalid users = root
  894. [2022-06-17 08:44:52.829403] doing parameter map to guest = Bad User
  895. [2022-06-17 08:44:52.831031] doing parameter null passwords = yes
  896. [2022-06-17 08:44:52.832542] lpcfg_do_global_parameter: WARNING: The "null passwords" option is deprecated
  897. [2022-06-17 08:44:52.834251] doing parameter passdb backend = smbpasswd
  898. [2022-06-17 08:44:52.835755] doing parameter socket options = IPTOS_LOWDELAY TCP_NODELAY
  899. [2022-06-17 08:44:52.837257] doing parameter load printers = No
  900. [2022-06-17 08:44:52.838752] doing parameter printcap name = /dev/null
  901. [2022-06-17 08:44:52.840244] doing parameter disable spoolss = yes
  902. [2022-06-17 08:44:52.841735] doing parameter printing = bsd
  903. [2022-06-17 08:44:52.843269] doing parameter mdns name = mdns
  904. [2022-06-17 08:44:52.845185] doing parameter veto files = /Thumbs.db/.DS_Store/._.DS_Store/.apdisk/
  905. [2022-06-17 08:44:52.846833] doing parameter delete veto files = yes
  906. [2022-06-17 08:44:52.848487] pm_process() returned Yes
  907. [2022-06-17 08:44:52.850122] lp_servicenumber: couldn't find homes
  908. [2022-06-17 08:44:52.851761] messaging_dgm_ref: messaging_dgm_init returned No error information
  909. [2022-06-17 08:44:52.853460] messaging_dgm_ref: unique = 18173276210601493798
  910. [2022-06-17 08:44:52.855110] Registering messaging pointer for type 2 - private_data=0
  911. [2022-06-17 08:44:52.856762] Registered MSG_REQ_POOL_USAGE
  912. [2022-06-17 08:44:52.858396] Registering messaging pointer for type 11 - private_data=0
  913. [2022-06-17 08:44:52.860038] Registering messaging pointer for type 12 - private_data=0
  914. [2022-06-17 08:44:52.861685] Registered MSG_REQ_DMALLOC_MARK and LOG_CHANGED
  915. [2022-06-17 08:44:52.863423] Registering messaging pointer for type 1 - private_data=0
  916. [2022-06-17 08:44:52.865095] Registering messaging pointer for type 5 - private_data=0
  917. [2022-06-17 08:44:52.866745] Registering messaging pointer for type 51 - private_data=0
  918. [2022-06-17 08:44:52.868382] messaging_init_internal: my id: 9557
  919. [2022-06-17 08:44:52.870021] global_dcesrv_context: Initializing DCE/RPC server context
  920. [2022-06-17 08:44:52.871642] INFO: Current debug levels:
  921. [2022-06-17 08:44:52.873326] all: 10
  922. [2022-06-17 08:44:52.874956] tdb: 10
  923. [2022-06-17 08:44:52.876592] printdrivers: 10
  924. [2022-06-17 08:44:52.878089] lanman: 10
  925. [2022-06-17 08:44:52.879826] smb: 10
  926. [2022-06-17 08:44:52.881430] rpc_parse: 10
  927. [2022-06-17 08:44:52.883091] rpc_srv: 10
  928. [2022-06-17 08:44:52.884723] rpc_cli: 10
  929. [2022-06-17 08:44:52.886346] passdb: 10
  930. [2022-06-17 08:44:52.887952] sam: 10
  931. [2022-06-17 08:44:52.889559] auth: 10
  932. [2022-06-17 08:44:52.891174] winbind: 10
  933. [2022-06-17 08:44:52.892784] vfs: 10
  934. [2022-06-17 08:44:52.894450] idmap: 10
  935. [2022-06-17 08:44:52.896064] quota: 10
  936. [2022-06-17 08:44:52.897670] acls: 10
  937. [2022-06-17 08:44:52.899270] locking: 10
  938. [2022-06-17 08:44:52.900886] msdfs: 10
  939. [2022-06-17 08:44:52.902482] dmapi: 10
  940. [2022-06-17 08:44:52.904158] registry: 10
  941. [2022-06-17 08:44:52.905772] scavenger: 10
  942. [2022-06-17 08:44:52.907381] dns: 10
  943. [2022-06-17 08:44:52.908992] ldb: 10
  944. [2022-06-17 08:44:52.910587] tevent: 10
  945. [2022-06-17 08:44:52.912210] auth_audit: 10
  946. [2022-06-17 08:44:52.913863] auth_json_audit: 10
  947. [2022-06-17 08:44:52.915485] kerberos: 10
  948. [2022-06-17 08:44:52.917103] drs_repl: 10
  949. [2022-06-17 08:44:52.918722] smb2: 10
  950. [2022-06-17 08:44:52.920333] smb2_credits: 10
  951. [2022-06-17 08:44:52.921949] dsdb_audit: 10
  952. [2022-06-17 08:44:52.923614] dsdb_json_audit: 10
  953. [2022-06-17 08:44:52.925244] dsdb_password_audit: 10
  954. [2022-06-17 08:44:52.926856] dsdb_password_json_audit: 10
  955. [2022-06-17 08:44:52.928487] dsdb_transaction_audit: 10
  956. [2022-06-17 08:44:52.930105] dsdb_transaction_json_audit: 10
  957. [2022-06-17 08:44:52.931732] dsdb_group_audit: 10
  958. [2022-06-17 08:44:52.933395] dsdb_group_json_audit: 10
  959. [2022-06-17 08:44:52.935033] lp_load_ex: refreshing parameters
  960. [2022-06-17 08:44:52.936669] Freeing parametrics:
  961. [2022-06-17 08:44:52.938278] Initialising global parameters
  962. [2022-06-17 08:44:52.939902] rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384)
  963. [2022-06-17 08:44:52.941547] INFO: Current debug levels:
  964. [2022-06-17 08:44:52.943223] all: 10
  965. [2022-06-17 08:44:52.944742] tdb: 10
  966. [2022-06-17 08:44:52.946226] printdrivers: 10
  967. [2022-06-17 08:44:52.947697] lanman: 10
  968. [2022-06-17 08:44:52.949165] smb: 10
  969. [2022-06-17 08:44:52.950622] rpc_parse: 10
  970. [2022-06-17 08:44:52.952409] rpc_srv: 10
  971. [2022-06-17 08:44:52.954120] rpc_cli: 10
  972. [2022-06-17 08:44:52.955727] passdb: 10
  973. [2022-06-17 08:44:52.957341] sam: 10
  974. [2022-06-17 08:44:52.958955] auth: 10
  975. [2022-06-17 08:44:52.960451] winbind: 10
  976. [2022-06-17 08:44:52.961916] vfs: 10
  977. [2022-06-17 08:44:52.963427] idmap: 10
  978. [2022-06-17 08:44:52.965167] quota: 10
  979. [2022-06-17 08:44:52.966776] acls: 10
  980. [2022-06-17 08:44:52.968406] locking: 10
  981. [2022-06-17 08:44:52.970031] msdfs: 10
  982. [2022-06-17 08:44:52.971645] dmapi: 10
  983. [2022-06-17 08:44:52.973320] registry: 10
  984. [2022-06-17 08:44:52.974942] scavenger: 10
  985. [2022-06-17 08:44:52.976555] dns: 10
  986. [2022-06-17 08:44:52.978041] ldb: 10
  987. [2022-06-17 08:44:52.979782] tevent: 10
  988. [2022-06-17 08:44:52.981402] auth_audit: 10
  989. [2022-06-17 08:44:52.983075] auth_json_audit: 10
  990. [2022-06-17 08:44:52.984710] kerberos: 10
  991. [2022-06-17 08:44:52.986330] drs_repl: 10
  992. [2022-06-17 08:44:52.988155] smb2: 10
  993. [2022-06-17 08:44:52.989802] smb2_credits: 10
  994. [2022-06-17 08:44:52.991303] dsdb_audit: 10
  995. [2022-06-17 08:44:52.993096] dsdb_json_audit: 10
  996. [2022-06-17 08:44:52.994738] dsdb_password_audit: 10
  997. [2022-06-17 08:44:52.996367] dsdb_password_json_audit: 10
  998. [2022-06-17 08:44:52.997994] dsdb_transaction_audit: 10
  999. [2022-06-17 08:44:52.999621] dsdb_transaction_json_audit: 10
  1000. [2022-06-17 08:44:53.001250] dsdb_group_audit: 10
  1001. [2022-06-17 08:44:53.002898] dsdb_group_json_audit: 10
  1002. [2022-06-17 08:44:53.004545] Processing section "[global]"
  1003. [2022-06-17 08:44:53.006197] doing parameter netbios name = zalupa
  1004. [2022-06-17 08:44:53.007835] doing parameter interfaces = br-lan
  1005. [2022-06-17 08:44:53.009471] doing parameter server string = SASAm
  1006. [2022-06-17 08:44:53.011098] doing parameter unix charset = UTF-8
  1007. [2022-06-17 08:44:53.012732] doing parameter workgroup = WORKGROUP
  1008. [2022-06-17 08:44:53.014441] doing parameter log level = 2
  1009. [2022-06-17 08:44:53.016100] doing parameter bind interfaces only = yes
  1010. [2022-06-17 08:44:53.017742] doing parameter deadtime = 15
  1011. [2022-06-17 08:44:53.019363] doing parameter enable core files = no
  1012. [2022-06-17 08:44:53.020986] doing parameter security = user
  1013. [2022-06-17 08:44:53.022630] doing parameter debug timestamp = yes
  1014. [2022-06-17 08:44:53.024338] doing parameter invalid users = root
  1015. [2022-06-17 08:44:53.025989] doing parameter map to guest = Bad User
  1016. [2022-06-17 08:44:53.027622] doing parameter null passwords = yes
  1017. [2022-06-17 08:44:53.029263] lpcfg_do_global_parameter: WARNING: The "null passwords" option is deprecated
  1018. [2022-06-17 08:44:53.030924] doing parameter passdb backend = smbpasswd
  1019. [2022-06-17 08:44:53.032561] doing parameter socket options = IPTOS_LOWDELAY TCP_NODELAY
  1020. [2022-06-17 08:44:53.034278] doing parameter load printers = No
  1021. [2022-06-17 08:44:53.035919] doing parameter printcap name = /dev/null
  1022. [2022-06-17 08:44:53.037435] doing parameter disable spoolss = yes
  1023. [2022-06-17 08:44:53.038923] doing parameter printing = bsd
  1024. [2022-06-17 08:44:53.040709] doing parameter mdns name = mdns
  1025. [2022-06-17 08:44:53.042342] doing parameter veto files = /Thumbs.db/.DS_Store/._.DS_Store/.apdisk/
  1026. [2022-06-17 08:44:53.044070] doing parameter delete veto files = yes
  1027. [2022-06-17 08:44:53.053519] Processing section "[shr]"
  1028. [2022-06-17 08:44:53.055312] add_a_service: Creating snum = 0 for shr
  1029. [2022-06-17 08:44:53.057653] hash_a_service: creating servicehash
  1030. [2022-06-17 08:44:53.060039] hash_a_service: hashing index 0 for service name shr
  1031. [2022-06-17 08:44:53.061842] doing parameter path = /mnt/share/
  1032. [2022-06-17 08:44:53.066851] doing parameter create mask = 0666
  1033. [2022-06-17 08:44:53.072734] doing parameter directory mask = 0777
  1034. [2022-06-17 08:44:53.074617] doing parameter read only = no
  1035. [2022-06-17 08:44:53.076312] doing parameter guest ok = yes
  1036. [2022-06-17 08:44:53.079343] doing parameter vfs objects = io_uring
  1037. [2022-06-17 08:44:53.081654] pm_process() returned Yes
  1038. [2022-06-17 08:44:53.083306] lp_servicenumber: couldn't find homes
  1039. [2022-06-17 08:44:53.085162] add_a_service: Creating snum = 1 for IPC$
  1040. [2022-06-17 08:44:53.086828] hash_a_service: hashing index 1 for service name IPC$
  1041. [2022-06-17 08:44:53.088486] adding IPC service
  1042. [2022-06-17 08:44:53.090106] INFO: Current debug levels:
  1043. [2022-06-17 08:44:53.091722] all: 10
  1044. [2022-06-17 08:44:53.093400] tdb: 10
  1045. [2022-06-17 08:44:53.095026] printdrivers: 10
  1046. [2022-06-17 08:44:53.096652] lanman: 10
  1047. [2022-06-17 08:44:53.098281] smb: 10
  1048. [2022-06-17 08:44:53.099885] rpc_parse: 10
  1049. [2022-06-17 08:44:53.101482] rpc_srv: 10
  1050. [2022-06-17 08:44:53.103136] rpc_cli: 10
  1051. [2022-06-17 08:44:53.104770] passdb: 10
  1052. [2022-06-17 08:44:53.106384] sam: 10
  1053. [2022-06-17 08:44:53.107986] auth: 10
  1054. [2022-06-17 08:44:53.109594] winbind: 10
  1055. [2022-06-17 08:44:53.111223] vfs: 10
  1056. [2022-06-17 08:44:53.112836] idmap: 10
  1057. [2022-06-17 08:44:53.114502] quota: 10
  1058. [2022-06-17 08:44:53.116104] acls: 10
  1059. [2022-06-17 08:44:53.117707] locking: 10
  1060. [2022-06-17 08:44:53.119323] msdfs: 10
  1061. [2022-06-17 08:44:53.120932] dmapi: 10
  1062. [2022-06-17 08:44:53.122541] registry: 10
  1063. [2022-06-17 08:44:53.124245] scavenger: 10
  1064. [2022-06-17 08:44:53.125741] dns: 10
  1065. [2022-06-17 08:44:53.127339] ldb: 10
  1066. [2022-06-17 08:44:53.129034] tevent: 10
  1067. [2022-06-17 08:44:53.130653] auth_audit: 10
  1068. [2022-06-17 08:44:53.132285] auth_json_audit: 10
  1069. [2022-06-17 08:44:53.133967] kerberos: 10
  1070. [2022-06-17 08:44:53.135594] drs_repl: 10
  1071. [2022-06-17 08:44:53.137209] smb2: 10
  1072. [2022-06-17 08:44:53.138830] smb2_credits: 10
  1073. [2022-06-17 08:44:53.140441] dsdb_audit: 10
  1074. [2022-06-17 08:44:53.142024] dsdb_json_audit: 10
  1075. [2022-06-17 08:44:53.143694] dsdb_password_audit: 10
  1076. [2022-06-17 08:44:53.145333] dsdb_password_json_audit: 10
  1077. [2022-06-17 08:44:53.146983] dsdb_transaction_audit: 10
  1078. [2022-06-17 08:44:53.148619] dsdb_transaction_json_audit: 10
  1079. [2022-06-17 08:44:53.150247] dsdb_group_audit: 10
  1080. [2022-06-17 08:44:53.151861] dsdb_group_json_audit: 10
  1081. [2022-06-17 08:44:53.153573] lp_file_list_changed()
  1082. [2022-06-17 08:44:53.155214] file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Fri Jun 17 08:38:04 2022
  1083. [2022-06-17 08:44:53.156884]
  1084. [2022-06-17 08:44:53.158508] INFO: Current debug levels:
  1085. [2022-06-17 08:44:53.160125] all: 10
  1086. [2022-06-17 08:44:53.161730] tdb: 10
  1087. [2022-06-17 08:44:53.163379] printdrivers: 10
  1088. [2022-06-17 08:44:53.165012] lanman: 10
  1089. [2022-06-17 08:44:53.166633] smb: 10
  1090. [2022-06-17 08:44:53.168257] rpc_parse: 10
  1091. [2022-06-17 08:44:53.169875] rpc_srv: 10
  1092. [2022-06-17 08:44:53.171492] rpc_cli: 10
  1093. [2022-06-17 08:44:53.173154] passdb: 10
  1094. [2022-06-17 08:44:53.174789] sam: 10
  1095. [2022-06-17 08:44:53.176400] auth: 10
  1096. [2022-06-17 08:44:53.177886] winbind: 10
  1097. [2022-06-17 08:44:53.179632] vfs: 10
  1098. [2022-06-17 08:44:53.181269] idmap: 10
  1099. [2022-06-17 08:44:53.182925] quota: 10
  1100. [2022-06-17 08:44:53.184558] acls: 10
  1101. [2022-06-17 08:44:53.186163] locking: 10
  1102. [2022-06-17 08:44:53.187755] msdfs: 10
  1103. [2022-06-17 08:44:53.189366] dmapi: 10
  1104. [2022-06-17 08:44:53.190981] registry: 10
  1105. [2022-06-17 08:44:53.192598] scavenger: 10
  1106. [2022-06-17 08:44:53.194313] dns: 10
  1107. [2022-06-17 08:44:53.195949] ldb: 10
  1108. [2022-06-17 08:44:53.197553] tevent: 10
  1109. [2022-06-17 08:44:53.199173] auth_audit: 10
  1110. [2022-06-17 08:44:53.200788] auth_json_audit: 10
  1111. [2022-06-17 08:44:53.202405] kerberos: 10
  1112. [2022-06-17 08:44:53.204117] drs_repl: 10
  1113. [2022-06-17 08:44:53.205741] smb2: 10
  1114. [2022-06-17 08:44:53.207350] smb2_credits: 10
  1115. [2022-06-17 08:44:53.208982] dsdb_audit: 10
  1116. [2022-06-17 08:44:53.210595] dsdb_json_audit: 10
  1117. [2022-06-17 08:44:53.212197] dsdb_password_audit: 10
  1118. [2022-06-17 08:44:53.213849] dsdb_password_json_audit: 10
  1119. [2022-06-17 08:44:53.215505] dsdb_transaction_audit: 10
  1120. [2022-06-17 08:44:53.217151] dsdb_transaction_json_audit: 10
  1121. [2022-06-17 08:44:53.218784] dsdb_group_audit: 10
  1122. [2022-06-17 08:44:53.220399] dsdb_group_json_audit: 10
  1123. [2022-06-17 08:44:53.222019] added interface br-lan ip=fd3f:ea31:1c91::1 bcast= netmask=ffff:ffff:ffff:fff0::
  1124. [2022-06-17 08:44:53.223737] added interface br-lan ip=192.168.1.250 bcast=192.168.255.255 netmask=255.255.0.0
  1125. [2022-06-17 08:44:53.225415] loaded services
  1126. [2022-06-17 08:44:53.227033] Netbios name list:-
  1127. [2022-06-17 08:44:53.228650] my_netbios_names[0]="ZALUPA"
  1128. [2022-06-17 08:44:53.230288] INFO: Profiling support unavailable in this build.
  1129. [2022-06-17 08:44:53.231933] Standard input is not a socket, assuming -D option
  1130. [2022-06-17 08:44:53.233630] Becoming a daemon.
  1131. [2022-06-17 08:44:53.235138] Process with PID=9526 does not exist.
  1132. [2022-06-17 08:44:53.236628] msg_dgm_ref_destructor: refs=0
  1133. [2022-06-17 08:44:53.238116] messaging_dgm_ref: messaging_dgm_init returned No error information
  1134. [2022-06-17 08:44:53.239630] messaging_dgm_ref: unique = 15217904554109505722
  1135. [2022-06-17 08:44:53.241134] Registered MSG_REQ_POOL_USAGE
  1136. [2022-06-17 08:44:53.242616] Attempting to register passdb backend smbpasswd
  1137. [2022-06-17 08:44:53.244185] Successfully added passdb backend 'smbpasswd'
  1138. [2022-06-17 08:44:53.245674] Attempting to register passdb backend tdbsam
  1139. [2022-06-17 08:44:53.247157] Successfully added passdb backend 'tdbsam'
  1140. [2022-06-17 08:44:53.248821] Attempting to find a passdb backend to match smbpasswd (smbpasswd)
  1141. [2022-06-17 08:44:53.250359] Found pdb backend smbpasswd
  1142. [2022-06-17 08:44:53.251841] pdb backend smbpasswd has a valid init
  1143. [2022-06-17 08:44:53.253382] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_version_global.tdb
  1144. [2022-06-17 08:44:53.254902] lock order: 1:/var/lock/smbXsrv_version_global.tdb 2:<none> 3:<none> 4:<none>
  1145. [2022-06-17 08:44:53.256412] db_tdb_log_key: Locking key 736D62587372765F7665
  1146. [2022-06-17 08:44:53.257920] db_tdb_fetch_locked_internal: Allocated locked data 0xb56e5dc0
  1147. [2022-06-17 08:44:53.259427] db_tdb_log_key: Unlocking key 736D62587372765F7665
  1148. [2022-06-17 08:44:53.260920] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_version_global.tdb
  1149. [2022-06-17 08:44:53.262434] smbXsrv_version_global_init
  1150. [2022-06-17 08:44:53.264190] &global_blob: struct smbXsrv_version_globalB
  1151. [2022-06-17 08:44:53.265729] version : SMBXSRV_VERSION_0 (0)
  1152. [2022-06-17 08:44:53.267228] seqnum : 0x00000001 (1)
  1153. [2022-06-17 08:44:53.268726] info : union smbXsrv_version_globalU(case 0)
  1154. [2022-06-17 08:44:53.270225] info0 : *
  1155. [2022-06-17 08:44:53.271714] info0: struct smbXsrv_version_global0
  1156. [2022-06-17 08:44:53.273267] db_rec : NULL
  1157. [2022-06-17 08:44:53.274776] num_nodes : 0x00000001 (1)
  1158. [2022-06-17 08:44:53.276279] nodes: ARRAY(1)
  1159. [2022-06-17 08:44:53.277766] nodes: struct smbXsrv_version_node0
  1160. [2022-06-17 08:44:53.279485] server_id: struct server_id
  1161. [2022-06-17 08:44:53.280997] pid : 0x0000000000002555 (9557)
  1162. [2022-06-17 08:44:53.282507] task_id : 0x00000000 (0)
  1163. [2022-06-17 08:44:53.284096] vnn : 0xffffffff (4294967295)
  1164. [2022-06-17 08:44:53.293004] unique_id : 0xd330db90657f10ba (-3228839519600045894)
  1165. [2022-06-17 08:44:53.295015] min_version : SMBXSRV_VERSION_0 (0)
  1166. [2022-06-17 08:44:53.296604] max_version : SMBXSRV_VERSION_0 (0)
  1167. [2022-06-17 08:44:53.298131] current_version : SMBXSRV_VERSION_0 (0)
  1168. [2022-06-17 08:44:53.299638] pid_to_procid: messaging_dgm_get_unique failed: No such file or directory
  1169. [2022-06-17 08:44:53.304967] msg_dgm_ref_destructor: refs=0
  1170. [2022-06-17 08:44:53.306603] messaging_dgm_ref: messaging_dgm_init returned No error information
  1171. [2022-06-17 08:44:53.308711] messaging_dgm_ref: unique = 18289446604332582717
  1172. [2022-06-17 08:44:53.310436] Registered MSG_REQ_POOL_USAGE
  1173. [2022-06-17 08:44:53.312098] Attempting to find a passdb backend to match smbpasswd (smbpasswd)
  1174. [2022-06-17 08:44:53.313819] Found pdb backend smbpasswd
  1175. [2022-06-17 08:44:53.315476] pdb backend smbpasswd has a valid init
  1176. [2022-06-17 08:44:53.317115] INFO: Current debug levels:
  1177. [2022-06-17 08:44:53.318721] all: 10
  1178. [2022-06-17 08:44:53.320328] tdb: 10
  1179. [2022-06-17 08:44:53.321949] printdrivers: 10
  1180. [2022-06-17 08:44:53.323635] lanman: 10
  1181. [2022-06-17 08:44:53.325246] smb: 10
  1182. [2022-06-17 08:44:53.326846] rpc_parse: 10
  1183. [2022-06-17 08:44:53.328454] rpc_srv: 10
  1184. [2022-06-17 08:44:53.330064] rpc_cli: 10
  1185. [2022-06-17 08:44:53.331679] passdb: 10
  1186. [2022-06-17 08:44:53.333341] sam: 10
  1187. [2022-06-17 08:44:53.334965] auth: 10
  1188. [2022-06-17 08:44:53.336578] winbind: 10
  1189. [2022-06-17 08:44:53.338200] vfs: 10
  1190. [2022-06-17 08:44:53.339799] idmap: 10
  1191. [2022-06-17 08:44:53.341290] quota: 10
  1192. [2022-06-17 08:44:53.342758] acls: 10
  1193. [2022-06-17 08:44:53.344289] locking: 10
  1194. [2022-06-17 08:44:53.345768] msdfs: 10
  1195. [2022-06-17 08:44:53.347238] dmapi: 10
  1196. [2022-06-17 08:44:53.348689] registry: 10
  1197. [2022-06-17 08:44:53.350146] scavenger: 10
  1198. [2022-06-17 08:44:53.351607] dns: 10
  1199. [2022-06-17 08:44:53.353114] ldb: 10
  1200. [2022-06-17 08:44:53.354739] tevent: 10
  1201. [2022-06-17 08:44:53.356259] auth_audit: 10
  1202. [2022-06-17 08:44:53.357737] auth_json_audit: 10
  1203. [2022-06-17 08:44:53.359631] kerberos: 10
  1204. [2022-06-17 08:44:53.361118] drs_repl: 10
  1205. [2022-06-17 08:44:53.362587] smb2: 10
  1206. [2022-06-17 08:44:53.364131] smb2_credits: 10
  1207. [2022-06-17 08:44:53.365615] dsdb_audit: 10
  1208. [2022-06-17 08:44:53.367083] dsdb_json_audit: 10
  1209. [2022-06-17 08:44:53.368551] dsdb_password_audit: 10
  1210. [2022-06-17 08:44:53.370328] dsdb_password_json_audit: 10
  1211. [2022-06-17 08:44:53.371980] dsdb_transaction_audit: 10
  1212. [2022-06-17 08:44:53.373671] dsdb_transaction_json_audit: 10
  1213. [2022-06-17 08:44:53.375318] dsdb_group_audit: 10
  1214. [2022-06-17 08:44:53.376931] dsdb_group_json_audit: 10
  1215. [2022-06-17 08:44:53.378552] Registering messaging pointer for type 794 - private_data=0xb6840d70
  1216. [2022-06-17 08:44:53.380207] Registering messaging pointer for type 795 - private_data=0xb6840d70
  1217. [2022-06-17 08:44:53.381852] Registering messaging pointer for type 796 - private_data=0xb6840d70
  1218. [2022-06-17 08:44:53.383558] messaging_dgm_send: Sending message to 9557
  1219. [2022-06-17 08:44:53.385203] msg_dgm_ref_destructor: refs=0
  1220. [2022-06-17 08:44:53.386835] messaging_dgm_ref: messaging_dgm_init returned No error information
  1221. [2022-06-17 08:44:53.388485] messaging_dgm_ref: unique = 1643749833637346486
  1222. [2022-06-17 08:44:53.390136] Registered MSG_REQ_POOL_USAGE
  1223. [2022-06-17 08:44:53.391780] Attempting to find a passdb backend to match smbpasswd (smbpasswd)
  1224. [2022-06-17 08:44:53.393481] Found pdb backend smbpasswd
  1225. [2022-06-17 08:44:53.395101] pdb backend smbpasswd has a valid init
  1226. [2022-06-17 08:44:53.396724] Registering messaging pointer for type 13 - private_data=0xb6840c90
  1227. [2022-06-17 08:44:53.398389] Registering messaging pointer for type 788 - private_data=0xb6840c90
  1228. [2022-06-17 08:44:53.400032] cleanupd_init: Started cleanupd pid=9561
  1229. [2022-06-17 08:44:53.401671] Registering messaging pointer for type 789 - private_data=0xb5c53d90
  1230. [2022-06-17 08:44:53.403363] regdb_init: registry db openend. refcount reset (1)
  1231. [2022-06-17 08:44:53.405031] reghook_cache_init: new tree with default ops 0xb6ab32e8 for key []
  1232. [2022-06-17 08:44:53.406689] regdb_fetch_values: Looking for values of key [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports]
  1233. [2022-06-17 08:44:53.408359] regdb_unpack_values: value[0]: name[Samba Printer Port] len[2]
  1234. [2022-06-17 08:44:53.409992] regdb_fetch_values: Looking for values of key [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers]
  1235. [2022-06-17 08:44:53.411553] regdb_unpack_values: value[0]: name[DefaultSpoolDirectory] len[70]
  1236. [2022-06-17 08:44:53.413334] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  1237. [2022-06-17 08:44:53.415037] regdb_unpack_values: value[0]: name[DisplayName] len[20]
  1238. [2022-06-17 08:44:53.416691] regdb_unpack_values: value[1]: name[ErrorControl] len[4]
  1239. [2022-06-17 08:44:53.418338] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  1240. [2022-06-17 08:44:53.420000] regdb_unpack_values: value[0]: name[DisplayName] len[20]
  1241. [2022-06-17 08:44:53.421629] regdb_unpack_values: value[1]: name[ErrorControl] len[4]
  1242. [2022-06-17 08:44:53.423313] reghook_cache_add: Adding ops 0xb6f0d434 for key [\HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers]
  1243. [2022-06-17 08:44:53.425001] pathtree_add: Enter
  1244. [2022-06-17 08:44:53.426641] pathtree_add: Successfully added node [HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers] to tree
  1245. [2022-06-17 08:44:53.428324] pathtree_add: Exit
  1246. [2022-06-17 08:44:53.429948] reghook_cache_add: Adding ops 0xb6ab32e8 for key [\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers]
  1247. [2022-06-17 08:44:53.431629] pathtree_add: Enter
  1248. [2022-06-17 08:44:53.433290] pathtree_add: Successfully added node [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers] to tree
  1249. [2022-06-17 08:44:53.434978] pathtree_add: Exit
  1250. [2022-06-17 08:44:53.436594] reghook_cache_add: Adding ops 0xb6ab32e8 for key [\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports]
  1251. [2022-06-17 08:44:53.438267] pathtree_add: Enter
  1252. [2022-06-17 08:44:53.439903] pathtree_add: Successfully added node [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports] to tree
  1253. [2022-06-17 08:44:53.441581] pathtree_add: Exit
  1254. [2022-06-17 08:44:53.443255] reghook_cache_add: Adding ops 0xb6ab32e8 for key [\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\PackageInstallation]
  1255. [2022-06-17 08:44:53.444959] pathtree_add: Enter
  1256. [2022-06-17 08:44:53.446584] pathtree_add: Successfully added node [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\PackageInstallation] to tree
  1257. [2022-06-17 08:44:53.448257] pathtree_add: Exit
  1258. [2022-06-17 08:44:53.449877] reghook_cache_add: Adding ops 0xb6f0d460 for key [\HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares]
  1259. [2022-06-17 08:44:53.451564] pathtree_add: Enter
  1260. [2022-06-17 08:44:53.453232] pathtree_add: Successfully added node [HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares] to tree
  1261. [2022-06-17 08:44:53.454933] pathtree_add: Exit
  1262. [2022-06-17 08:44:53.456549] reghook_cache_add: Adding ops 0xb6ab320c for key [\HKLM\SOFTWARE\Samba\smbconf]
  1263. [2022-06-17 08:44:53.458190] pathtree_add: Enter
  1264. [2022-06-17 08:44:53.459803] pathtree_add: Successfully added node [HKLM\SOFTWARE\Samba\smbconf] to tree
  1265. [2022-06-17 08:44:53.461330] pathtree_add: Exit
  1266. [2022-06-17 08:44:53.463130] reghook_cache_add: Adding ops 0xb6f0d48c for key [\HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters]
  1267. [2022-06-17 08:44:53.464826] pathtree_add: Enter
  1268. [2022-06-17 08:44:53.466451] pathtree_add: Successfully added node [HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters] to tree
  1269. [2022-06-17 08:44:53.468122] pathtree_add: Exit
  1270. [2022-06-17 08:44:53.469737] reghook_cache_add: Adding ops 0xb6f0d4b8 for key [\HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions]
  1271. [2022-06-17 08:44:53.471398] pathtree_add: Enter
  1272. [2022-06-17 08:44:53.473053] pathtree_add: Successfully added node [HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions] to tree
  1273. [2022-06-17 08:44:53.474734] pathtree_add: Exit
  1274. [2022-06-17 08:44:53.476364] reghook_cache_add: Adding ops 0xb6f0d4e4 for key [\HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
  1275. [2022-06-17 08:44:53.478032] pathtree_add: Enter
  1276. [2022-06-17 08:44:53.479651] pathtree_add: Successfully added node [HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] to tree
  1277. [2022-06-17 08:44:53.481305] pathtree_add: Exit
  1278. [2022-06-17 08:44:53.482979] reghook_cache_add: Adding ops 0xb6f0d510 for key [\HKPT]
  1279. [2022-06-17 08:44:53.484643] pathtree_add: Enter
  1280. [2022-06-17 08:44:53.486270] pathtree_add: Successfully added node [HKPT] to tree
  1281. [2022-06-17 08:44:53.487932] pathtree_add: Exit
  1282. [2022-06-17 08:44:53.489544] reghook_cache_add: Adding ops 0xb6f0d53c for key [\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion]
  1283. [2022-06-17 08:44:53.491213] pathtree_add: Enter
  1284. [2022-06-17 08:44:53.492832] pathtree_add: Successfully added node [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion] to tree
  1285. [2022-06-17 08:44:53.494556] pathtree_add: Exit
  1286. [2022-06-17 08:44:53.496185] reghook_cache_add: Adding ops 0xb6f0d568 for key [\HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib]
  1287. [2022-06-17 08:44:53.497863] pathtree_add: Enter
  1288. [2022-06-17 08:44:53.499489] pathtree_add: Successfully added node [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib] to tree
  1289. [2022-06-17 08:44:53.501153] pathtree_add: Exit
  1290. [2022-06-17 08:44:53.502777] regdb_close: decrementing refcount (1->0)
  1291. [2022-06-17 08:44:53.504461] Could not convert SID S-1-5-18 to gid, ignoring it
  1292. [2022-06-17 08:44:53.506088] Security token SIDs (1):
  1293. [2022-06-17 08:44:53.507694] SID[ 0]: S-1-5-18
  1294. [2022-06-17 08:44:53.509297] Privileges (0xFFFFFFFFFFFFFFFF):
  1295. [2022-06-17 08:44:53.510945] Privilege[ 0]: SeMachineAccountPrivilege
  1296. [2022-06-17 08:44:53.512584] Privilege[ 1]: SeTakeOwnershipPrivilege
  1297. [2022-06-17 08:44:53.514305] Privilege[ 2]: SeBackupPrivilege
  1298. [2022-06-17 08:44:53.515941] Privilege[ 3]: SeRestorePrivilege
  1299. [2022-06-17 08:44:53.517572] Privilege[ 4]: SeRemoteShutdownPrivilege
  1300. [2022-06-17 08:44:53.519193] Privilege[ 5]: SePrintOperatorPrivilege
  1301. [2022-06-17 08:44:53.520828] Privilege[ 6]: SeAddUsersPrivilege
  1302. [2022-06-17 08:44:53.522463] Privilege[ 7]: SeDiskOperatorPrivilege
  1303. [2022-06-17 08:44:53.524168] Privilege[ 8]: SeSecurityPrivilege
  1304. [2022-06-17 08:44:53.525801] Privilege[ 9]: SeSystemtimePrivilege
  1305. [2022-06-17 08:44:53.527431] Privilege[ 10]: SeShutdownPrivilege
  1306. [2022-06-17 08:44:53.529053] Privilege[ 11]: SeDebugPrivilege
  1307. [2022-06-17 08:44:53.530677] Privilege[ 12]: SeSystemEnvironmentPrivilege
  1308. [2022-06-17 08:44:53.532308] Privilege[ 13]: SeSystemProfilePrivilege
  1309. [2022-06-17 08:44:53.534024] Privilege[ 14]: SeProfileSingleProcessPrivilege
  1310. [2022-06-17 08:44:53.535682] Privilege[ 15]: SeIncreaseBasePriorityPrivilege
  1311. [2022-06-17 08:44:53.537327] Privilege[ 16]: SeLoadDriverPrivilege
  1312. [2022-06-17 08:44:53.538841] Privilege[ 17]: SeCreatePagefilePrivilege
  1313. [2022-06-17 08:44:53.540333] Privilege[ 18]: SeIncreaseQuotaPrivilege
  1314. [2022-06-17 08:44:53.541811] Privilege[ 19]: SeChangeNotifyPrivilege
  1315. [2022-06-17 08:44:53.543340] Privilege[ 20]: SeUndockPrivilege
  1316. [2022-06-17 08:44:53.545149] Privilege[ 21]: SeManageVolumePrivilege
  1317. [2022-06-17 08:44:53.547212] Privilege[ 22]: SeImpersonatePrivilege
  1318. [2022-06-17 08:44:53.549601] Privilege[ 23]: SeCreateGlobalPrivilege
  1319. [2022-06-17 08:44:53.552193] Privilege[ 24]: SeEnableDelegationPrivilege
  1320. [2022-06-17 08:44:53.554216] Rights (0x 0):
  1321. [2022-06-17 08:44:53.555896] UNIX token of user 0
  1322. [2022-06-17 08:44:53.557531] Primary group is 0 and contains 1 supplementary groups
  1323. [2022-06-17 08:44:53.559193] Group[ 0]: 0
  1324. [2022-06-17 08:44:53.560816] Finding user nobody
  1325. [2022-06-17 08:44:53.562440] Trying _Get_Pwnam(), username as lowercase is nobody
  1326. [2022-06-17 08:44:53.564172] Get_Pwnam_internals did find user [nobody]!
  1327. [2022-06-17 08:44:53.566158] Finding user nobody
  1328. [2022-06-17 08:44:53.567805] Trying _Get_Pwnam(), username as lowercase is nobody
  1329. [2022-06-17 08:44:53.569963] Get_Pwnam_internals did find user [nobody]!
  1330. [2022-06-17 08:44:53.572019] Create local NT token for nobody
  1331. [2022-06-17 08:44:53.573747] Finding user nobody
  1332. [2022-06-17 08:44:53.575404] Trying _Get_Pwnam(), username as lowercase is nobody
  1333. [2022-06-17 08:44:53.577069] Get_Pwnam_internals did find user [nobody]!
  1334. [2022-06-17 08:44:53.578952] sys_getgrouplist: user [nobody]
  1335. [2022-06-17 08:44:53.580821] Opening cache file at /var/lock/gencache.tdb
  1336. [2022-06-17 08:44:53.582485] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1337. [2022-06-17 08:44:53.584229] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1338. [2022-06-17 08:44:53.585880] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1339. [2022-06-17 08:44:53.587543] Security token: (NULL)
  1340. [2022-06-17 08:44:53.589184] UNIX token of user 0
  1341. [2022-06-17 08:44:53.590806] Primary group is 0 and contains 0 supplementary groups
  1342. [2022-06-17 08:44:53.592452] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1343. [2022-06-17 08:44:53.594173] xid_to_sid: GID 65534 -> S-1-22-2-65534 fallback
  1344. [2022-06-17 08:44:53.595823] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1345. [2022-06-17 08:44:53.597455] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1346. [2022-06-17 08:44:53.599088] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1347. [2022-06-17 08:44:53.600727] Security token: (NULL)
  1348. [2022-06-17 08:44:53.612702] UNIX token of user 0
  1349. [2022-06-17 08:44:53.614473] Primary group is 0 and contains 0 supplementary groups
  1350. [2022-06-17 08:44:53.616255] Failed to fetch domain sid for WORKGROUP
  1351. [2022-06-17 08:44:53.617788] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1352. [2022-06-17 08:44:53.619281] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1353. [2022-06-17 08:44:53.620770] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1354. [2022-06-17 08:44:53.622576] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1355. [2022-06-17 08:44:53.624327] Security token: (NULL)
  1356. [2022-06-17 08:44:53.625963] UNIX token of user 0
  1357. [2022-06-17 08:44:53.627457] Primary group is 0 and contains 0 supplementary groups
  1358. [2022-06-17 08:44:53.629064] Could not find map for sid S-1-5-32-544
  1359. [2022-06-17 08:44:53.630701] create_builtin_administrators: Failed to create Administrators
  1360. [2022-06-17 08:44:53.632352] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1361. [2022-06-17 08:44:53.634077] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1362. [2022-06-17 08:44:53.635730] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1363. [2022-06-17 08:44:53.637350] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1364. [2022-06-17 08:44:53.638998] Security token: (NULL)
  1365. [2022-06-17 08:44:53.640613] UNIX token of user 0
  1366. [2022-06-17 08:44:53.642238] Primary group is 0 and contains 0 supplementary groups
  1367. [2022-06-17 08:44:53.643906] Could not find map for sid S-1-5-32-545
  1368. [2022-06-17 08:44:53.645547] create_builtin_users: Failed to create Users
  1369. [2022-06-17 08:44:53.647199] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1370. [2022-06-17 08:44:53.648846] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1371. [2022-06-17 08:44:53.650488] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1372. [2022-06-17 08:44:53.652120] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1373. [2022-06-17 08:44:53.653798] Security token: (NULL)
  1374. [2022-06-17 08:44:53.655429] UNIX token of user 0
  1375. [2022-06-17 08:44:53.657045] Primary group is 0 and contains 0 supplementary groups
  1376. [2022-06-17 08:44:53.658693] Could not find map for sid S-1-5-32-546
  1377. [2022-06-17 08:44:53.660336] create_builtin_guests: Failed to create Guests
  1378. [2022-06-17 08:44:53.661984] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1379. [2022-06-17 08:44:53.663681] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1380. [2022-06-17 08:44:53.665336] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1381. [2022-06-17 08:44:53.666978] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1382. [2022-06-17 08:44:53.668619] Security token: (NULL)
  1383. [2022-06-17 08:44:53.670244] UNIX token of user 0
  1384. [2022-06-17 08:44:53.671871] Primary group is 0 and contains 0 supplementary groups
  1385. [2022-06-17 08:44:53.673567] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1386. [2022-06-17 08:44:53.675219] get_privileges: No privileges assigned to SID [S-1-5-21-3939785350-4027435424-1589595352-501]
  1387. [2022-06-17 08:44:53.677031] get_privileges: No privileges assigned to SID [S-1-5-21-3939785350-4027435424-1589595352-514]
  1388. [2022-06-17 08:44:53.678709] get_privileges: No privileges assigned to SID [S-1-22-2-65534]
  1389. [2022-06-17 08:44:53.680346] get_privileges_for_sids: sid = S-1-1-0
  1390. [2022-06-17 08:44:53.681977] Privilege set: 0x0
  1391. [2022-06-17 08:44:53.683654] get_privileges: No privileges assigned to SID [S-1-5-2]
  1392. [2022-06-17 08:44:53.685320] get_privileges: No privileges assigned to SID [S-1-5-32-546]
  1393. [2022-06-17 08:44:53.686973] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-501]: value=[65534:U]
  1394. [2022-06-17 08:44:53.688637] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-501]: id=[65534], endptr=[:U]
  1395. [2022-06-17 08:44:53.690317] wbcSidsToUnixIds returned WBC_ERR_WINBIND_NOT_AVAILABLE
  1396. [2022-06-17 08:44:53.691961] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1397. [2022-06-17 08:44:53.693649] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1398. [2022-06-17 08:44:53.695307] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1399. [2022-06-17 08:44:53.696954] Security token: (NULL)
  1400. [2022-06-17 08:44:53.698578] UNIX token of user 0
  1401. [2022-06-17 08:44:53.700184] Primary group is 0 and contains 0 supplementary groups
  1402. [2022-06-17 08:44:53.701818] lookup_global_sam_rid: looking up RID 514.
  1403. [2022-06-17 08:44:53.703516] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  1404. [2022-06-17 08:44:53.705169] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  1405. [2022-06-17 08:44:53.706815] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  1406. [2022-06-17 08:44:53.708468] Security token: (NULL)
  1407. [2022-06-17 08:44:53.710091] UNIX token of user 0
  1408. [2022-06-17 08:44:53.711708] Primary group is 0 and contains 0 supplementary groups
  1409. [2022-06-17 08:44:53.713397] smbpasswd_getsampwrid: search by sid: S-1-5-21-3939785350-4027435424-1589595352-514
  1410. [2022-06-17 08:44:53.715058] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  1411. [2022-06-17 08:44:53.716706] getsmbfilepwent: skipping comment or blank line
  1412. [2022-06-17 08:44:53.718356] getsmbfilepwent: LM password for user nobody invalidated
  1413. [2022-06-17 08:44:53.720012] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  1414. [2022-06-17 08:44:53.721657] getsmbfilepwent: LM password for user useruser invalidated
  1415. [2022-06-17 08:44:53.723369] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  1416. [2022-06-17 08:44:53.725027] getsmbfilepwent: end of file reached.
  1417. [2022-06-17 08:44:53.726663] endsmbfilepwent_internal: closed password file.
  1418. [2022-06-17 08:44:53.728301] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  1419. [2022-06-17 08:44:53.729934] Can't find a unix id for an unmapped group
  1420. [2022-06-17 08:44:53.731577] SID S-1-5-21-3939785350-4027435424-1589595352-514 belongs to our domain, but there is no corresponding object in the database.
  1421. [2022-06-17 08:44:53.733325] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1422. [2022-06-17 08:44:53.734978] LEGACY: mapping failed for sid S-1-5-21-3939785350-4027435424-1589595352-514
  1423. [2022-06-17 08:44:53.736637] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1424. [2022-06-17 08:44:53.738269] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1425. [2022-06-17 08:44:53.739894] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1426. [2022-06-17 08:44:53.741526] Security token: (NULL)
  1427. [2022-06-17 08:44:53.743190] UNIX token of user 0
  1428. [2022-06-17 08:44:53.744831] Primary group is 0 and contains 0 supplementary groups
  1429. [2022-06-17 08:44:53.746475] lookup_global_sam_rid: looking up RID 514.
  1430. [2022-06-17 08:44:53.748814] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  1431. [2022-06-17 08:44:53.750455] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  1432. [2022-06-17 08:44:53.752091] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  1433. [2022-06-17 08:44:53.753785] Security token: (NULL)
  1434. [2022-06-17 08:44:53.755418] UNIX token of user 0
  1435. [2022-06-17 08:44:53.757057] Primary group is 0 and contains 0 supplementary groups
  1436. [2022-06-17 08:44:53.758704] smbpasswd_getsampwrid: search by sid: S-1-5-21-3939785350-4027435424-1589595352-514
  1437. [2022-06-17 08:44:53.760354] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  1438. [2022-06-17 08:44:53.761988] getsmbfilepwent: skipping comment or blank line
  1439. [2022-06-17 08:44:53.763684] getsmbfilepwent: LM password for user nobody invalidated
  1440. [2022-06-17 08:44:53.765340] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  1441. [2022-06-17 08:44:53.766991] getsmbfilepwent: LM password for user useruser invalidated
  1442. [2022-06-17 08:44:53.768635] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  1443. [2022-06-17 08:44:53.770290] getsmbfilepwent: end of file reached.
  1444. [2022-06-17 08:44:53.771929] endsmbfilepwent_internal: closed password file.
  1445. [2022-06-17 08:44:53.773610] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  1446. [2022-06-17 08:44:53.775258] Can't find a unix id for an unmapped group
  1447. [2022-06-17 08:44:53.776887] SID S-1-5-21-3939785350-4027435424-1589595352-514 belongs to our domain, but there is no corresponding object in the database.
  1448. [2022-06-17 08:44:53.778558] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1449. [2022-06-17 08:44:53.780193] LEGACY: mapping failed for sid S-1-5-21-3939785350-4027435424-1589595352-514
  1450. [2022-06-17 08:44:53.781851] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1451. [2022-06-17 08:44:53.783545] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1452. [2022-06-17 08:44:53.785192] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1453. [2022-06-17 08:44:53.786841] Security token: (NULL)
  1454. [2022-06-17 08:44:53.788454] UNIX token of user 0
  1455. [2022-06-17 08:44:53.790083] Primary group is 0 and contains 0 supplementary groups
  1456. [2022-06-17 08:44:53.791726] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1457. [2022-06-17 08:44:53.793427] LEGACY: mapping failed for sid S-1-1-0
  1458. [2022-06-17 08:44:53.794957] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1459. [2022-06-17 08:44:53.796459] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1460. [2022-06-17 08:44:53.797952] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1461. [2022-06-17 08:44:53.799595] Security token: (NULL)
  1462. [2022-06-17 08:44:53.801217] UNIX token of user 0
  1463. [2022-06-17 08:44:53.802829] Primary group is 0 and contains 0 supplementary groups
  1464. [2022-06-17 08:44:53.804544] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1465. [2022-06-17 08:44:53.806193] LEGACY: mapping failed for sid S-1-1-0
  1466. [2022-06-17 08:44:53.807826] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1467. [2022-06-17 08:44:53.809457] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1468. [2022-06-17 08:44:53.811084] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1469. [2022-06-17 08:44:53.812721] Security token: (NULL)
  1470. [2022-06-17 08:44:53.814390] UNIX token of user 0
  1471. [2022-06-17 08:44:53.816024] Primary group is 0 and contains 0 supplementary groups
  1472. [2022-06-17 08:44:53.817552] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1473. [2022-06-17 08:44:53.819049] LEGACY: mapping failed for sid S-1-5-2
  1474. [2022-06-17 08:44:53.820534] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1475. [2022-06-17 08:44:53.822023] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1476. [2022-06-17 08:44:53.823642] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1477. [2022-06-17 08:44:53.825155] Security token: (NULL)
  1478. [2022-06-17 08:44:53.826636] UNIX token of user 0
  1479. [2022-06-17 08:44:53.828556] Primary group is 0 and contains 0 supplementary groups
  1480. [2022-06-17 08:44:53.830207] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1481. [2022-06-17 08:44:53.831720] LEGACY: mapping failed for sid S-1-5-2
  1482. [2022-06-17 08:44:53.833408] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1483. [2022-06-17 08:44:53.835182] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1484. [2022-06-17 08:44:53.836823] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1485. [2022-06-17 08:44:53.838431] Security token: (NULL)
  1486. [2022-06-17 08:44:53.839936] UNIX token of user 0
  1487. [2022-06-17 08:44:53.841683] Primary group is 0 and contains 0 supplementary groups
  1488. [2022-06-17 08:44:53.843254] Could not find map for sid S-1-5-32-546
  1489. [2022-06-17 08:44:53.845026] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1490. [2022-06-17 08:44:53.846661] LEGACY: mapping failed for sid S-1-5-32-546
  1491. [2022-06-17 08:44:53.848283] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1492. [2022-06-17 08:44:53.849906] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1493. [2022-06-17 08:44:53.851546] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1494. [2022-06-17 08:44:53.853251] Security token: (NULL)
  1495. [2022-06-17 08:44:53.854907] UNIX token of user 0
  1496. [2022-06-17 08:44:53.856530] Primary group is 0 and contains 0 supplementary groups
  1497. [2022-06-17 08:44:53.858158] Could not find map for sid S-1-5-32-546
  1498. [2022-06-17 08:44:53.859787] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1499. [2022-06-17 08:44:53.861423] LEGACY: mapping failed for sid S-1-5-32-546
  1500. [2022-06-17 08:44:53.863104] Could not convert SID S-1-5-21-3939785350-4027435424-1589595352-514 to gid, ignoring it
  1501. [2022-06-17 08:44:53.864774] Could not convert SID S-1-1-0 to gid, ignoring it
  1502. [2022-06-17 08:44:53.866419] Could not convert SID S-1-5-2 to gid, ignoring it
  1503. [2022-06-17 08:44:53.868067] Could not convert SID S-1-5-32-546 to gid, ignoring it
  1504. [2022-06-17 08:44:53.869716] Security token SIDs (7):
  1505. [2022-06-17 08:44:53.871335] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-501
  1506. [2022-06-17 08:44:53.872997] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-514
  1507. [2022-06-17 08:44:53.874649] SID[ 2]: S-1-22-2-65534
  1508. [2022-06-17 08:44:53.876268] SID[ 3]: S-1-1-0
  1509. [2022-06-17 08:44:53.877888] SID[ 4]: S-1-5-2
  1510. [2022-06-17 08:44:53.879513] SID[ 5]: S-1-5-32-546
  1511. [2022-06-17 08:44:53.881125] SID[ 6]: S-1-22-1-65534
  1512. [2022-06-17 08:44:53.882746] Privileges (0x 0):
  1513. [2022-06-17 08:44:53.884446] Rights (0x 0):
  1514. [2022-06-17 08:44:53.886074] UNIX token of user 65534
  1515. [2022-06-17 08:44:53.887699] Primary group is 65534 and contains 1 supplementary groups
  1516. [2022-06-17 08:44:53.889336] Group[ 0]: 65534
  1517. [2022-06-17 08:44:53.890951] Finding user nobody
  1518. [2022-06-17 08:44:53.892568] Trying _Get_Pwnam(), username as lowercase is nobody
  1519. [2022-06-17 08:44:53.894269] Get_Pwnam_internals did find user [nobody]!
  1520. [2022-06-17 08:44:53.895916] wbcSidsToUnixIds returned WBC_ERR_WINBIND_NOT_AVAILABLE
  1521. [2022-06-17 08:44:53.897555] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1522. [2022-06-17 08:44:53.899179] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1523. [2022-06-17 08:44:53.900823] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1524. [2022-06-17 08:44:53.902456] Security token: (NULL)
  1525. [2022-06-17 08:44:53.904161] UNIX token of user 0
  1526. [2022-06-17 08:44:53.905786] Primary group is 0 and contains 0 supplementary groups
  1527. [2022-06-17 08:44:53.907425] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1528. [2022-06-17 08:44:53.908935] LEGACY: mapping failed for sid S-1-5-7
  1529. [2022-06-17 08:44:53.910646] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1530. [2022-06-17 08:44:53.912292] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1531. [2022-06-17 08:44:53.922989] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1532. [2022-06-17 08:44:53.924920] Security token: (NULL)
  1533. [2022-06-17 08:44:53.926613] UNIX token of user 0
  1534. [2022-06-17 08:44:53.928256] Primary group is 0 and contains 0 supplementary groups
  1535. [2022-06-17 08:44:53.929901] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1536. [2022-06-17 08:44:53.931544] LEGACY: mapping failed for sid S-1-5-7
  1537. [2022-06-17 08:44:53.933243] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1538. [2022-06-17 08:44:53.937702] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1539. [2022-06-17 08:44:53.939473] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1540. [2022-06-17 08:44:53.941145] Security token: (NULL)
  1541. [2022-06-17 08:44:53.942779] UNIX token of user 0
  1542. [2022-06-17 08:44:53.944468] Primary group is 0 and contains 0 supplementary groups
  1543. [2022-06-17 08:44:53.946122] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1544. [2022-06-17 08:44:53.947747] LEGACY: mapping failed for sid S-1-1-0
  1545. [2022-06-17 08:44:53.949385] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1546. [2022-06-17 08:44:53.951026] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1547. [2022-06-17 08:44:53.952666] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1548. [2022-06-17 08:44:53.954354] Security token: (NULL)
  1549. [2022-06-17 08:44:53.955983] UNIX token of user 0
  1550. [2022-06-17 08:44:53.957585] Primary group is 0 and contains 0 supplementary groups
  1551. [2022-06-17 08:44:53.959227] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1552. [2022-06-17 08:44:53.960869] LEGACY: mapping failed for sid S-1-1-0
  1553. [2022-06-17 08:44:53.962503] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1554. [2022-06-17 08:44:53.964228] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1555. [2022-06-17 08:44:53.965875] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1556. [2022-06-17 08:44:53.967505] Security token: (NULL)
  1557. [2022-06-17 08:44:53.969118] UNIX token of user 0
  1558. [2022-06-17 08:44:53.970730] Primary group is 0 and contains 0 supplementary groups
  1559. [2022-06-17 08:44:53.972361] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1560. [2022-06-17 08:44:53.974091] LEGACY: mapping failed for sid S-1-5-2
  1561. [2022-06-17 08:44:53.975735] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1562. [2022-06-17 08:44:53.977371] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1563. [2022-06-17 08:44:53.979019] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1564. [2022-06-17 08:44:53.980658] Security token: (NULL)
  1565. [2022-06-17 08:44:53.982266] UNIX token of user 0
  1566. [2022-06-17 08:44:53.983940] Primary group is 0 and contains 0 supplementary groups
  1567. [2022-06-17 08:44:53.985603] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1568. [2022-06-17 08:44:53.987234] LEGACY: mapping failed for sid S-1-5-2
  1569. [2022-06-17 08:44:53.988872] Could not convert SID S-1-5-7 to gid, ignoring it
  1570. [2022-06-17 08:44:53.990514] Could not convert SID S-1-1-0 to gid, ignoring it
  1571. [2022-06-17 08:44:53.992148] Could not convert SID S-1-5-2 to gid, ignoring it
  1572. [2022-06-17 08:44:53.993710] sys_getgrouplist: user [nobody]
  1573. [2022-06-17 08:44:53.995348] Security token SIDs (5):
  1574. [2022-06-17 08:44:53.996986] SID[ 0]: S-1-5-7
  1575. [2022-06-17 08:44:53.998614] SID[ 1]: S-1-1-0
  1576. [2022-06-17 08:44:54.000398] SID[ 2]: S-1-5-2
  1577. [2022-06-17 08:44:54.002046] SID[ 3]: S-1-22-1-65534
  1578. [2022-06-17 08:44:54.003726] SID[ 4]: S-1-22-2-65534
  1579. [2022-06-17 08:44:54.005357] Privileges (0x 0):
  1580. [2022-06-17 08:44:54.006997] Rights (0x 0):
  1581. [2022-06-17 08:44:54.008641] UNIX token of user 65534
  1582. [2022-06-17 08:44:54.010256] Primary group is 65534 and contains 1 supplementary groups
  1583. [2022-06-17 08:44:54.011908] Group[ 0]: 65534
  1584. [2022-06-17 08:44:54.013574] dcesrv_init: Registering DCE/RPC endpoint servers
  1585. [2022-06-17 08:44:54.015228] DCERPC endpoint server 'winreg' registered
  1586. [2022-06-17 08:44:54.016849] DCERPC endpoint server 'srvsvc' registered
  1587. [2022-06-17 08:44:54.018485] DCERPC endpoint server 'lsarpc' registered
  1588. [2022-06-17 08:44:54.020117] DCERPC endpoint server 'samr' registered
  1589. [2022-06-17 08:44:54.021750] DCERPC endpoint server 'netdfs' registered
  1590. [2022-06-17 08:44:54.023443] DCERPC endpoint server 'dssetup' registered
  1591. [2022-06-17 08:44:54.025087] DCERPC endpoint server 'wkssvc' registered
  1592. [2022-06-17 08:44:54.026715] DCERPC endpoint server 'svcctl' registered
  1593. [2022-06-17 08:44:54.028219] DCERPC endpoint server 'ntsvcs' registered
  1594. [2022-06-17 08:44:54.029964] DCERPC endpoint server 'eventlog' registered
  1595. [2022-06-17 08:44:54.031601] DCERPC endpoint server 'initshutdown' registered
  1596. [2022-06-17 08:44:54.033286] dcesrv_init: Initializing DCE/RPC modules
  1597. [2022-06-17 08:44:54.034939] dcesrv_init: Initializing DCE/RPC registered endpoint servers
  1598. [2022-06-17 08:44:54.036586] dcesrv_interface_register: Interface 'winreg' registered on endpoint 'ncacn_np:[\pipe\winreg]' (single process required)
  1599. [2022-06-17 08:44:54.038258] winreg__check_register_in_endpoint: Interface 'winreg' not registered in endpoint 'winreg' as service is embedded
  1600. [2022-06-17 08:44:54.039928] dcesrv_interface_register: Interface 'winreg' registered on endpoint 'ncalrpc:' (single process required)
  1601. [2022-06-17 08:44:54.041597] dcesrv_interface_register: Interface 'srvsvc' registered on endpoint 'ncacn_np:[\pipe\srvsvc]' (single process required)
  1602. [2022-06-17 08:44:54.043314] srvsvc__check_register_in_endpoint: Interface 'srvsvc' not registered in endpoint 'srvsvc' as service is embedded
  1603. [2022-06-17 08:44:54.044899] dcesrv_interface_register: Interface 'srvsvc' registered on endpoint 'ncalrpc:' (single process required)
  1604. [2022-06-17 08:44:54.046704] dcesrv_interface_register: Interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\netlogon]' (single process required)
  1605. [2022-06-17 08:44:54.048405] dcesrv_interface_register: Interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\lsarpc]' (single process required)
  1606. [2022-06-17 08:44:54.050086] dcesrv_interface_register: Interface 'lsarpc' registered on endpoint 'ncacn_np:[\pipe\lsass]' (single process required)
  1607. [2022-06-17 08:44:54.051765] lsarpc__check_register_in_endpoint: Interface 'lsarpc' not registered in endpoint 'lsarpc' as service is embedded
  1608. [2022-06-17 08:44:54.053482] dcesrv_interface_register: Interface 'lsarpc' registered on endpoint 'ncalrpc:' (single process required)
  1609. [2022-06-17 08:44:54.055166] dcesrv_interface_register: Interface 'samr' registered on endpoint 'ncacn_np:[\pipe\samr]' (single process required)
  1610. [2022-06-17 08:44:54.056841] samr__check_register_in_endpoint: Interface 'samr' not registered in endpoint 'samr' as service is embedded
  1611. [2022-06-17 08:44:54.058532] dcesrv_interface_register: Interface 'samr' registered on endpoint 'ncalrpc:' (single process required)
  1612. [2022-06-17 08:44:54.060198] dcesrv_interface_register: Interface 'netdfs' registered on endpoint 'ncacn_np:[\pipe\netdfs]' (single process required)
  1613. [2022-06-17 08:44:54.061871] netdfs__check_register_in_endpoint: Interface 'netdfs' not registered in endpoint 'netdfs' as service is embedded
  1614. [2022-06-17 08:44:54.063729] dcesrv_interface_register: Interface 'netdfs' registered on endpoint 'ncalrpc:' (single process required)
  1615. [2022-06-17 08:44:54.065422] dcesrv_interface_register: Interface 'dssetup' registered on endpoint 'ncacn_np:[\pipe\lsarpc]' (single process required)
  1616. [2022-06-17 08:44:54.067099] dcesrv_interface_register: Interface 'dssetup' registered on endpoint 'ncacn_np:[\pipe\lsass]' (single process required)
  1617. [2022-06-17 08:44:54.068779] dssetup__check_register_in_endpoint: Interface 'dssetup' not registered in endpoint 'dssetup' as service is embedded
  1618. [2022-06-17 08:44:54.070454] dcesrv_interface_register: Interface 'dssetup' registered on endpoint 'ncalrpc:' (single process required)
  1619. [2022-06-17 08:44:54.072128] dcesrv_interface_register: Interface 'wkssvc' registered on endpoint 'ncacn_np:[\pipe\wkssvc]' (single process required)
  1620. [2022-06-17 08:44:54.073846] wkssvc__check_register_in_endpoint: Interface 'wkssvc' not registered in endpoint 'wkssvc' as service is embedded
  1621. [2022-06-17 08:44:54.075535] dcesrv_interface_register: Interface 'wkssvc' registered on endpoint 'ncalrpc:' (single process required)
  1622. [2022-06-17 08:44:54.077204] Initialise the svcctl registry keys if needed.
  1623. [2022-06-17 08:44:54.078852] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  1624. [2022-06-17 08:44:54.080474] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  1625. [2022-06-17 08:44:54.082105] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  1626. [2022-06-17 08:44:54.083809] Security token: (NULL)
  1627. [2022-06-17 08:44:54.085450] UNIX token of user 0
  1628. [2022-06-17 08:44:54.087067] Primary group is 0 and contains 0 supplementary groups
  1629. [2022-06-17 08:44:54.088704] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  1630. [2022-06-17 08:44:54.090349] regdb_open: registry db opened. refcount reset (1)
  1631. [2022-06-17 08:44:54.091991] make_internal_ncacn_conn: Create pipe requested winreg
  1632. [2022-06-17 08:44:54.093718] Created internal pipe winreg
  1633. [2022-06-17 08:44:54.095380] winreg_OpenHKLM: struct winreg_OpenHKLM
  1634. [2022-06-17 08:44:54.097018] in: struct winreg_OpenHKLM
  1635. [2022-06-17 08:44:54.098649] system_name : NULL
  1636. [2022-06-17 08:44:54.100275] access_mask : 0x02000000 (33554432)
  1637. [2022-06-17 08:44:54.101799] 0: KEY_QUERY_VALUE
  1638. [2022-06-17 08:44:54.103339] 0: KEY_SET_VALUE
  1639. [2022-06-17 08:44:54.105043] 0: KEY_CREATE_SUB_KEY
  1640. [2022-06-17 08:44:54.106692] 0: KEY_ENUMERATE_SUB_KEYS
  1641. [2022-06-17 08:44:54.108337] 0: KEY_NOTIFY
  1642. [2022-06-17 08:44:54.109977] 0: KEY_CREATE_LINK
  1643. [2022-06-17 08:44:54.111617] 0: KEY_WOW64_64KEY
  1644. [2022-06-17 08:44:54.113297] 0: KEY_WOW64_32KEY
  1645. [2022-06-17 08:44:54.114945] regkey_open_onelevel: name = [HKLM]
  1646. [2022-06-17 08:44:54.116579] regdb_open: incrementing refcount (1->2)
  1647. [2022-06-17 08:44:54.118215] reghook_cache_find: Searching for keyname [\HKLM]
  1648. [2022-06-17 08:44:54.119878] pathtree_find: Enter [\HKLM]
  1649. [2022-06-17 08:44:54.121513] pathtree_find: Exit
  1650. [2022-06-17 08:44:54.123171] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM]
  1651. [2022-06-17 08:44:54.124717] winreg_OpenHKLM: struct winreg_OpenHKLM
  1652. [2022-06-17 08:44:54.126208] out: struct winreg_OpenHKLM
  1653. [2022-06-17 08:44:54.127699] handle : *
  1654. [2022-06-17 08:44:54.129186] handle: struct policy_handle
  1655. [2022-06-17 08:44:54.130956] handle_type : 0x00000001 (1)
  1656. [2022-06-17 08:44:54.132600] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  1657. [2022-06-17 08:44:54.134342] result : WERR_OK
  1658. [2022-06-17 08:44:54.135980] winreg_OpenKey: struct winreg_OpenKey
  1659. [2022-06-17 08:44:54.137625] in: struct winreg_OpenKey
  1660. [2022-06-17 08:44:54.139264] parent_handle : *
  1661. [2022-06-17 08:44:54.140886] parent_handle: struct policy_handle
  1662. [2022-06-17 08:44:54.142515] handle_type : 0x00000001 (1)
  1663. [2022-06-17 08:44:54.144280] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  1664. [2022-06-17 08:44:54.145830] keyname: struct winreg_String
  1665. [2022-06-17 08:44:54.147604] name_len : 0x0044 (68)
  1666. [2022-06-17 08:44:54.149234] name_size : 0x0044 (68)
  1667. [2022-06-17 08:44:54.150873] name : *
  1668. [2022-06-17 08:44:54.152510] name : 'SYSTEM\CurrentControlSet\Services'
  1669. [2022-06-17 08:44:54.154254] options : 0x00000000 (0)
  1670. [2022-06-17 08:44:54.155899] 0: REG_OPTION_VOLATILE
  1671. [2022-06-17 08:44:54.157550] 0: REG_OPTION_CREATE_LINK
  1672. [2022-06-17 08:44:54.159194] 0: REG_OPTION_BACKUP_RESTORE
  1673. [2022-06-17 08:44:54.160821] 0: REG_OPTION_OPEN_LINK
  1674. [2022-06-17 08:44:54.162452] access_mask : 0x02000000 (33554432)
  1675. [2022-06-17 08:44:54.164179] 0: KEY_QUERY_VALUE
  1676. [2022-06-17 08:44:54.165825] 0: KEY_SET_VALUE
  1677. [2022-06-17 08:44:54.167474] 0: KEY_CREATE_SUB_KEY
  1678. [2022-06-17 08:44:54.169104] 0: KEY_ENUMERATE_SUB_KEYS
  1679. [2022-06-17 08:44:54.170739] 0: KEY_NOTIFY
  1680. [2022-06-17 08:44:54.172366] 0: KEY_CREATE_LINK
  1681. [2022-06-17 08:44:54.174084] 0: KEY_WOW64_64KEY
  1682. [2022-06-17 08:44:54.182977] 0: KEY_WOW64_32KEY
  1683. [2022-06-17 08:44:54.184846] regkey_open_onelevel: name = [SYSTEM]
  1684. [2022-06-17 08:44:54.186552] regdb_open: incrementing refcount (2->3)
  1685. [2022-06-17 08:44:54.188093] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  1686. [2022-06-17 08:44:54.189868] pathtree_find: Enter [\HKLM\SYSTEM]
  1687. [2022-06-17 08:44:54.195554] pathtree_find: Exit
  1688. [2022-06-17 08:44:54.197313] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  1689. [2022-06-17 08:44:54.198997] regkey_open_onelevel: name = [CurrentControlSet]
  1690. [2022-06-17 08:44:54.200651] regdb_open: incrementing refcount (3->4)
  1691. [2022-06-17 08:44:54.202301] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  1692. [2022-06-17 08:44:54.204057] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  1693. [2022-06-17 08:44:54.205724] pathtree_find: Exit
  1694. [2022-06-17 08:44:54.207334] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  1695. [2022-06-17 08:44:54.208995] regkey_open_onelevel: name = [Services]
  1696. [2022-06-17 08:44:54.210630] regdb_open: incrementing refcount (4->5)
  1697. [2022-06-17 08:44:54.212258] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  1698. [2022-06-17 08:44:54.213966] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  1699. [2022-06-17 08:44:54.215630] pathtree_find: Exit
  1700. [2022-06-17 08:44:54.217259] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  1701. [2022-06-17 08:44:54.218927] regdb_close: decrementing refcount (5->4)
  1702. [2022-06-17 08:44:54.220565] regdb_close: decrementing refcount (4->3)
  1703. [2022-06-17 08:44:54.222190] winreg_OpenKey: struct winreg_OpenKey
  1704. [2022-06-17 08:44:54.223866] out: struct winreg_OpenKey
  1705. [2022-06-17 08:44:54.225493] handle : *
  1706. [2022-06-17 08:44:54.227128] handle: struct policy_handle
  1707. [2022-06-17 08:44:54.228779] handle_type : 0x00000001 (1)
  1708. [2022-06-17 08:44:54.230417] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1709. [2022-06-17 08:44:54.232073] result : WERR_OK
  1710. [2022-06-17 08:44:54.233759] winreg_QueryInfoKey: struct winreg_QueryInfoKey
  1711. [2022-06-17 08:44:54.235411] in: struct winreg_QueryInfoKey
  1712. [2022-06-17 08:44:54.237043] handle : *
  1713. [2022-06-17 08:44:54.238680] handle: struct policy_handle
  1714. [2022-06-17 08:44:54.240329] handle_type : 0x00000001 (1)
  1715. [2022-06-17 08:44:54.241977] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1716. [2022-06-17 08:44:54.243685] classname : *
  1717. [2022-06-17 08:44:54.245320] classname: struct winreg_String
  1718. [2022-06-17 08:44:54.246971] name_len : 0x0000 (0)
  1719. [2022-06-17 08:44:54.248621] name_size : 0x0000 (0)
  1720. [2022-06-17 08:44:54.250137] name : NULL
  1721. [2022-06-17 08:44:54.251634] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services' (ops 0xb6ab32e8)
  1722. [2022-06-17 08:44:54.253188] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services]
  1723. [2022-06-17 08:44:54.254966] regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
  1724. [2022-06-17 08:44:54.256637] winreg_QueryInfoKey: struct winreg_QueryInfoKey
  1725. [2022-06-17 08:44:54.258283] out: struct winreg_QueryInfoKey
  1726. [2022-06-17 08:44:54.259919] classname : *
  1727. [2022-06-17 08:44:54.261428] classname: struct winreg_String
  1728. [2022-06-17 08:44:54.263267] name_len : 0x0000 (0)
  1729. [2022-06-17 08:44:54.264946] name_size : 0x0000 (0)
  1730. [2022-06-17 08:44:54.266596] name : NULL
  1731. [2022-06-17 08:44:54.268231] num_subkeys : *
  1732. [2022-06-17 08:44:54.269857] num_subkeys : 0x00000007 (7)
  1733. [2022-06-17 08:44:54.271496] max_subkeylen : *
  1734. [2022-06-17 08:44:54.273174] max_subkeylen : 0x0000001c (28)
  1735. [2022-06-17 08:44:54.274838] max_classlen : *
  1736. [2022-06-17 08:44:54.276479] max_classlen : 0x00000000 (0)
  1737. [2022-06-17 08:44:54.278134] num_values : *
  1738. [2022-06-17 08:44:54.279762] num_values : 0x00000000 (0)
  1739. [2022-06-17 08:44:54.281401] max_valnamelen : *
  1740. [2022-06-17 08:44:54.283072] max_valnamelen : 0x00000002 (2)
  1741. [2022-06-17 08:44:54.284721] max_valbufsize : *
  1742. [2022-06-17 08:44:54.286232] max_valbufsize : 0x00000000 (0)
  1743. [2022-06-17 08:44:54.287742] secdescsize : *
  1744. [2022-06-17 08:44:54.289237] secdescsize : 0x00000078 (120)
  1745. [2022-06-17 08:44:54.291010] last_changed_time : *
  1746. [2022-06-17 08:44:54.292646] last_changed_time : NTTIME(0)
  1747. [2022-06-17 08:44:54.294375] result : WERR_OK
  1748. [2022-06-17 08:44:54.296011] winreg_EnumKey: struct winreg_EnumKey
  1749. [2022-06-17 08:44:54.297642] in: struct winreg_EnumKey
  1750. [2022-06-17 08:44:54.299289] handle : *
  1751. [2022-06-17 08:44:54.300800] handle: struct policy_handle
  1752. [2022-06-17 08:44:54.302296] handle_type : 0x00000001 (1)
  1753. [2022-06-17 08:44:54.303997] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1754. [2022-06-17 08:44:54.305659] enum_index : 0x00000000 (0)
  1755. [2022-06-17 08:44:54.307307] name : *
  1756. [2022-06-17 08:44:54.308939] name: struct winreg_StringBuf
  1757. [2022-06-17 08:44:54.310580] length : 0x0000 (0)
  1758. [2022-06-17 08:44:54.312244] size : 0x001e (30)
  1759. [2022-06-17 08:44:54.313954] name : *
  1760. [2022-06-17 08:44:54.315600] name : ''
  1761. [2022-06-17 08:44:54.317248] keyclass : *
  1762. [2022-06-17 08:44:54.318874] keyclass: struct winreg_StringBuf
  1763. [2022-06-17 08:44:54.320514] length : 0x0000 (0)
  1764. [2022-06-17 08:44:54.322156] size : 0x0002 (2)
  1765. [2022-06-17 08:44:54.323852] name : *
  1766. [2022-06-17 08:44:54.325519] name : ''
  1767. [2022-06-17 08:44:54.327172] last_changed_time : *
  1768. [2022-06-17 08:44:54.328797] last_changed_time : NTTIME(0)
  1769. [2022-06-17 08:44:54.330425] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  1770. [2022-06-17 08:44:54.332067] winreg_EnumKey: struct winreg_EnumKey
  1771. [2022-06-17 08:44:54.333761] out: struct winreg_EnumKey
  1772. [2022-06-17 08:44:54.335403] name : *
  1773. [2022-06-17 08:44:54.337041] name: struct winreg_StringBuf
  1774. [2022-06-17 08:44:54.338684] length : 0x001a (26)
  1775. [2022-06-17 08:44:54.340327] size : 0x001e (30)
  1776. [2022-06-17 08:44:54.341962] name : *
  1777. [2022-06-17 08:44:54.343655] name : 'LanmanServer'
  1778. [2022-06-17 08:44:54.345303] keyclass : *
  1779. [2022-06-17 08:44:54.346946] keyclass: struct winreg_StringBuf
  1780. [2022-06-17 08:44:54.348589] length : 0x0000 (0)
  1781. [2022-06-17 08:44:54.350229] size : 0x0002 (2)
  1782. [2022-06-17 08:44:54.351869] name : *
  1783. [2022-06-17 08:44:54.353589] name : ''
  1784. [2022-06-17 08:44:54.355247] last_changed_time : *
  1785. [2022-06-17 08:44:54.356882] last_changed_time : NTTIME(0)
  1786. [2022-06-17 08:44:54.358523] result : WERR_OK
  1787. [2022-06-17 08:44:54.360175] winreg_EnumKey: struct winreg_EnumKey
  1788. [2022-06-17 08:44:54.361799] in: struct winreg_EnumKey
  1789. [2022-06-17 08:44:54.363469] handle : *
  1790. [2022-06-17 08:44:54.365101] handle: struct policy_handle
  1791. [2022-06-17 08:44:54.366716] handle_type : 0x00000001 (1)
  1792. [2022-06-17 08:44:54.368372] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1793. [2022-06-17 08:44:54.370025] enum_index : 0x00000001 (1)
  1794. [2022-06-17 08:44:54.371672] name : *
  1795. [2022-06-17 08:44:54.373354] name: struct winreg_StringBuf
  1796. [2022-06-17 08:44:54.375007] length : 0x0000 (0)
  1797. [2022-06-17 08:44:54.376646] size : 0x001e (30)
  1798. [2022-06-17 08:44:54.378283] name : *
  1799. [2022-06-17 08:44:54.379911] name : ''
  1800. [2022-06-17 08:44:54.381553] keyclass : *
  1801. [2022-06-17 08:44:54.383244] keyclass: struct winreg_StringBuf
  1802. [2022-06-17 08:44:54.384908] length : 0x0000 (0)
  1803. [2022-06-17 08:44:54.386562] size : 0x0002 (2)
  1804. [2022-06-17 08:44:54.388205] name : *
  1805. [2022-06-17 08:44:54.389845] name : ''
  1806. [2022-06-17 08:44:54.391477] last_changed_time : *
  1807. [2022-06-17 08:44:54.393164] last_changed_time : NTTIME(0)
  1808. [2022-06-17 08:44:54.394821] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  1809. [2022-06-17 08:44:54.396498] winreg_EnumKey: struct winreg_EnumKey
  1810. [2022-06-17 08:44:54.398134] out: struct winreg_EnumKey
  1811. [2022-06-17 08:44:54.399775] name : *
  1812. [2022-06-17 08:44:54.401400] name: struct winreg_StringBuf
  1813. [2022-06-17 08:44:54.403077] length : 0x0012 (18)
  1814. [2022-06-17 08:44:54.404741] size : 0x001e (30)
  1815. [2022-06-17 08:44:54.406388] name : *
  1816. [2022-06-17 08:44:54.408025] name : 'Eventlog'
  1817. [2022-06-17 08:44:54.409675] keyclass : *
  1818. [2022-06-17 08:44:54.411311] keyclass: struct winreg_StringBuf
  1819. [2022-06-17 08:44:54.412998] length : 0x0000 (0)
  1820. [2022-06-17 08:44:54.414656] size : 0x0002 (2)
  1821. [2022-06-17 08:44:54.416295] name : *
  1822. [2022-06-17 08:44:54.417921] name : ''
  1823. [2022-06-17 08:44:54.419565] last_changed_time : *
  1824. [2022-06-17 08:44:54.421207] last_changed_time : NTTIME(0)
  1825. [2022-06-17 08:44:54.422852] result : WERR_OK
  1826. [2022-06-17 08:44:54.424556] winreg_EnumKey: struct winreg_EnumKey
  1827. [2022-06-17 08:44:54.426192] in: struct winreg_EnumKey
  1828. [2022-06-17 08:44:54.427820] handle : *
  1829. [2022-06-17 08:44:54.429453] handle: struct policy_handle
  1830. [2022-06-17 08:44:54.431099] handle_type : 0x00000001 (1)
  1831. [2022-06-17 08:44:54.432754] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1832. [2022-06-17 08:44:54.434372] enum_index : 0x00000002 (2)
  1833. [2022-06-17 08:44:54.435877] name : *
  1834. [2022-06-17 08:44:54.437638] name: struct winreg_StringBuf
  1835. [2022-06-17 08:44:54.439286] length : 0x0000 (0)
  1836. [2022-06-17 08:44:54.440924] size : 0x001e (30)
  1837. [2022-06-17 08:44:54.442560] name : *
  1838. [2022-06-17 08:44:54.444287] name : ''
  1839. [2022-06-17 08:44:54.445938] keyclass : *
  1840. [2022-06-17 08:44:54.447578] keyclass: struct winreg_StringBuf
  1841. [2022-06-17 08:44:54.452954] length : 0x0000 (0)
  1842. [2022-06-17 08:44:54.460887] size : 0x0002 (2)
  1843. [2022-06-17 08:44:54.462571] name : *
  1844. [2022-06-17 08:44:54.464306] name : ''
  1845. [2022-06-17 08:44:54.465967] last_changed_time : *
  1846. [2022-06-17 08:44:54.467604] last_changed_time : NTTIME(0)
  1847. [2022-06-17 08:44:54.469247] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  1848. [2022-06-17 08:44:54.470880] winreg_EnumKey: struct winreg_EnumKey
  1849. [2022-06-17 08:44:54.472505] out: struct winreg_EnumKey
  1850. [2022-06-17 08:44:54.474212] name : *
  1851. [2022-06-17 08:44:54.475846] name: struct winreg_StringBuf
  1852. [2022-06-17 08:44:54.477495] length : 0x000c (12)
  1853. [2022-06-17 08:44:54.479142] size : 0x001e (30)
  1854. [2022-06-17 08:44:54.480775] name : *
  1855. [2022-06-17 08:44:54.482420] name : 'Tcpip'
  1856. [2022-06-17 08:44:54.484135] keyclass : *
  1857. [2022-06-17 08:44:54.485766] keyclass: struct winreg_StringBuf
  1858. [2022-06-17 08:44:54.487406] length : 0x0000 (0)
  1859. [2022-06-17 08:44:54.489034] size : 0x0002 (2)
  1860. [2022-06-17 08:44:54.490671] name : *
  1861. [2022-06-17 08:44:54.492330] name : ''
  1862. [2022-06-17 08:44:54.493935] last_changed_time : *
  1863. [2022-06-17 08:44:54.495434] last_changed_time : NTTIME(0)
  1864. [2022-06-17 08:44:54.496924] result : WERR_OK
  1865. [2022-06-17 08:44:54.498407] winreg_EnumKey: struct winreg_EnumKey
  1866. [2022-06-17 08:44:54.499889] in: struct winreg_EnumKey
  1867. [2022-06-17 08:44:54.501377] handle : *
  1868. [2022-06-17 08:44:54.502908] handle: struct policy_handle
  1869. [2022-06-17 08:44:54.504421] handle_type : 0x00000001 (1)
  1870. [2022-06-17 08:44:54.505932] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1871. [2022-06-17 08:44:54.507607] enum_index : 0x00000003 (3)
  1872. [2022-06-17 08:44:54.509138] name : *
  1873. [2022-06-17 08:44:54.510638] name: struct winreg_StringBuf
  1874. [2022-06-17 08:44:54.512133] length : 0x0000 (0)
  1875. [2022-06-17 08:44:54.513689] size : 0x001e (30)
  1876. [2022-06-17 08:44:54.515202] name : *
  1877. [2022-06-17 08:44:54.516707] name : ''
  1878. [2022-06-17 08:44:54.518204] keyclass : *
  1879. [2022-06-17 08:44:54.519687] keyclass: struct winreg_StringBuf
  1880. [2022-06-17 08:44:54.521167] length : 0x0000 (0)
  1881. [2022-06-17 08:44:54.522829] size : 0x0002 (2)
  1882. [2022-06-17 08:44:54.524419] name : *
  1883. [2022-06-17 08:44:54.525933] name : ''
  1884. [2022-06-17 08:44:54.527444] last_changed_time : *
  1885. [2022-06-17 08:44:54.528935] last_changed_time : NTTIME(0)
  1886. [2022-06-17 08:44:54.530418] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  1887. [2022-06-17 08:44:54.531916] winreg_EnumKey: struct winreg_EnumKey
  1888. [2022-06-17 08:44:54.533452] out: struct winreg_EnumKey
  1889. [2022-06-17 08:44:54.534958] name : *
  1890. [2022-06-17 08:44:54.536453] name: struct winreg_StringBuf
  1891. [2022-06-17 08:44:54.537947] length : 0x0012 (18)
  1892. [2022-06-17 08:44:54.539447] size : 0x001e (30)
  1893. [2022-06-17 08:44:54.540947] name : *
  1894. [2022-06-17 08:44:54.542451] name : 'Netlogon'
  1895. [2022-06-17 08:44:54.544019] keyclass : *
  1896. [2022-06-17 08:44:54.545522] keyclass: struct winreg_StringBuf
  1897. [2022-06-17 08:44:54.547025] length : 0x0000 (0)
  1898. [2022-06-17 08:44:54.548515] size : 0x0002 (2)
  1899. [2022-06-17 08:44:54.550015] name : *
  1900. [2022-06-17 08:44:54.551620] name : ''
  1901. [2022-06-17 08:44:54.553334] last_changed_time : *
  1902. [2022-06-17 08:44:54.554875] last_changed_time : NTTIME(0)
  1903. [2022-06-17 08:44:54.556392] result : WERR_OK
  1904. [2022-06-17 08:44:54.557905] winreg_EnumKey: struct winreg_EnumKey
  1905. [2022-06-17 08:44:54.559408] in: struct winreg_EnumKey
  1906. [2022-06-17 08:44:54.560909] handle : *
  1907. [2022-06-17 08:44:54.562393] handle: struct policy_handle
  1908. [2022-06-17 08:44:54.563966] handle_type : 0x00000001 (1)
  1909. [2022-06-17 08:44:54.565486] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1910. [2022-06-17 08:44:54.567003] enum_index : 0x00000004 (4)
  1911. [2022-06-17 08:44:54.568682] name : *
  1912. [2022-06-17 08:44:54.570208] name: struct winreg_StringBuf
  1913. [2022-06-17 08:44:54.571712] length : 0x0000 (0)
  1914. [2022-06-17 08:44:54.573267] size : 0x001e (30)
  1915. [2022-06-17 08:44:54.574790] name : *
  1916. [2022-06-17 08:44:54.576289] name : ''
  1917. [2022-06-17 08:44:54.577782] keyclass : *
  1918. [2022-06-17 08:44:54.579271] keyclass: struct winreg_StringBuf
  1919. [2022-06-17 08:44:54.580779] length : 0x0000 (0)
  1920. [2022-06-17 08:44:54.582284] size : 0x0002 (2)
  1921. [2022-06-17 08:44:54.584026] name : *
  1922. [2022-06-17 08:44:54.585557] name : ''
  1923. [2022-06-17 08:44:54.587065] last_changed_time : *
  1924. [2022-06-17 08:44:54.588561] last_changed_time : NTTIME(0)
  1925. [2022-06-17 08:44:54.590054] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  1926. [2022-06-17 08:44:54.591564] winreg_EnumKey: struct winreg_EnumKey
  1927. [2022-06-17 08:44:54.593111] out: struct winreg_EnumKey
  1928. [2022-06-17 08:44:54.594631] name : *
  1929. [2022-06-17 08:44:54.596126] name: struct winreg_StringBuf
  1930. [2022-06-17 08:44:54.597620] length : 0x0010 (16)
  1931. [2022-06-17 08:44:54.599328] size : 0x001e (30)
  1932. [2022-06-17 08:44:54.600840] name : *
  1933. [2022-06-17 08:44:54.602345] name : 'Spooler'
  1934. [2022-06-17 08:44:54.603957] keyclass : *
  1935. [2022-06-17 08:44:54.605474] keyclass: struct winreg_StringBuf
  1936. [2022-06-17 08:44:54.606973] length : 0x0000 (0)
  1937. [2022-06-17 08:44:54.608480] size : 0x0002 (2)
  1938. [2022-06-17 08:44:54.609985] name : *
  1939. [2022-06-17 08:44:54.611479] name : ''
  1940. [2022-06-17 08:44:54.613201] last_changed_time : *
  1941. [2022-06-17 08:44:54.614760] last_changed_time : NTTIME(0)
  1942. [2022-06-17 08:44:54.616276] result : WERR_OK
  1943. [2022-06-17 08:44:54.618374] winreg_EnumKey: struct winreg_EnumKey
  1944. [2022-06-17 08:44:54.620742] in: struct winreg_EnumKey
  1945. [2022-06-17 08:44:54.622401] handle : *
  1946. [2022-06-17 08:44:54.624183] handle: struct policy_handle
  1947. [2022-06-17 08:44:54.625859] handle_type : 0x00000001 (1)
  1948. [2022-06-17 08:44:54.627518] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1949. [2022-06-17 08:44:54.629170] enum_index : 0x00000005 (5)
  1950. [2022-06-17 08:44:54.630818] name : *
  1951. [2022-06-17 08:44:54.632452] name: struct winreg_StringBuf
  1952. [2022-06-17 08:44:54.634290] length : 0x0000 (0)
  1953. [2022-06-17 08:44:54.635936] size : 0x001e (30)
  1954. [2022-06-17 08:44:54.637565] name : *
  1955. [2022-06-17 08:44:54.639212] name : ''
  1956. [2022-06-17 08:44:54.640877] keyclass : *
  1957. [2022-06-17 08:44:54.642511] keyclass: struct winreg_StringBuf
  1958. [2022-06-17 08:44:54.644115] length : 0x0000 (0)
  1959. [2022-06-17 08:44:54.645735] size : 0x0002 (2)
  1960. [2022-06-17 08:44:54.647376] name : *
  1961. [2022-06-17 08:44:54.649019] name : ''
  1962. [2022-06-17 08:44:54.650665] last_changed_time : *
  1963. [2022-06-17 08:44:54.652306] last_changed_time : NTTIME(0)
  1964. [2022-06-17 08:44:54.654031] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  1965. [2022-06-17 08:44:54.655702] winreg_EnumKey: struct winreg_EnumKey
  1966. [2022-06-17 08:44:54.657343] out: struct winreg_EnumKey
  1967. [2022-06-17 08:44:54.658972] name : *
  1968. [2022-06-17 08:44:54.660596] name: struct winreg_StringBuf
  1969. [2022-06-17 08:44:54.662238] length : 0x001e (30)
  1970. [2022-06-17 08:44:54.663919] size : 0x001e (30)
  1971. [2022-06-17 08:44:54.665583] name : *
  1972. [2022-06-17 08:44:54.667233] name : 'RemoteRegistry'
  1973. [2022-06-17 08:44:54.668881] keyclass : *
  1974. [2022-06-17 08:44:54.670523] keyclass: struct winreg_StringBuf
  1975. [2022-06-17 08:44:54.672157] length : 0x0000 (0)
  1976. [2022-06-17 08:44:54.673854] size : 0x0002 (2)
  1977. [2022-06-17 08:44:54.675512] name : *
  1978. [2022-06-17 08:44:54.677252] name : ''
  1979. [2022-06-17 08:44:54.678914] last_changed_time : *
  1980. [2022-06-17 08:44:54.680558] last_changed_time : NTTIME(0)
  1981. [2022-06-17 08:44:54.682181] result : WERR_OK
  1982. [2022-06-17 08:44:54.683864] winreg_EnumKey: struct winreg_EnumKey
  1983. [2022-06-17 08:44:54.685510] in: struct winreg_EnumKey
  1984. [2022-06-17 08:44:54.687157] handle : *
  1985. [2022-06-17 08:44:54.688802] handle: struct policy_handle
  1986. [2022-06-17 08:44:54.690436] handle_type : 0x00000001 (1)
  1987. [2022-06-17 08:44:54.692090] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  1988. [2022-06-17 08:44:54.693791] enum_index : 0x00000006 (6)
  1989. [2022-06-17 08:44:54.695441] name : *
  1990. [2022-06-17 08:44:54.697078] name: struct winreg_StringBuf
  1991. [2022-06-17 08:44:54.698722] length : 0x0000 (0)
  1992. [2022-06-17 08:44:54.700369] size : 0x001e (30)
  1993. [2022-06-17 08:44:54.702012] name : *
  1994. [2022-06-17 08:44:54.703713] name : ''
  1995. [2022-06-17 08:44:54.705372] keyclass : *
  1996. [2022-06-17 08:44:54.707008] keyclass: struct winreg_StringBuf
  1997. [2022-06-17 08:44:54.708641] length : 0x0000 (0)
  1998. [2022-06-17 08:44:54.710273] size : 0x0002 (2)
  1999. [2022-06-17 08:44:54.711918] name : *
  2000. [2022-06-17 08:44:54.713621] name : ''
  2001. [2022-06-17 08:44:54.715276] last_changed_time : *
  2002. [2022-06-17 08:44:54.722985] last_changed_time : NTTIME(0)
  2003. [2022-06-17 08:44:54.724869] _winreg_EnumKey: enumerating key [HKLM\SYSTEM\CurrentControlSet\Services]
  2004. [2022-06-17 08:44:54.726588] winreg_EnumKey: struct winreg_EnumKey
  2005. [2022-06-17 08:44:54.732997] out: struct winreg_EnumKey
  2006. [2022-06-17 08:44:54.734881] name : *
  2007. [2022-06-17 08:44:54.736595] name: struct winreg_StringBuf
  2008. [2022-06-17 08:44:54.738278] length : 0x000a (10)
  2009. [2022-06-17 08:44:54.739942] size : 0x001e (30)
  2010. [2022-06-17 08:44:54.742423] name : *
  2011. [2022-06-17 08:44:54.744201] name : 'WINS'
  2012. [2022-06-17 08:44:54.745868] keyclass : *
  2013. [2022-06-17 08:44:54.747507] keyclass: struct winreg_StringBuf
  2014. [2022-06-17 08:44:54.749152] length : 0x0000 (0)
  2015. [2022-06-17 08:44:54.750803] size : 0x0002 (2)
  2016. [2022-06-17 08:44:54.752454] name : *
  2017. [2022-06-17 08:44:54.754060] name : ''
  2018. [2022-06-17 08:44:54.755566] last_changed_time : *
  2019. [2022-06-17 08:44:54.757052] last_changed_time : NTTIME(0)
  2020. [2022-06-17 08:44:54.758826] result : WERR_OK
  2021. [2022-06-17 08:44:54.760468] winreg_CreateKey: struct winreg_CreateKey
  2022. [2022-06-17 08:44:54.762110] in: struct winreg_CreateKey
  2023. [2022-06-17 08:44:54.763812] handle : *
  2024. [2022-06-17 08:44:54.765456] handle: struct policy_handle
  2025. [2022-06-17 08:44:54.767090] handle_type : 0x00000001 (1)
  2026. [2022-06-17 08:44:54.768608] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  2027. [2022-06-17 08:44:54.770125] name: struct winreg_String
  2028. [2022-06-17 08:44:54.771613] name_len : 0x0054 (84)
  2029. [2022-06-17 08:44:54.773169] name_size : 0x0054 (84)
  2030. [2022-06-17 08:44:54.774679] name : *
  2031. [2022-06-17 08:44:54.776174] name : 'SYSTEM\CurrentControlSet\Services\Spooler'
  2032. [2022-06-17 08:44:54.777670] keyclass: struct winreg_String
  2033. [2022-06-17 08:44:54.779159] name_len : 0x0002 (2)
  2034. [2022-06-17 08:44:54.780645] name_size : 0x0002 (2)
  2035. [2022-06-17 08:44:54.782315] name : *
  2036. [2022-06-17 08:44:54.783939] name : ''
  2037. [2022-06-17 08:44:54.785458] options : 0x00000000 (0)
  2038. [2022-06-17 08:44:54.786960] 0: REG_OPTION_VOLATILE
  2039. [2022-06-17 08:44:54.788449] 0: REG_OPTION_CREATE_LINK
  2040. [2022-06-17 08:44:54.789927] 0: REG_OPTION_BACKUP_RESTORE
  2041. [2022-06-17 08:44:54.791408] 0: REG_OPTION_OPEN_LINK
  2042. [2022-06-17 08:44:54.792931] access_mask : 0x02000000 (33554432)
  2043. [2022-06-17 08:44:54.794457] 0: KEY_QUERY_VALUE
  2044. [2022-06-17 08:44:54.795958] 0: KEY_SET_VALUE
  2045. [2022-06-17 08:44:54.797654] 0: KEY_CREATE_SUB_KEY
  2046. [2022-06-17 08:44:54.799187] 0: KEY_ENUMERATE_SUB_KEYS
  2047. [2022-06-17 08:44:54.800692] 0: KEY_NOTIFY
  2048. [2022-06-17 08:44:54.802190] 0: KEY_CREATE_LINK
  2049. [2022-06-17 08:44:54.803734] 0: KEY_WOW64_64KEY
  2050. [2022-06-17 08:44:54.805240] 0: KEY_WOW64_32KEY
  2051. [2022-06-17 08:44:54.806745] secdesc : NULL
  2052. [2022-06-17 08:44:54.808232] action_taken : *
  2053. [2022-06-17 08:44:54.809724] action_taken : REG_ACTION_NONE (0)
  2054. [2022-06-17 08:44:54.811215] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\Spooler'
  2055. [2022-06-17 08:44:54.813501] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2056. [2022-06-17 08:44:54.815182] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2057. [2022-06-17 08:44:54.816705] regkey_open_onelevel: name = [SYSTEM]
  2058. [2022-06-17 08:44:54.818391] regdb_open: incrementing refcount (3->4)
  2059. [2022-06-17 08:44:54.820036] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  2060. [2022-06-17 08:44:54.822350] pathtree_find: Enter [\HKLM\SYSTEM]
  2061. [2022-06-17 08:44:54.823977] pathtree_find: Exit
  2062. [2022-06-17 08:44:54.825611] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  2063. [2022-06-17 08:44:54.827382] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2064. [2022-06-17 08:44:54.829020] regkey_open_onelevel: name = [CurrentControlSet]
  2065. [2022-06-17 08:44:54.830663] regdb_open: incrementing refcount (4->5)
  2066. [2022-06-17 08:44:54.832190] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  2067. [2022-06-17 08:44:54.834025] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  2068. [2022-06-17 08:44:54.835560] pathtree_find: Exit
  2069. [2022-06-17 08:44:54.837178] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  2070. [2022-06-17 08:44:54.838830] regdb_close: decrementing refcount (5->4)
  2071. [2022-06-17 08:44:54.840467] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2072. [2022-06-17 08:44:54.842110] regkey_open_onelevel: name = [Services]
  2073. [2022-06-17 08:44:54.843802] regdb_open: incrementing refcount (4->5)
  2074. [2022-06-17 08:44:54.845305] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  2075. [2022-06-17 08:44:54.847087] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  2076. [2022-06-17 08:44:54.848733] pathtree_find: Exit
  2077. [2022-06-17 08:44:54.850235] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  2078. [2022-06-17 08:44:54.851877] regdb_close: decrementing refcount (5->4)
  2079. [2022-06-17 08:44:54.853565] regkey_open_onelevel: name = [Spooler]
  2080. [2022-06-17 08:44:54.855240] regdb_open: incrementing refcount (4->5)
  2081. [2022-06-17 08:44:54.857005] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2082. [2022-06-17 08:44:54.858547] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2083. [2022-06-17 08:44:54.860194] pathtree_find: Exit
  2084. [2022-06-17 08:44:54.861809] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2085. [2022-06-17 08:44:54.863615] regdb_close: decrementing refcount (5->4)
  2086. [2022-06-17 08:44:54.865391] winreg_CreateKey: struct winreg_CreateKey
  2087. [2022-06-17 08:44:54.866925] out: struct winreg_CreateKey
  2088. [2022-06-17 08:44:54.868571] new_handle : *
  2089. [2022-06-17 08:44:54.870323] new_handle: struct policy_handle
  2090. [2022-06-17 08:44:54.871857] handle_type : 0x00000001 (1)
  2091. [2022-06-17 08:44:54.873560] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2092. [2022-06-17 08:44:54.875217] action_taken : *
  2093. [2022-06-17 08:44:54.876953] action_taken : REG_OPENED_EXISTING_KEY (2)
  2094. [2022-06-17 08:44:54.878593] result : WERR_OK
  2095. [2022-06-17 08:44:54.880133] winreg_SetValue: struct winreg_SetValue
  2096. [2022-06-17 08:44:54.881771] in: struct winreg_SetValue
  2097. [2022-06-17 08:44:54.883451] handle : *
  2098. [2022-06-17 08:44:54.885104] handle: struct policy_handle
  2099. [2022-06-17 08:44:54.886853] handle_type : 0x00000001 (1)
  2100. [2022-06-17 08:44:54.888484] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2101. [2022-06-17 08:44:54.890024] name: struct winreg_String
  2102. [2022-06-17 08:44:54.891666] name_len : 0x000c (12)
  2103. [2022-06-17 08:44:54.893364] name_size : 0x000c (12)
  2104. [2022-06-17 08:44:54.895027] name : *
  2105. [2022-06-17 08:44:54.896664] name : 'Start'
  2106. [2022-06-17 08:44:54.898304] type : REG_DWORD (4)
  2107. [2022-06-17 08:44:54.900051] data : *
  2108. [2022-06-17 08:44:54.901576] data: ARRAY(4)
  2109. [2022-06-17 08:44:54.903256] [0] : 0x02 (2)
  2110. [2022-06-17 08:44:54.904912] [1] : 0x00 (0)
  2111. [2022-06-17 08:44:54.906637] [2] : 0x00 (0)
  2112. [2022-06-17 08:44:54.908172] [3] : 0x00 (0)
  2113. [2022-06-17 08:44:54.909886] size : 0x00000004 (4)
  2114. [2022-06-17 08:44:54.911406] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:Start]
  2115. [2022-06-17 08:44:54.913137] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2116. [2022-06-17 08:44:54.914813] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\Spooler' (ops 0xb6ab32e8)
  2117. [2022-06-17 08:44:54.916501] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2118. [2022-06-17 08:44:54.918180] regdb_unpack_values: value[0]: name[Start] len[4]
  2119. [2022-06-17 08:44:54.919823] regdb_unpack_values: value[1]: name[Type] len[4]
  2120. [2022-06-17 08:44:54.921443] regdb_unpack_values: value[2]: name[ErrorControl] len[4]
  2121. [2022-06-17 08:44:54.923153] regdb_unpack_values: value[3]: name[ObjectName] len[24]
  2122. [2022-06-17 08:44:54.924803] regdb_unpack_values: value[4]: name[DisplayName] len[28]
  2123. [2022-06-17 08:44:54.926554] regdb_unpack_values: value[5]: name[ImagePath] len[54]
  2124. [2022-06-17 08:44:54.928088] regdb_unpack_values: value[6]: name[Description] len[106]
  2125. [2022-06-17 08:44:54.929734] winreg_SetValue: struct winreg_SetValue
  2126. [2022-06-17 08:44:54.931373] out: struct winreg_SetValue
  2127. [2022-06-17 08:44:54.933041] result : WERR_OK
  2128. [2022-06-17 08:44:54.934794] winreg_SetValue: struct winreg_SetValue
  2129. [2022-06-17 08:44:54.936434] in: struct winreg_SetValue
  2130. [2022-06-17 08:44:54.938053] handle : *
  2131. [2022-06-17 08:44:54.939568] handle: struct policy_handle
  2132. [2022-06-17 08:44:54.941228] handle_type : 0x00000001 (1)
  2133. [2022-06-17 08:44:54.943013] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2134. [2022-06-17 08:44:54.944578] name: struct winreg_String
  2135. [2022-06-17 08:44:54.946319] name_len : 0x000a (10)
  2136. [2022-06-17 08:44:54.947841] name_size : 0x000a (10)
  2137. [2022-06-17 08:44:54.949476] name : *
  2138. [2022-06-17 08:44:54.951205] name : 'Type'
  2139. [2022-06-17 08:44:54.952740] type : REG_DWORD (4)
  2140. [2022-06-17 08:44:54.954549] data : *
  2141. [2022-06-17 08:44:54.956079] data: ARRAY(4)
  2142. [2022-06-17 08:44:54.957698] [0] : 0x10 (16)
  2143. [2022-06-17 08:44:54.959328] [1] : 0x00 (0)
  2144. [2022-06-17 08:44:54.961065] [2] : 0x00 (0)
  2145. [2022-06-17 08:44:54.962587] [3] : 0x00 (0)
  2146. [2022-06-17 08:44:54.964290] size : 0x00000004 (4)
  2147. [2022-06-17 08:44:54.965950] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:Type]
  2148. [2022-06-17 08:44:54.967604] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2149. [2022-06-17 08:44:54.969371] winreg_SetValue: struct winreg_SetValue
  2150. [2022-06-17 08:44:54.970897] out: struct winreg_SetValue
  2151. [2022-06-17 08:44:54.972527] result : WERR_OK
  2152. [2022-06-17 08:44:54.974235] winreg_SetValue: struct winreg_SetValue
  2153. [2022-06-17 08:44:54.975875] in: struct winreg_SetValue
  2154. [2022-06-17 08:44:54.977517] handle : *
  2155. [2022-06-17 08:44:54.979141] handle: struct policy_handle
  2156. [2022-06-17 08:44:54.991108] handle_type : 0x00000001 (1)
  2157. [2022-06-17 08:44:54.993026] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2158. [2022-06-17 08:44:54.994643] name: struct winreg_String
  2159. [2022-06-17 08:44:54.996314] name_len : 0x001a (26)
  2160. [2022-06-17 08:44:54.998077] name_size : 0x001a (26)
  2161. [2022-06-17 08:44:54.999629] name : *
  2162. [2022-06-17 08:44:55.001372] name : 'ErrorControl'
  2163. [2022-06-17 08:44:55.003055] type : REG_DWORD (4)
  2164. [2022-06-17 08:44:55.004594] data : *
  2165. [2022-06-17 08:44:55.006232] data: ARRAY(4)
  2166. [2022-06-17 08:44:55.007879] [0] : 0x01 (1)
  2167. [2022-06-17 08:44:55.009512] [1] : 0x00 (0)
  2168. [2022-06-17 08:44:55.011160] [2] : 0x00 (0)
  2169. [2022-06-17 08:44:55.012797] [3] : 0x00 (0)
  2170. [2022-06-17 08:44:55.014784] size : 0x00000004 (4)
  2171. [2022-06-17 08:44:55.016462] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:ErrorControl]
  2172. [2022-06-17 08:44:55.018030] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2173. [2022-06-17 08:44:55.019688] winreg_SetValue: struct winreg_SetValue
  2174. [2022-06-17 08:44:55.021401] out: struct winreg_SetValue
  2175. [2022-06-17 08:44:55.023086] result : WERR_OK
  2176. [2022-06-17 08:44:55.024634] winreg_SetValue: struct winreg_SetValue
  2177. [2022-06-17 08:44:55.026280] in: struct winreg_SetValue
  2178. [2022-06-17 08:44:55.027914] handle : *
  2179. [2022-06-17 08:44:55.029540] handle: struct policy_handle
  2180. [2022-06-17 08:44:55.031177] handle_type : 0x00000001 (1)
  2181. [2022-06-17 08:44:55.032966] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2182. [2022-06-17 08:44:55.034641] name: struct winreg_String
  2183. [2022-06-17 08:44:55.036183] name_len : 0x0016 (22)
  2184. [2022-06-17 08:44:55.037819] name_size : 0x0016 (22)
  2185. [2022-06-17 08:44:55.039456] name : *
  2186. [2022-06-17 08:44:55.041083] name : 'ObjectName'
  2187. [2022-06-17 08:44:55.042720] type : REG_SZ (1)
  2188. [2022-06-17 08:44:55.044512] data : *
  2189. [2022-06-17 08:44:55.046036] data: ARRAY(24)
  2190. [2022-06-17 08:44:55.047679] [0] : 0x4c (76)
  2191. [2022-06-17 08:44:55.054263] [1] : 0x00 (0)
  2192. [2022-06-17 08:44:55.062983] [2] : 0x6f (111)
  2193. [2022-06-17 08:44:55.064904] [3] : 0x00 (0)
  2194. [2022-06-17 08:44:55.066499] [4] : 0x63 (99)
  2195. [2022-06-17 08:44:55.068165] [5] : 0x00 (0)
  2196. [2022-06-17 08:44:55.069821] [6] : 0x61 (97)
  2197. [2022-06-17 08:44:55.071471] [7] : 0x00 (0)
  2198. [2022-06-17 08:44:55.073293] [8] : 0x6c (108)
  2199. [2022-06-17 08:44:55.074852] [9] : 0x00 (0)
  2200. [2022-06-17 08:44:55.078643] [10] : 0x53 (83)
  2201. [2022-06-17 08:44:55.080359] [11] : 0x00 (0)
  2202. [2022-06-17 08:44:55.082020] [12] : 0x79 (121)
  2203. [2022-06-17 08:44:55.083726] [13] : 0x00 (0)
  2204. [2022-06-17 08:44:55.085412] [14] : 0x73 (115)
  2205. [2022-06-17 08:44:55.087064] [15] : 0x00 (0)
  2206. [2022-06-17 08:44:55.088706] [16] : 0x74 (116)
  2207. [2022-06-17 08:44:55.090353] [17] : 0x00 (0)
  2208. [2022-06-17 08:44:55.091993] [18] : 0x65 (101)
  2209. [2022-06-17 08:44:55.093681] [19] : 0x00 (0)
  2210. [2022-06-17 08:44:55.095433] [20] : 0x6d (109)
  2211. [2022-06-17 08:44:55.096966] [21] : 0x00 (0)
  2212. [2022-06-17 08:44:55.098742] [22] : 0x00 (0)
  2213. [2022-06-17 08:44:55.100281] [23] : 0x00 (0)
  2214. [2022-06-17 08:44:55.102027] size : 0x00000018 (24)
  2215. [2022-06-17 08:44:55.103713] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:ObjectName]
  2216. [2022-06-17 08:44:55.105369] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2217. [2022-06-17 08:44:55.106904] winreg_SetValue: struct winreg_SetValue
  2218. [2022-06-17 08:44:55.108542] out: struct winreg_SetValue
  2219. [2022-06-17 08:44:55.110185] result : WERR_OK
  2220. [2022-06-17 08:44:55.111826] winreg_SetValue: struct winreg_SetValue
  2221. [2022-06-17 08:44:55.113550] in: struct winreg_SetValue
  2222. [2022-06-17 08:44:55.115199] handle : *
  2223. [2022-06-17 08:44:55.116837] handle: struct policy_handle
  2224. [2022-06-17 08:44:55.118577] handle_type : 0x00000001 (1)
  2225. [2022-06-17 08:44:55.120116] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2226. [2022-06-17 08:44:55.121765] name: struct winreg_String
  2227. [2022-06-17 08:44:55.123457] name_len : 0x0018 (24)
  2228. [2022-06-17 08:44:55.125112] name_size : 0x0018 (24)
  2229. [2022-06-17 08:44:55.126760] name : *
  2230. [2022-06-17 08:44:55.128513] name : 'DisplayName'
  2231. [2022-06-17 08:44:55.130044] type : REG_SZ (1)
  2232. [2022-06-17 08:44:55.131680] data : *
  2233. [2022-06-17 08:44:55.133361] data: ARRAY(28)
  2234. [2022-06-17 08:44:55.135006] [0] : 0x50 (80)
  2235. [2022-06-17 08:44:55.136658] [1] : 0x00 (0)
  2236. [2022-06-17 08:44:55.138293] [2] : 0x72 (114)
  2237. [2022-06-17 08:44:55.139920] [3] : 0x00 (0)
  2238. [2022-06-17 08:44:55.141551] [4] : 0x69 (105)
  2239. [2022-06-17 08:44:55.143366] [5] : 0x00 (0)
  2240. [2022-06-17 08:44:55.145015] [6] : 0x6e (110)
  2241. [2022-06-17 08:44:55.146560] [7] : 0x00 (0)
  2242. [2022-06-17 08:44:55.148196] [8] : 0x74 (116)
  2243. [2022-06-17 08:44:55.149846] [9] : 0x00 (0)
  2244. [2022-06-17 08:44:55.151480] [10] : 0x20 (32)
  2245. [2022-06-17 08:44:55.153262] [11] : 0x00 (0)
  2246. [2022-06-17 08:44:55.154810] [12] : 0x53 (83)
  2247. [2022-06-17 08:44:55.156473] [13] : 0x00 (0)
  2248. [2022-06-17 08:44:55.158112] [14] : 0x70 (112)
  2249. [2022-06-17 08:44:55.159757] [15] : 0x00 (0)
  2250. [2022-06-17 08:44:55.161393] [16] : 0x6f (111)
  2251. [2022-06-17 08:44:55.163072] [17] : 0x00 (0)
  2252. [2022-06-17 08:44:55.164727] [18] : 0x6f (111)
  2253. [2022-06-17 08:44:55.166356] [19] : 0x00 (0)
  2254. [2022-06-17 08:44:55.167984] [20] : 0x6c (108)
  2255. [2022-06-17 08:44:55.169634] [21] : 0x00 (0)
  2256. [2022-06-17 08:44:55.171281] [22] : 0x65 (101)
  2257. [2022-06-17 08:44:55.173061] [23] : 0x00 (0)
  2258. [2022-06-17 08:44:55.174716] [24] : 0x72 (114)
  2259. [2022-06-17 08:44:55.176243] [25] : 0x00 (0)
  2260. [2022-06-17 08:44:55.177983] [26] : 0x00 (0)
  2261. [2022-06-17 08:44:55.179513] [27] : 0x00 (0)
  2262. [2022-06-17 08:44:55.181150] size : 0x0000001c (28)
  2263. [2022-06-17 08:44:55.182790] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:DisplayName]
  2264. [2022-06-17 08:44:55.184556] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2265. [2022-06-17 08:44:55.186213] winreg_SetValue: struct winreg_SetValue
  2266. [2022-06-17 08:44:55.187850] out: struct winreg_SetValue
  2267. [2022-06-17 08:44:55.189478] result : WERR_OK
  2268. [2022-06-17 08:44:55.191203] winreg_SetValue: struct winreg_SetValue
  2269. [2022-06-17 08:44:55.192723] in: struct winreg_SetValue
  2270. [2022-06-17 08:44:55.194508] handle : *
  2271. [2022-06-17 08:44:55.196035] handle: struct policy_handle
  2272. [2022-06-17 08:44:55.197681] handle_type : 0x00000001 (1)
  2273. [2022-06-17 08:44:55.199336] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2274. [2022-06-17 08:44:55.201073] name: struct winreg_String
  2275. [2022-06-17 08:44:55.202587] name_len : 0x0014 (20)
  2276. [2022-06-17 08:44:55.204262] name_size : 0x0014 (20)
  2277. [2022-06-17 08:44:55.206005] name : *
  2278. [2022-06-17 08:44:55.207538] name : 'ImagePath'
  2279. [2022-06-17 08:44:55.209190] type : REG_SZ (1)
  2280. [2022-06-17 08:44:55.210940] data : *
  2281. [2022-06-17 08:44:55.212467] data: ARRAY(54)
  2282. [2022-06-17 08:44:55.214155] [0] : 0x2f (47)
  2283. [2022-06-17 08:44:55.215798] [1] : 0x00 (0)
  2284. [2022-06-17 08:44:55.217435] [2] : 0x75 (117)
  2285. [2022-06-17 08:44:55.219067] [3] : 0x00 (0)
  2286. [2022-06-17 08:44:55.220901] [4] : 0x73 (115)
  2287. [2022-06-17 08:44:55.222665] [5] : 0x00 (0)
  2288. [2022-06-17 08:44:55.224260] [6] : 0x72 (114)
  2289. [2022-06-17 08:44:55.226016] [7] : 0x00 (0)
  2290. [2022-06-17 08:44:55.227673] [8] : 0x2f (47)
  2291. [2022-06-17 08:44:55.229426] [9] : 0x00 (0)
  2292. [2022-06-17 08:44:55.230962] [10] : 0x6c (108)
  2293. [2022-06-17 08:44:55.232715] [11] : 0x00 (0)
  2294. [2022-06-17 08:44:55.234314] [12] : 0x69 (105)
  2295. [2022-06-17 08:44:55.235969] [13] : 0x00 (0)
  2296. [2022-06-17 08:44:55.237597] [14] : 0x62 (98)
  2297. [2022-06-17 08:44:55.239237] [15] : 0x00 (0)
  2298. [2022-06-17 08:44:55.240969] [16] : 0x2f (47)
  2299. [2022-06-17 08:44:55.242603] [17] : 0x00 (0)
  2300. [2022-06-17 08:44:55.244316] [18] : 0x73 (115)
  2301. [2022-06-17 08:44:55.245860] [19] : 0x00 (0)
  2302. [2022-06-17 08:44:55.247504] [20] : 0x61 (97)
  2303. [2022-06-17 08:44:55.249256] [21] : 0x00 (0)
  2304. [2022-06-17 08:44:55.250781] [22] : 0x6d (109)
  2305. [2022-06-17 08:44:55.252514] [23] : 0x00 (0)
  2306. [2022-06-17 08:44:55.254122] [24] : 0x62 (98)
  2307. [2022-06-17 08:44:55.263380] [25] : 0x00 (0)
  2308. [2022-06-17 08:44:55.265154] [26] : 0x61 (97)
  2309. [2022-06-17 08:44:55.266910] [27] : 0x00 (0)
  2310. [2022-06-17 08:44:55.269123] [28] : 0x2f (47)
  2311. [2022-06-17 08:44:55.274832] [29] : 0x00 (0)
  2312. [2022-06-17 08:44:55.276485] [30] : 0x73 (115)
  2313. [2022-06-17 08:44:55.278020] [31] : 0x00 (0)
  2314. [2022-06-17 08:44:55.279694] [32] : 0x76 (118)
  2315. [2022-06-17 08:44:55.281473] [33] : 0x00 (0)
  2316. [2022-06-17 08:44:55.283058] [34] : 0x63 (99)
  2317. [2022-06-17 08:44:55.284710] [35] : 0x00 (0)
  2318. [2022-06-17 08:44:55.286352] [36] : 0x63 (99)
  2319. [2022-06-17 08:44:55.287993] [37] : 0x00 (0)
  2320. [2022-06-17 08:44:55.289753] [38] : 0x74 (116)
  2321. [2022-06-17 08:44:55.291278] [39] : 0x00 (0)
  2322. [2022-06-17 08:44:55.292773] [40] : 0x6c (108)
  2323. [2022-06-17 08:44:55.294609] [41] : 0x00 (0)
  2324. [2022-06-17 08:44:55.296248] [42] : 0x2f (47)
  2325. [2022-06-17 08:44:55.297779] [43] : 0x00 (0)
  2326. [2022-06-17 08:44:55.299411] [44] : 0x73 (115)
  2327. [2022-06-17 08:44:55.301038] [45] : 0x00 (0)
  2328. [2022-06-17 08:44:55.302664] [46] : 0x6d (109)
  2329. [2022-06-17 08:44:55.304474] [47] : 0x00 (0)
  2330. [2022-06-17 08:44:55.306118] [48] : 0x62 (98)
  2331. [2022-06-17 08:44:55.307658] [49] : 0x00 (0)
  2332. [2022-06-17 08:44:55.309294] [50] : 0x64 (100)
  2333. [2022-06-17 08:44:55.310930] [51] : 0x00 (0)
  2334. [2022-06-17 08:44:55.312560] [52] : 0x00 (0)
  2335. [2022-06-17 08:44:55.314253] [53] : 0x00 (0)
  2336. [2022-06-17 08:44:55.316013] size : 0x00000036 (54)
  2337. [2022-06-17 08:44:55.317559] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:ImagePath]
  2338. [2022-06-17 08:44:55.319342] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2339. [2022-06-17 08:44:55.320980] winreg_SetValue: struct winreg_SetValue
  2340. [2022-06-17 08:44:55.322601] out: struct winreg_SetValue
  2341. [2022-06-17 08:44:55.324312] result : WERR_OK
  2342. [2022-06-17 08:44:55.325957] winreg_SetValue: struct winreg_SetValue
  2343. [2022-06-17 08:44:55.327478] in: struct winreg_SetValue
  2344. [2022-06-17 08:44:55.329198] handle : *
  2345. [2022-06-17 08:44:55.330723] handle: struct policy_handle
  2346. [2022-06-17 08:44:55.332371] handle_type : 0x00000001 (1)
  2347. [2022-06-17 08:44:55.334094] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2348. [2022-06-17 08:44:55.335764] name: struct winreg_String
  2349. [2022-06-17 08:44:55.337500] name_len : 0x0018 (24)
  2350. [2022-06-17 08:44:55.339028] name_size : 0x0018 (24)
  2351. [2022-06-17 08:44:55.340677] name : *
  2352. [2022-06-17 08:44:55.342322] name : 'Description'
  2353. [2022-06-17 08:44:55.344078] type : REG_SZ (1)
  2354. [2022-06-17 08:44:55.345589] data : *
  2355. [2022-06-17 08:44:55.347078] data: ARRAY(106)
  2356. [2022-06-17 08:44:55.348670] [0] : 0x49 (73)
  2357. [2022-06-17 08:44:55.350424] [1] : 0x00 (0)
  2358. [2022-06-17 08:44:55.351957] [2] : 0x6e (110)
  2359. [2022-06-17 08:44:55.353660] [3] : 0x00 (0)
  2360. [2022-06-17 08:44:55.355333] [4] : 0x74 (116)
  2361. [2022-06-17 08:44:55.356978] [5] : 0x00 (0)
  2362. [2022-06-17 08:44:55.358714] [6] : 0x65 (101)
  2363. [2022-06-17 08:44:55.360247] [7] : 0x00 (0)
  2364. [2022-06-17 08:44:55.361888] [8] : 0x72 (114)
  2365. [2022-06-17 08:44:55.363690] [9] : 0x00 (0)
  2366. [2022-06-17 08:44:55.365342] [10] : 0x6e (110)
  2367. [2022-06-17 08:44:55.366980] [11] : 0x00 (0)
  2368. [2022-06-17 08:44:55.368518] [12] : 0x61 (97)
  2369. [2022-06-17 08:44:55.370156] [13] : 0x00 (0)
  2370. [2022-06-17 08:44:55.371789] [14] : 0x6c (108)
  2371. [2022-06-17 08:44:55.373478] [15] : 0x00 (0)
  2372. [2022-06-17 08:44:55.375233] [16] : 0x20 (32)
  2373. [2022-06-17 08:44:55.376769] [17] : 0x00 (0)
  2374. [2022-06-17 08:44:55.378528] [18] : 0x73 (115)
  2375. [2022-06-17 08:44:55.380066] [19] : 0x00 (0)
  2376. [2022-06-17 08:44:55.381716] [20] : 0x65 (101)
  2377. [2022-06-17 08:44:55.383261] [21] : 0x00 (0)
  2378. [2022-06-17 08:44:55.384969] [22] : 0x72 (114)
  2379. [2022-06-17 08:44:55.386619] [23] : 0x00 (0)
  2380. [2022-06-17 08:44:55.388146] [24] : 0x76 (118)
  2381. [2022-06-17 08:44:55.389798] [25] : 0x00 (0)
  2382. [2022-06-17 08:44:55.391534] [26] : 0x69 (105)
  2383. [2022-06-17 08:44:55.393118] [27] : 0x00 (0)
  2384. [2022-06-17 08:44:55.394787] [28] : 0x63 (99)
  2385. [2022-06-17 08:44:55.396537] [29] : 0x00 (0)
  2386. [2022-06-17 08:44:55.398062] [30] : 0x65 (101)
  2387. [2022-06-17 08:44:55.399702] [31] : 0x00 (0)
  2388. [2022-06-17 08:44:55.401450] [32] : 0x20 (32)
  2389. [2022-06-17 08:44:55.403132] [33] : 0x00 (0)
  2390. [2022-06-17 08:44:55.404684] [34] : 0x66 (102)
  2391. [2022-06-17 08:44:55.406325] [35] : 0x00 (0)
  2392. [2022-06-17 08:44:55.407975] [36] : 0x6f (111)
  2393. [2022-06-17 08:44:55.409620] [37] : 0x00 (0)
  2394. [2022-06-17 08:44:55.411250] [38] : 0x72 (114)
  2395. [2022-06-17 08:44:55.413022] [39] : 0x00 (0)
  2396. [2022-06-17 08:44:55.414671] [40] : 0x20 (32)
  2397. [2022-06-17 08:44:55.416197] [41] : 0x00 (0)
  2398. [2022-06-17 08:44:55.417833] [42] : 0x73 (115)
  2399. [2022-06-17 08:44:55.419472] [43] : 0x00 (0)
  2400. [2022-06-17 08:44:55.421101] [44] : 0x70 (112)
  2401. [2022-06-17 08:44:55.422757] [45] : 0x00 (0)
  2402. [2022-06-17 08:44:55.424547] [46] : 0x6f (111)
  2403. [2022-06-17 08:44:55.426188] [47] : 0x00 (0)
  2404. [2022-06-17 08:44:55.427724] [48] : 0x6f (111)
  2405. [2022-06-17 08:44:55.429368] [49] : 0x00 (0)
  2406. [2022-06-17 08:44:55.431012] [50] : 0x6c (108)
  2407. [2022-06-17 08:44:55.432739] [51] : 0x00 (0)
  2408. [2022-06-17 08:44:55.434427] [52] : 0x69 (105)
  2409. [2022-06-17 08:44:55.435967] [53] : 0x00 (0)
  2410. [2022-06-17 08:44:55.437612] [54] : 0x6e (110)
  2411. [2022-06-17 08:44:55.439253] [55] : 0x00 (0)
  2412. [2022-06-17 08:44:55.440998] [56] : 0x67 (103)
  2413. [2022-06-17 08:44:55.442518] [57] : 0x00 (0)
  2414. [2022-06-17 08:44:55.444232] [58] : 0x20 (32)
  2415. [2022-06-17 08:44:55.445976] [59] : 0x00 (0)
  2416. [2022-06-17 08:44:55.447498] [60] : 0x66 (102)
  2417. [2022-06-17 08:44:55.449137] [61] : 0x00 (0)
  2418. [2022-06-17 08:44:55.450897] [62] : 0x69 (105)
  2419. [2022-06-17 08:44:55.452520] [63] : 0x00 (0)
  2420. [2022-06-17 08:44:55.454132] [64] : 0x6c (108)
  2421. [2022-06-17 08:44:55.455897] [65] : 0x00 (0)
  2422. [2022-06-17 08:44:55.457519] [66] : 0x65 (101)
  2423. [2022-06-17 08:44:55.459049] [67] : 0x00 (0)
  2424. [2022-06-17 08:44:55.460685] [68] : 0x73 (115)
  2425. [2022-06-17 08:44:55.462325] [69] : 0x00 (0)
  2426. [2022-06-17 08:44:55.464055] [70] : 0x20 (32)
  2427. [2022-06-17 08:44:55.465708] [71] : 0x00 (0)
  2428. [2022-06-17 08:44:55.467339] [72] : 0x74 (116)
  2429. [2022-06-17 08:44:55.469074] [73] : 0x00 (0)
  2430. [2022-06-17 08:44:55.470592] [74] : 0x6f (111)
  2431. [2022-06-17 08:44:55.472232] [75] : 0x00 (0)
  2432. [2022-06-17 08:44:55.474061] [76] : 0x20 (32)
  2433. [2022-06-17 08:44:55.475601] [77] : 0x00 (0)
  2434. [2022-06-17 08:44:55.477243] [78] : 0x70 (112)
  2435. [2022-06-17 08:44:55.478986] [79] : 0x00 (0)
  2436. [2022-06-17 08:44:55.480512] [80] : 0x72 (114)
  2437. [2022-06-17 08:44:55.482148] [81] : 0x00 (0)
  2438. [2022-06-17 08:44:55.483943] [82] : 0x69 (105)
  2439. [2022-06-17 08:44:55.485487] [83] : 0x00 (0)
  2440. [2022-06-17 08:44:55.487135] [84] : 0x6e (110)
  2441. [2022-06-17 08:44:55.488788] [85] : 0x00 (0)
  2442. [2022-06-17 08:44:55.490529] [86] : 0x74 (116)
  2443. [2022-06-17 08:44:55.492065] [87] : 0x00 (0)
  2444. [2022-06-17 08:44:55.493747] [88] : 0x20 (32)
  2445. [2022-06-17 08:44:55.495257] [89] : 0x00 (0)
  2446. [2022-06-17 08:44:55.496921] [90] : 0x64 (100)
  2447. [2022-06-17 08:44:55.498580] [91] : 0x00 (0)
  2448. [2022-06-17 08:44:55.500219] [92] : 0x65 (101)
  2449. [2022-06-17 08:44:55.501853] [93] : 0x00 (0)
  2450. [2022-06-17 08:44:55.503551] [94] : 0x76 (118)
  2451. [2022-06-17 08:44:55.505194] [95] : 0x00 (0)
  2452. [2022-06-17 08:44:55.512985] [96] : 0x69 (105)
  2453. [2022-06-17 08:44:55.514711] [97] : 0x00 (0)
  2454. [2022-06-17 08:44:55.516561] [98] : 0x63 (99)
  2455. [2022-06-17 08:44:55.522985] [99] : 0x00 (0)
  2456. [2022-06-17 08:44:55.524808] [100] : 0x65 (101)
  2457. [2022-06-17 08:44:55.526402] [101] : 0x00 (0)
  2458. [2022-06-17 08:44:55.528056] [102] : 0x73 (115)
  2459. [2022-06-17 08:44:55.529821] [103] : 0x00 (0)
  2460. [2022-06-17 08:44:55.531772] [104] : 0x00 (0)
  2461. [2022-06-17 08:44:55.533503] [105] : 0x00 (0)
  2462. [2022-06-17 08:44:55.535181] size : 0x0000006a (106)
  2463. [2022-06-17 08:44:55.536721] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler:Description]
  2464. [2022-06-17 08:44:55.538402] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2465. [2022-06-17 08:44:55.540048] winreg_SetValue: struct winreg_SetValue
  2466. [2022-06-17 08:44:55.541678] out: struct winreg_SetValue
  2467. [2022-06-17 08:44:55.543371] result : WERR_OK
  2468. [2022-06-17 08:44:55.544881] winreg_CloseKey: struct winreg_CloseKey
  2469. [2022-06-17 08:44:55.546391] in: struct winreg_CloseKey
  2470. [2022-06-17 08:44:55.548037] handle : *
  2471. [2022-06-17 08:44:55.550197] handle: struct policy_handle
  2472. [2022-06-17 08:44:55.552365] handle_type : 0x00000001 (1)
  2473. [2022-06-17 08:44:55.554673] uuid : 6ba549c9-3717-479f-bc41-450a66b25f4b
  2474. [2022-06-17 08:44:55.556257] regdb_close: decrementing refcount (4->3)
  2475. [2022-06-17 08:44:55.558284] winreg_CloseKey: struct winreg_CloseKey
  2476. [2022-06-17 08:44:55.560971] out: struct winreg_CloseKey
  2477. [2022-06-17 08:44:55.563103] handle : *
  2478. [2022-06-17 08:44:55.565015] handle: struct policy_handle
  2479. [2022-06-17 08:44:55.566706] handle_type : 0x00000000 (0)
  2480. [2022-06-17 08:44:55.568487] uuid : 00000000-0000-0000-0000-000000000000
  2481. [2022-06-17 08:44:55.570032] result : WERR_OK
  2482. [2022-06-17 08:44:55.571675] winreg_CreateKey: struct winreg_CreateKey
  2483. [2022-06-17 08:44:55.573467] in: struct winreg_CreateKey
  2484. [2022-06-17 08:44:55.575011] handle : *
  2485. [2022-06-17 08:44:55.576656] handle: struct policy_handle
  2486. [2022-06-17 08:44:55.579016] handle_type : 0x00000001 (1)
  2487. [2022-06-17 08:44:55.580597] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  2488. [2022-06-17 08:44:55.582266] name: struct winreg_String
  2489. [2022-06-17 08:44:55.583990] name_len : 0x0066 (102)
  2490. [2022-06-17 08:44:55.585651] name_size : 0x0066 (102)
  2491. [2022-06-17 08:44:55.587311] name : *
  2492. [2022-06-17 08:44:55.589057] name : 'SYSTEM\CurrentControlSet\Services\Spooler\Security'
  2493. [2022-06-17 08:44:55.590720] keyclass: struct winreg_String
  2494. [2022-06-17 08:44:55.592236] name_len : 0x0002 (2)
  2495. [2022-06-17 08:44:55.594054] name_size : 0x0002 (2)
  2496. [2022-06-17 08:44:55.595701] name : *
  2497. [2022-06-17 08:44:55.597244] name : ''
  2498. [2022-06-17 08:44:55.598992] options : 0x00000000 (0)
  2499. [2022-06-17 08:44:55.600522] 0: REG_OPTION_VOLATILE
  2500. [2022-06-17 08:44:55.602169] 0: REG_OPTION_CREATE_LINK
  2501. [2022-06-17 08:44:55.603871] 0: REG_OPTION_BACKUP_RESTORE
  2502. [2022-06-17 08:44:55.605516] 0: REG_OPTION_OPEN_LINK
  2503. [2022-06-17 08:44:55.607253] access_mask : 0x02000000 (33554432)
  2504. [2022-06-17 08:44:55.608898] 0: KEY_QUERY_VALUE
  2505. [2022-06-17 08:44:55.610534] 0: KEY_SET_VALUE
  2506. [2022-06-17 08:44:55.612178] 0: KEY_CREATE_SUB_KEY
  2507. [2022-06-17 08:44:55.613863] 0: KEY_ENUMERATE_SUB_KEYS
  2508. [2022-06-17 08:44:55.615508] 0: KEY_NOTIFY
  2509. [2022-06-17 08:44:55.617037] 0: KEY_CREATE_LINK
  2510. [2022-06-17 08:44:55.618669] 0: KEY_WOW64_64KEY
  2511. [2022-06-17 08:44:55.620313] 0: KEY_WOW64_32KEY
  2512. [2022-06-17 08:44:55.622050] secdesc : NULL
  2513. [2022-06-17 08:44:55.623661] action_taken : *
  2514. [2022-06-17 08:44:55.625333] action_taken : REG_OPENED_EXISTING_KEY (2)
  2515. [2022-06-17 08:44:55.627099] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\Spooler\Security'
  2516. [2022-06-17 08:44:55.628656] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2517. [2022-06-17 08:44:55.630300] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2518. [2022-06-17 08:44:55.631951] regkey_open_onelevel: name = [SYSTEM]
  2519. [2022-06-17 08:44:55.633650] regdb_open: incrementing refcount (3->4)
  2520. [2022-06-17 08:44:55.635310] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  2521. [2022-06-17 08:44:55.637067] pathtree_find: Enter [\HKLM\SYSTEM]
  2522. [2022-06-17 08:44:55.638703] pathtree_find: Exit
  2523. [2022-06-17 08:44:55.640219] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  2524. [2022-06-17 08:44:55.641856] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2525. [2022-06-17 08:44:55.643546] regkey_open_onelevel: name = [CurrentControlSet]
  2526. [2022-06-17 08:44:55.645288] regdb_open: incrementing refcount (4->5)
  2527. [2022-06-17 08:44:55.646930] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  2528. [2022-06-17 08:44:55.648473] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  2529. [2022-06-17 08:44:55.650120] pathtree_find: Exit
  2530. [2022-06-17 08:44:55.651731] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  2531. [2022-06-17 08:44:55.653438] regdb_close: decrementing refcount (5->4)
  2532. [2022-06-17 08:44:55.655182] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2533. [2022-06-17 08:44:55.656718] regkey_open_onelevel: name = [Services]
  2534. [2022-06-17 08:44:55.658369] regdb_open: incrementing refcount (4->5)
  2535. [2022-06-17 08:44:55.660004] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  2536. [2022-06-17 08:44:55.661665] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  2537. [2022-06-17 08:44:55.663357] pathtree_find: Exit
  2538. [2022-06-17 08:44:55.665085] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  2539. [2022-06-17 08:44:55.666746] regdb_close: decrementing refcount (5->4)
  2540. [2022-06-17 08:44:55.668278] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2541. [2022-06-17 08:44:55.670027] regkey_open_onelevel: name = [Spooler]
  2542. [2022-06-17 08:44:55.671552] regdb_open: incrementing refcount (4->5)
  2543. [2022-06-17 08:44:55.673246] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2544. [2022-06-17 08:44:55.674921] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2545. [2022-06-17 08:44:55.676574] pathtree_find: Exit
  2546. [2022-06-17 08:44:55.678273] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
  2547. [2022-06-17 08:44:55.679823] regdb_close: decrementing refcount (5->4)
  2548. [2022-06-17 08:44:55.681312] regkey_open_onelevel: name = [Security]
  2549. [2022-06-17 08:44:55.682808] regdb_open: incrementing refcount (4->5)
  2550. [2022-06-17 08:44:55.684365] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
  2551. [2022-06-17 08:44:55.685889] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
  2552. [2022-06-17 08:44:55.687613] pathtree_find: Exit
  2553. [2022-06-17 08:44:55.689103] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
  2554. [2022-06-17 08:44:55.690625] regdb_close: decrementing refcount (5->4)
  2555. [2022-06-17 08:44:55.692374] winreg_CreateKey: struct winreg_CreateKey
  2556. [2022-06-17 08:44:55.694088] out: struct winreg_CreateKey
  2557. [2022-06-17 08:44:55.695624] new_handle : *
  2558. [2022-06-17 08:44:55.697255] new_handle: struct policy_handle
  2559. [2022-06-17 08:44:55.698894] handle_type : 0x00000001 (1)
  2560. [2022-06-17 08:44:55.700541] uuid : 7ed948d4-fcd0-4fb7-8f39-cb4d83b52b26
  2561. [2022-06-17 08:44:55.702192] action_taken : *
  2562. [2022-06-17 08:44:55.703908] action_taken : REG_OPENED_EXISTING_KEY (2)
  2563. [2022-06-17 08:44:55.705559] result : WERR_OK
  2564. [2022-06-17 08:44:55.707337] winreg_SetValue: struct winreg_SetValue
  2565. [2022-06-17 08:44:55.708971] in: struct winreg_SetValue
  2566. [2022-06-17 08:44:55.710493] handle : *
  2567. [2022-06-17 08:44:55.711983] handle: struct policy_handle
  2568. [2022-06-17 08:44:55.713703] handle_type : 0x00000001 (1)
  2569. [2022-06-17 08:44:55.715343] uuid : 7ed948d4-fcd0-4fb7-8f39-cb4d83b52b26
  2570. [2022-06-17 08:44:55.716883] name: struct winreg_String
  2571. [2022-06-17 08:44:55.718518] name_len : 0x0012 (18)
  2572. [2022-06-17 08:44:55.720169] name_size : 0x0012 (18)
  2573. [2022-06-17 08:44:55.721815] name : *
  2574. [2022-06-17 08:44:55.723615] name : 'Security'
  2575. [2022-06-17 08:44:55.725152] type : REG_BINARY (3)
  2576. [2022-06-17 08:44:55.726794] data : *
  2577. [2022-06-17 08:44:55.728285] data: ARRAY(120)
  2578. [2022-06-17 08:44:55.729909] [0] : 0x01 (1)
  2579. [2022-06-17 08:44:55.731661] [1] : 0x00 (0)
  2580. [2022-06-17 08:44:55.733249] [2] : 0x04 (4)
  2581. [2022-06-17 08:44:55.734917] [3] : 0x80 (128)
  2582. [2022-06-17 08:44:55.736555] [4] : 0x00 (0)
  2583. [2022-06-17 08:44:55.738210] [5] : 0x00 (0)
  2584. [2022-06-17 08:44:55.739842] [6] : 0x00 (0)
  2585. [2022-06-17 08:44:55.741580] [7] : 0x00 (0)
  2586. [2022-06-17 08:44:55.743164] [8] : 0x00 (0)
  2587. [2022-06-17 08:44:55.744935] [9] : 0x00 (0)
  2588. [2022-06-17 08:44:55.746476] [10] : 0x00 (0)
  2589. [2022-06-17 08:44:55.748219] [11] : 0x00 (0)
  2590. [2022-06-17 08:44:55.749848] [12] : 0x00 (0)
  2591. [2022-06-17 08:44:55.751375] [13] : 0x00 (0)
  2592. [2022-06-17 08:44:55.753054] [14] : 0x00 (0)
  2593. [2022-06-17 08:44:55.754706] [15] : 0x00 (0)
  2594. [2022-06-17 08:44:55.756357] [16] : 0x14 (20)
  2595. [2022-06-17 08:44:55.758004] [17] : 0x00 (0)
  2596. [2022-06-17 08:44:55.759637] [18] : 0x00 (0)
  2597. [2022-06-17 08:44:55.761281] [19] : 0x00 (0)
  2598. [2022-06-17 08:44:55.763058] [20] : 0x02 (2)
  2599. [2022-06-17 08:44:55.764598] [21] : 0x00 (0)
  2600. [2022-06-17 08:44:55.766260] [22] : 0x64 (100)
  2601. [2022-06-17 08:44:55.767911] [23] : 0x00 (0)
  2602. [2022-06-17 08:44:55.769546] [24] : 0x04 (4)
  2603. [2022-06-17 08:44:55.781500] [25] : 0x00 (0)
  2604. [2022-06-17 08:44:55.783364] [26] : 0x00 (0)
  2605. [2022-06-17 08:44:55.785043] [27] : 0x00 (0)
  2606. [2022-06-17 08:44:55.786699] [28] : 0x00 (0)
  2607. [2022-06-17 08:44:55.788232] [29] : 0x00 (0)
  2608. [2022-06-17 08:44:55.789891] [30] : 0x14 (20)
  2609. [2022-06-17 08:44:55.791533] [31] : 0x00 (0)
  2610. [2022-06-17 08:44:55.793222] [32] : 0x8d (141)
  2611. [2022-06-17 08:44:55.794733] [33] : 0x01 (1)
  2612. [2022-06-17 08:44:55.796462] [34] : 0x02 (2)
  2613. [2022-06-17 08:44:55.798087] [35] : 0x00 (0)
  2614. [2022-06-17 08:44:55.799608] [36] : 0x01 (1)
  2615. [2022-06-17 08:44:55.801248] [37] : 0x01 (1)
  2616. [2022-06-17 08:44:55.803037] [38] : 0x00 (0)
  2617. [2022-06-17 08:44:55.804585] [39] : 0x00 (0)
  2618. [2022-06-17 08:44:55.806239] [40] : 0x00 (0)
  2619. [2022-06-17 08:44:55.807883] [41] : 0x00 (0)
  2620. [2022-06-17 08:44:55.809516] [42] : 0x00 (0)
  2621. [2022-06-17 08:44:55.811806] [43] : 0x01 (1)
  2622. [2022-06-17 08:44:55.813623] [44] : 0x00 (0)
  2623. [2022-06-17 08:44:55.815308] [45] : 0x00 (0)
  2624. [2022-06-17 08:44:55.816958] [46] : 0x00 (0)
  2625. [2022-06-17 08:44:55.818602] [47] : 0x00 (0)
  2626. [2022-06-17 08:44:55.820235] [48] : 0x00 (0)
  2627. [2022-06-17 08:44:55.821869] [49] : 0x00 (0)
  2628. [2022-06-17 08:44:55.823547] [50] : 0x18 (24)
  2629. [2022-06-17 08:44:55.825191] [51] : 0x00 (0)
  2630. [2022-06-17 08:44:55.826838] [52] : 0xfd (253)
  2631. [2022-06-17 08:44:55.828480] [53] : 0x01 (1)
  2632. [2022-06-17 08:44:55.830129] [54] : 0x02 (2)
  2633. [2022-06-17 08:44:55.831762] [55] : 0x00 (0)
  2634. [2022-06-17 08:44:55.833455] [56] : 0x01 (1)
  2635. [2022-06-17 08:44:55.835105] [57] : 0x02 (2)
  2636. [2022-06-17 08:44:55.836748] [58] : 0x00 (0)
  2637. [2022-06-17 08:44:55.838380] [59] : 0x00 (0)
  2638. [2022-06-17 08:44:55.840014] [60] : 0x00 (0)
  2639. [2022-06-17 08:44:55.841648] [61] : 0x00 (0)
  2640. [2022-06-17 08:44:55.843360] [62] : 0x00 (0)
  2641. [2022-06-17 08:44:55.845007] [63] : 0x05 (5)
  2642. [2022-06-17 08:44:55.846639] [64] : 0x20 (32)
  2643. [2022-06-17 08:44:55.848280] [65] : 0x00 (0)
  2644. [2022-06-17 08:44:55.849920] [66] : 0x00 (0)
  2645. [2022-06-17 08:44:55.851569] [67] : 0x00 (0)
  2646. [2022-06-17 08:44:55.853267] [68] : 0x23 (35)
  2647. [2022-06-17 08:44:55.854931] [69] : 0x02 (2)
  2648. [2022-06-17 08:44:55.856555] [70] : 0x00 (0)
  2649. [2022-06-17 08:44:55.858196] [71] : 0x00 (0)
  2650. [2022-06-17 08:44:55.859833] [72] : 0x00 (0)
  2651. [2022-06-17 08:44:55.861473] [73] : 0x00 (0)
  2652. [2022-06-17 08:44:55.863167] [74] : 0x18 (24)
  2653. [2022-06-17 08:44:55.864825] [75] : 0x00 (0)
  2654. [2022-06-17 08:44:55.866473] [76] : 0xff (255)
  2655. [2022-06-17 08:44:55.868106] [77] : 0x01 (1)
  2656. [2022-06-17 08:44:55.869738] [78] : 0x0f (15)
  2657. [2022-06-17 08:44:55.871386] [79] : 0x00 (0)
  2658. [2022-06-17 08:44:55.873062] [80] : 0x01 (1)
  2659. [2022-06-17 08:44:55.874722] [81] : 0x02 (2)
  2660. [2022-06-17 08:44:55.876368] [82] : 0x00 (0)
  2661. [2022-06-17 08:44:55.878009] [83] : 0x00 (0)
  2662. [2022-06-17 08:44:55.879657] [84] : 0x00 (0)
  2663. [2022-06-17 08:44:55.881297] [85] : 0x00 (0)
  2664. [2022-06-17 08:44:55.882974] [86] : 0x00 (0)
  2665. [2022-06-17 08:44:55.884629] [87] : 0x05 (5)
  2666. [2022-06-17 08:44:55.886282] [88] : 0x20 (32)
  2667. [2022-06-17 08:44:55.887937] [89] : 0x00 (0)
  2668. [2022-06-17 08:44:55.889570] [90] : 0x00 (0)
  2669. [2022-06-17 08:44:55.891200] [91] : 0x00 (0)
  2670. [2022-06-17 08:44:55.892832] [92] : 0x25 (37)
  2671. [2022-06-17 08:44:55.894523] [93] : 0x02 (2)
  2672. [2022-06-17 08:44:55.896162] [94] : 0x00 (0)
  2673. [2022-06-17 08:44:55.897792] [95] : 0x00 (0)
  2674. [2022-06-17 08:44:55.899437] [96] : 0x00 (0)
  2675. [2022-06-17 08:44:55.901081] [97] : 0x00 (0)
  2676. [2022-06-17 08:44:55.902716] [98] : 0x18 (24)
  2677. [2022-06-17 08:44:55.904554] [99] : 0x00 (0)
  2678. [2022-06-17 08:44:55.906207] [100] : 0xff (255)
  2679. [2022-06-17 08:44:55.907842] [101] : 0x01 (1)
  2680. [2022-06-17 08:44:55.909480] [102] : 0x0f (15)
  2681. [2022-06-17 08:44:55.911115] [103] : 0x00 (0)
  2682. [2022-06-17 08:44:55.912764] [104] : 0x01 (1)
  2683. [2022-06-17 08:44:55.914484] [105] : 0x02 (2)
  2684. [2022-06-17 08:44:55.916133] [106] : 0x00 (0)
  2685. [2022-06-17 08:44:55.917764] [107] : 0x00 (0)
  2686. [2022-06-17 08:44:55.919400] [108] : 0x00 (0)
  2687. [2022-06-17 08:44:55.921041] [109] : 0x00 (0)
  2688. [2022-06-17 08:44:55.922680] [110] : 0x00 (0)
  2689. [2022-06-17 08:44:55.924381] [111] : 0x05 (5)
  2690. [2022-06-17 08:44:55.926019] [112] : 0x20 (32)
  2691. [2022-06-17 08:44:55.927663] [113] : 0x00 (0)
  2692. [2022-06-17 08:44:55.929300] [114] : 0x00 (0)
  2693. [2022-06-17 08:44:55.930932] [115] : 0x00 (0)
  2694. [2022-06-17 08:44:55.932580] [116] : 0x20 (32)
  2695. [2022-06-17 08:44:55.934310] [117] : 0x02 (2)
  2696. [2022-06-17 08:44:55.935961] [118] : 0x00 (0)
  2697. [2022-06-17 08:44:55.937594] [119] : 0x00 (0)
  2698. [2022-06-17 08:44:55.939111] size : 0x00000078 (120)
  2699. [2022-06-17 08:44:55.940613] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security:Security]
  2700. [2022-06-17 08:44:55.942355] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2701. [2022-06-17 08:44:55.943958] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security' (ops 0xb6ab32e8)
  2702. [2022-06-17 08:44:55.945717] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
  2703. [2022-06-17 08:44:55.947405] regdb_unpack_values: value[0]: name[Security] len[120]
  2704. [2022-06-17 08:44:55.949068] winreg_SetValue: struct winreg_SetValue
  2705. [2022-06-17 08:44:55.950711] out: struct winreg_SetValue
  2706. [2022-06-17 08:44:55.952336] result : WERR_OK
  2707. [2022-06-17 08:44:55.954063] winreg_CloseKey: struct winreg_CloseKey
  2708. [2022-06-17 08:44:55.955701] in: struct winreg_CloseKey
  2709. [2022-06-17 08:44:55.957334] handle : *
  2710. [2022-06-17 08:44:55.958968] handle: struct policy_handle
  2711. [2022-06-17 08:44:55.960607] handle_type : 0x00000001 (1)
  2712. [2022-06-17 08:44:55.962248] uuid : 7ed948d4-fcd0-4fb7-8f39-cb4d83b52b26
  2713. [2022-06-17 08:44:55.963946] regdb_close: decrementing refcount (4->3)
  2714. [2022-06-17 08:44:55.965575] winreg_CloseKey: struct winreg_CloseKey
  2715. [2022-06-17 08:44:55.967217] out: struct winreg_CloseKey
  2716. [2022-06-17 08:44:55.968843] handle : *
  2717. [2022-06-17 08:44:55.970468] handle: struct policy_handle
  2718. [2022-06-17 08:44:55.972115] handle_type : 0x00000000 (0)
  2719. [2022-06-17 08:44:55.973809] uuid : 00000000-0000-0000-0000-000000000000
  2720. [2022-06-17 08:44:55.975470] result : WERR_OK
  2721. [2022-06-17 08:44:55.977108] winreg_CreateKey: struct winreg_CreateKey
  2722. [2022-06-17 08:44:55.978729] in: struct winreg_CreateKey
  2723. [2022-06-17 08:44:55.980360] handle : *
  2724. [2022-06-17 08:44:55.981967] handle: struct policy_handle
  2725. [2022-06-17 08:44:55.983672] handle_type : 0x00000001 (1)
  2726. [2022-06-17 08:44:55.985346] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  2727. [2022-06-17 08:44:55.987012] name: struct winreg_String
  2728. [2022-06-17 08:44:55.988526] name_len : 0x0056 (86)
  2729. [2022-06-17 08:44:55.990283] name_size : 0x0056 (86)
  2730. [2022-06-17 08:44:55.991911] name : *
  2731. [2022-06-17 08:44:55.993619] name : 'SYSTEM\CurrentControlSet\Services\NETLOGON'
  2732. [2022-06-17 08:44:55.995163] keyclass: struct winreg_String
  2733. [2022-06-17 08:44:55.996931] name_len : 0x0002 (2)
  2734. [2022-06-17 08:44:55.998549] name_size : 0x0002 (2)
  2735. [2022-06-17 08:44:56.000201] name : *
  2736. [2022-06-17 08:44:56.001834] name : ''
  2737. [2022-06-17 08:44:56.003522] options : 0x00000000 (0)
  2738. [2022-06-17 08:44:56.005172] 0: REG_OPTION_VOLATILE
  2739. [2022-06-17 08:44:56.006805] 0: REG_OPTION_CREATE_LINK
  2740. [2022-06-17 08:44:56.008449] 0: REG_OPTION_BACKUP_RESTORE
  2741. [2022-06-17 08:44:56.010084] 0: REG_OPTION_OPEN_LINK
  2742. [2022-06-17 08:44:56.011728] access_mask : 0x02000000 (33554432)
  2743. [2022-06-17 08:44:56.013415] 0: KEY_QUERY_VALUE
  2744. [2022-06-17 08:44:56.015063] 0: KEY_SET_VALUE
  2745. [2022-06-17 08:44:56.016703] 0: KEY_CREATE_SUB_KEY
  2746. [2022-06-17 08:44:56.018325] 0: KEY_ENUMERATE_SUB_KEYS
  2747. [2022-06-17 08:44:56.019961] 0: KEY_NOTIFY
  2748. [2022-06-17 08:44:56.021605] 0: KEY_CREATE_LINK
  2749. [2022-06-17 08:44:56.023471] 0: KEY_WOW64_64KEY
  2750. [2022-06-17 08:44:56.025165] 0: KEY_WOW64_32KEY
  2751. [2022-06-17 08:44:56.032980] secdesc : NULL
  2752. [2022-06-17 08:44:56.034865] action_taken : *
  2753. [2022-06-17 08:44:56.036555] action_taken : REG_ACTION_NONE (0)
  2754. [2022-06-17 08:44:56.038229] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\NETLOGON'
  2755. [2022-06-17 08:44:56.043517] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2756. [2022-06-17 08:44:56.045295] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2757. [2022-06-17 08:44:56.046990] regkey_open_onelevel: name = [SYSTEM]
  2758. [2022-06-17 08:44:56.050049] regdb_open: incrementing refcount (3->4)
  2759. [2022-06-17 08:44:56.051839] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  2760. [2022-06-17 08:44:56.053586] pathtree_find: Enter [\HKLM\SYSTEM]
  2761. [2022-06-17 08:44:56.055244] pathtree_find: Exit
  2762. [2022-06-17 08:44:56.056873] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  2763. [2022-06-17 08:44:56.058530] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2764. [2022-06-17 08:44:56.060180] regkey_open_onelevel: name = [CurrentControlSet]
  2765. [2022-06-17 08:44:56.061844] regdb_open: incrementing refcount (4->5)
  2766. [2022-06-17 08:44:56.063532] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  2767. [2022-06-17 08:44:56.065190] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  2768. [2022-06-17 08:44:56.066844] pathtree_find: Exit
  2769. [2022-06-17 08:44:56.068476] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  2770. [2022-06-17 08:44:56.070190] regdb_close: decrementing refcount (5->4)
  2771. [2022-06-17 08:44:56.071843] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  2772. [2022-06-17 08:44:56.073545] regkey_open_onelevel: name = [Services]
  2773. [2022-06-17 08:44:56.075183] regdb_open: incrementing refcount (4->5)
  2774. [2022-06-17 08:44:56.076814] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  2775. [2022-06-17 08:44:56.078470] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  2776. [2022-06-17 08:44:56.080111] pathtree_find: Exit
  2777. [2022-06-17 08:44:56.081737] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  2778. [2022-06-17 08:44:56.083430] regdb_close: decrementing refcount (5->4)
  2779. [2022-06-17 08:44:56.085081] regkey_open_onelevel: name = [NETLOGON]
  2780. [2022-06-17 08:44:56.086714] regdb_open: incrementing refcount (4->5)
  2781. [2022-06-17 08:44:56.088342] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  2782. [2022-06-17 08:44:56.089987] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  2783. [2022-06-17 08:44:56.091642] pathtree_find: Exit
  2784. [2022-06-17 08:44:56.093342] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  2785. [2022-06-17 08:44:56.095031] regdb_close: decrementing refcount (5->4)
  2786. [2022-06-17 08:44:56.096672] winreg_CreateKey: struct winreg_CreateKey
  2787. [2022-06-17 08:44:56.098304] out: struct winreg_CreateKey
  2788. [2022-06-17 08:44:56.099925] new_handle : *
  2789. [2022-06-17 08:44:56.101552] new_handle: struct policy_handle
  2790. [2022-06-17 08:44:56.103221] handle_type : 0x00000001 (1)
  2791. [2022-06-17 08:44:56.104881] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2792. [2022-06-17 08:44:56.106553] action_taken : *
  2793. [2022-06-17 08:44:56.108195] action_taken : REG_OPENED_EXISTING_KEY (2)
  2794. [2022-06-17 08:44:56.109844] result : WERR_OK
  2795. [2022-06-17 08:44:56.111365] winreg_SetValue: struct winreg_SetValue
  2796. [2022-06-17 08:44:56.113136] in: struct winreg_SetValue
  2797. [2022-06-17 08:44:56.114790] handle : *
  2798. [2022-06-17 08:44:56.116423] handle: struct policy_handle
  2799. [2022-06-17 08:44:56.118072] handle_type : 0x00000001 (1)
  2800. [2022-06-17 08:44:56.119718] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2801. [2022-06-17 08:44:56.121387] name: struct winreg_String
  2802. [2022-06-17 08:44:56.123054] name_len : 0x000c (12)
  2803. [2022-06-17 08:44:56.124715] name_size : 0x000c (12)
  2804. [2022-06-17 08:44:56.126358] name : *
  2805. [2022-06-17 08:44:56.127881] name : 'Start'
  2806. [2022-06-17 08:44:56.129386] type : REG_DWORD (4)
  2807. [2022-06-17 08:44:56.131115] data : *
  2808. [2022-06-17 08:44:56.132763] data: ARRAY(4)
  2809. [2022-06-17 08:44:56.134491] [0] : 0x02 (2)
  2810. [2022-06-17 08:44:56.136138] [1] : 0x00 (0)
  2811. [2022-06-17 08:44:56.137780] [2] : 0x00 (0)
  2812. [2022-06-17 08:44:56.139414] [3] : 0x00 (0)
  2813. [2022-06-17 08:44:56.141051] size : 0x00000004 (4)
  2814. [2022-06-17 08:44:56.142695] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:Start]
  2815. [2022-06-17 08:44:56.144415] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2816. [2022-06-17 08:44:56.146073] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON' (ops 0xb6ab32e8)
  2817. [2022-06-17 08:44:56.147751] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  2818. [2022-06-17 08:44:56.149401] regdb_unpack_values: value[0]: name[Start] len[4]
  2819. [2022-06-17 08:44:56.151057] regdb_unpack_values: value[1]: name[Type] len[4]
  2820. [2022-06-17 08:44:56.152692] regdb_unpack_values: value[2]: name[ErrorControl] len[4]
  2821. [2022-06-17 08:44:56.154408] regdb_unpack_values: value[3]: name[ObjectName] len[24]
  2822. [2022-06-17 08:44:56.156063] regdb_unpack_values: value[4]: name[DisplayName] len[20]
  2823. [2022-06-17 08:44:56.157715] regdb_unpack_values: value[5]: name[ImagePath] len[54]
  2824. [2022-06-17 08:44:56.159349] regdb_unpack_values: value[6]: name[Description] len[164]
  2825. [2022-06-17 08:44:56.160962] winreg_SetValue: struct winreg_SetValue
  2826. [2022-06-17 08:44:56.162609] out: struct winreg_SetValue
  2827. [2022-06-17 08:44:56.164323] result : WERR_OK
  2828. [2022-06-17 08:44:56.165979] winreg_SetValue: struct winreg_SetValue
  2829. [2022-06-17 08:44:56.167617] in: struct winreg_SetValue
  2830. [2022-06-17 08:44:56.169254] handle : *
  2831. [2022-06-17 08:44:56.170882] handle: struct policy_handle
  2832. [2022-06-17 08:44:56.172518] handle_type : 0x00000001 (1)
  2833. [2022-06-17 08:44:56.174261] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2834. [2022-06-17 08:44:56.175917] name: struct winreg_String
  2835. [2022-06-17 08:44:56.177554] name_len : 0x000a (10)
  2836. [2022-06-17 08:44:56.179202] name_size : 0x000a (10)
  2837. [2022-06-17 08:44:56.180861] name : *
  2838. [2022-06-17 08:44:56.182491] name : 'Type'
  2839. [2022-06-17 08:44:56.184203] type : REG_DWORD (4)
  2840. [2022-06-17 08:44:56.185830] data : *
  2841. [2022-06-17 08:44:56.187461] data: ARRAY(4)
  2842. [2022-06-17 08:44:56.189084] [0] : 0x10 (16)
  2843. [2022-06-17 08:44:56.190743] [1] : 0x00 (0)
  2844. [2022-06-17 08:44:56.192388] [2] : 0x00 (0)
  2845. [2022-06-17 08:44:56.194111] [3] : 0x00 (0)
  2846. [2022-06-17 08:44:56.195747] size : 0x00000004 (4)
  2847. [2022-06-17 08:44:56.197383] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:Type]
  2848. [2022-06-17 08:44:56.199024] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2849. [2022-06-17 08:44:56.200659] winreg_SetValue: struct winreg_SetValue
  2850. [2022-06-17 08:44:56.202298] out: struct winreg_SetValue
  2851. [2022-06-17 08:44:56.204002] result : WERR_OK
  2852. [2022-06-17 08:44:56.205651] winreg_SetValue: struct winreg_SetValue
  2853. [2022-06-17 08:44:56.207290] in: struct winreg_SetValue
  2854. [2022-06-17 08:44:56.208919] handle : *
  2855. [2022-06-17 08:44:56.210547] handle: struct policy_handle
  2856. [2022-06-17 08:44:56.212173] handle_type : 0x00000001 (1)
  2857. [2022-06-17 08:44:56.213858] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2858. [2022-06-17 08:44:56.215516] name: struct winreg_String
  2859. [2022-06-17 08:44:56.217162] name_len : 0x001a (26)
  2860. [2022-06-17 08:44:56.218797] name_size : 0x001a (26)
  2861. [2022-06-17 08:44:56.220439] name : *
  2862. [2022-06-17 08:44:56.222072] name : 'ErrorControl'
  2863. [2022-06-17 08:44:56.223762] type : REG_DWORD (4)
  2864. [2022-06-17 08:44:56.225421] data : *
  2865. [2022-06-17 08:44:56.227063] data: ARRAY(4)
  2866. [2022-06-17 08:44:56.228686] [0] : 0x01 (1)
  2867. [2022-06-17 08:44:56.230338] [1] : 0x00 (0)
  2868. [2022-06-17 08:44:56.231972] [2] : 0x00 (0)
  2869. [2022-06-17 08:44:56.233671] [3] : 0x00 (0)
  2870. [2022-06-17 08:44:56.235347] size : 0x00000004 (4)
  2871. [2022-06-17 08:44:56.237001] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:ErrorControl]
  2872. [2022-06-17 08:44:56.238667] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2873. [2022-06-17 08:44:56.240314] winreg_SetValue: struct winreg_SetValue
  2874. [2022-06-17 08:44:56.241950] out: struct winreg_SetValue
  2875. [2022-06-17 08:44:56.243626] result : WERR_OK
  2876. [2022-06-17 08:44:56.245274] winreg_SetValue: struct winreg_SetValue
  2877. [2022-06-17 08:44:56.246906] in: struct winreg_SetValue
  2878. [2022-06-17 08:44:56.248538] handle : *
  2879. [2022-06-17 08:44:56.250178] handle: struct policy_handle
  2880. [2022-06-17 08:44:56.251819] handle_type : 0x00000001 (1)
  2881. [2022-06-17 08:44:56.253516] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2882. [2022-06-17 08:44:56.255058] name: struct winreg_String
  2883. [2022-06-17 08:44:56.256686] name_len : 0x0016 (22)
  2884. [2022-06-17 08:44:56.258322] name_size : 0x0016 (22)
  2885. [2022-06-17 08:44:56.259977] name : *
  2886. [2022-06-17 08:44:56.261618] name : 'ObjectName'
  2887. [2022-06-17 08:44:56.263307] type : REG_SZ (1)
  2888. [2022-06-17 08:44:56.264973] data : *
  2889. [2022-06-17 08:44:56.266728] data: ARRAY(24)
  2890. [2022-06-17 08:44:56.268381] [0] : 0x4c (76)
  2891. [2022-06-17 08:44:56.270007] [1] : 0x00 (0)
  2892. [2022-06-17 08:44:56.271649] [2] : 0x6f (111)
  2893. [2022-06-17 08:44:56.273321] [3] : 0x00 (0)
  2894. [2022-06-17 08:44:56.274988] [4] : 0x63 (99)
  2895. [2022-06-17 08:44:56.276648] [5] : 0x00 (0)
  2896. [2022-06-17 08:44:56.278296] [6] : 0x61 (97)
  2897. [2022-06-17 08:44:56.279934] [7] : 0x00 (0)
  2898. [2022-06-17 08:44:56.281565] [8] : 0x6c (108)
  2899. [2022-06-17 08:44:56.283249] [9] : 0x00 (0)
  2900. [2022-06-17 08:44:56.284895] [10] : 0x53 (83)
  2901. [2022-06-17 08:44:56.286539] [11] : 0x00 (0)
  2902. [2022-06-17 08:44:56.288180] [12] : 0x79 (121)
  2903. [2022-06-17 08:44:56.292952] [13] : 0x00 (0)
  2904. [2022-06-17 08:44:56.302126] [14] : 0x73 (115)
  2905. [2022-06-17 08:44:56.303808] [15] : 0x00 (0)
  2906. [2022-06-17 08:44:56.305505] [16] : 0x74 (116)
  2907. [2022-06-17 08:44:56.307191] [17] : 0x00 (0)
  2908. [2022-06-17 08:44:56.308839] [18] : 0x65 (101)
  2909. [2022-06-17 08:44:56.310499] [19] : 0x00 (0)
  2910. [2022-06-17 08:44:56.312139] [20] : 0x6d (109)
  2911. [2022-06-17 08:44:56.313840] [21] : 0x00 (0)
  2912. [2022-06-17 08:44:56.315487] [22] : 0x00 (0)
  2913. [2022-06-17 08:44:56.317132] [23] : 0x00 (0)
  2914. [2022-06-17 08:44:56.318765] size : 0x00000018 (24)
  2915. [2022-06-17 08:44:56.320397] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:ObjectName]
  2916. [2022-06-17 08:44:56.322070] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2917. [2022-06-17 08:44:56.323789] winreg_SetValue: struct winreg_SetValue
  2918. [2022-06-17 08:44:56.325441] out: struct winreg_SetValue
  2919. [2022-06-17 08:44:56.327054] result : WERR_OK
  2920. [2022-06-17 08:44:56.328691] winreg_SetValue: struct winreg_SetValue
  2921. [2022-06-17 08:44:56.330322] in: struct winreg_SetValue
  2922. [2022-06-17 08:44:56.331962] handle : *
  2923. [2022-06-17 08:44:56.333653] handle: struct policy_handle
  2924. [2022-06-17 08:44:56.335313] handle_type : 0x00000001 (1)
  2925. [2022-06-17 08:44:56.336964] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2926. [2022-06-17 08:44:56.338608] name: struct winreg_String
  2927. [2022-06-17 08:44:56.340239] name_len : 0x0018 (24)
  2928. [2022-06-17 08:44:56.341875] name_size : 0x0018 (24)
  2929. [2022-06-17 08:44:56.343557] name : *
  2930. [2022-06-17 08:44:56.345203] name : 'DisplayName'
  2931. [2022-06-17 08:44:56.346867] type : REG_SZ (1)
  2932. [2022-06-17 08:44:56.348509] data : *
  2933. [2022-06-17 08:44:56.350151] data: ARRAY(20)
  2934. [2022-06-17 08:44:56.351778] [0] : 0x4e (78)
  2935. [2022-06-17 08:44:56.353467] [1] : 0x00 (0)
  2936. [2022-06-17 08:44:56.355118] [2] : 0x65 (101)
  2937. [2022-06-17 08:44:56.356759] [3] : 0x00 (0)
  2938. [2022-06-17 08:44:56.358394] [4] : 0x74 (116)
  2939. [2022-06-17 08:44:56.360050] [5] : 0x00 (0)
  2940. [2022-06-17 08:44:56.361702] [6] : 0x20 (32)
  2941. [2022-06-17 08:44:56.363380] [7] : 0x00 (0)
  2942. [2022-06-17 08:44:56.365022] [8] : 0x4c (76)
  2943. [2022-06-17 08:44:56.366661] [9] : 0x00 (0)
  2944. [2022-06-17 08:44:56.368288] [10] : 0x6f (111)
  2945. [2022-06-17 08:44:56.369939] [11] : 0x00 (0)
  2946. [2022-06-17 08:44:56.371589] [12] : 0x67 (103)
  2947. [2022-06-17 08:44:56.373272] [13] : 0x00 (0)
  2948. [2022-06-17 08:44:56.374927] [14] : 0x6f (111)
  2949. [2022-06-17 08:44:56.376547] [15] : 0x00 (0)
  2950. [2022-06-17 08:44:56.378172] [16] : 0x6e (110)
  2951. [2022-06-17 08:44:56.379814] [17] : 0x00 (0)
  2952. [2022-06-17 08:44:56.381440] [18] : 0x00 (0)
  2953. [2022-06-17 08:44:56.383132] [19] : 0x00 (0)
  2954. [2022-06-17 08:44:56.384782] size : 0x00000014 (20)
  2955. [2022-06-17 08:44:56.386426] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:DisplayName]
  2956. [2022-06-17 08:44:56.388097] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  2957. [2022-06-17 08:44:56.389737] winreg_SetValue: struct winreg_SetValue
  2958. [2022-06-17 08:44:56.391379] out: struct winreg_SetValue
  2959. [2022-06-17 08:44:56.393072] result : WERR_OK
  2960. [2022-06-17 08:44:56.394731] winreg_SetValue: struct winreg_SetValue
  2961. [2022-06-17 08:44:56.396378] in: struct winreg_SetValue
  2962. [2022-06-17 08:44:56.398011] handle : *
  2963. [2022-06-17 08:44:56.399636] handle: struct policy_handle
  2964. [2022-06-17 08:44:56.401271] handle_type : 0x00000001 (1)
  2965. [2022-06-17 08:44:56.402951] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  2966. [2022-06-17 08:44:56.404630] name: struct winreg_String
  2967. [2022-06-17 08:44:56.406283] name_len : 0x0014 (20)
  2968. [2022-06-17 08:44:56.407936] name_size : 0x0014 (20)
  2969. [2022-06-17 08:44:56.409577] name : *
  2970. [2022-06-17 08:44:56.411216] name : 'ImagePath'
  2971. [2022-06-17 08:44:56.412902] type : REG_SZ (1)
  2972. [2022-06-17 08:44:56.414554] data : *
  2973. [2022-06-17 08:44:56.416191] data: ARRAY(54)
  2974. [2022-06-17 08:44:56.417834] [0] : 0x2f (47)
  2975. [2022-06-17 08:44:56.419475] [1] : 0x00 (0)
  2976. [2022-06-17 08:44:56.421123] [2] : 0x75 (117)
  2977. [2022-06-17 08:44:56.422761] [3] : 0x00 (0)
  2978. [2022-06-17 08:44:56.424459] [4] : 0x73 (115)
  2979. [2022-06-17 08:44:56.426105] [5] : 0x00 (0)
  2980. [2022-06-17 08:44:56.427741] [6] : 0x72 (114)
  2981. [2022-06-17 08:44:56.429387] [7] : 0x00 (0)
  2982. [2022-06-17 08:44:56.431036] [8] : 0x2f (47)
  2983. [2022-06-17 08:44:56.432674] [9] : 0x00 (0)
  2984. [2022-06-17 08:44:56.434367] [10] : 0x6c (108)
  2985. [2022-06-17 08:44:56.436014] [11] : 0x00 (0)
  2986. [2022-06-17 08:44:56.437647] [12] : 0x69 (105)
  2987. [2022-06-17 08:44:56.439162] [13] : 0x00 (0)
  2988. [2022-06-17 08:44:56.440647] [14] : 0x62 (98)
  2989. [2022-06-17 08:44:56.442133] [15] : 0x00 (0)
  2990. [2022-06-17 08:44:56.443928] [16] : 0x2f (47)
  2991. [2022-06-17 08:44:56.445584] [17] : 0x00 (0)
  2992. [2022-06-17 08:44:56.447233] [18] : 0x73 (115)
  2993. [2022-06-17 08:44:56.448872] [19] : 0x00 (0)
  2994. [2022-06-17 08:44:56.450497] [20] : 0x61 (97)
  2995. [2022-06-17 08:44:56.452135] [21] : 0x00 (0)
  2996. [2022-06-17 08:44:56.453822] [22] : 0x6d (109)
  2997. [2022-06-17 08:44:56.455479] [23] : 0x00 (0)
  2998. [2022-06-17 08:44:56.457130] [24] : 0x62 (98)
  2999. [2022-06-17 08:44:56.458779] [25] : 0x00 (0)
  3000. [2022-06-17 08:44:56.460412] [26] : 0x61 (97)
  3001. [2022-06-17 08:44:56.462043] [27] : 0x00 (0)
  3002. [2022-06-17 08:44:56.463816] [28] : 0x2f (47)
  3003. [2022-06-17 08:44:56.465492] [29] : 0x00 (0)
  3004. [2022-06-17 08:44:56.467142] [30] : 0x73 (115)
  3005. [2022-06-17 08:44:56.468784] [31] : 0x00 (0)
  3006. [2022-06-17 08:44:56.470300] [32] : 0x76 (118)
  3007. [2022-06-17 08:44:56.471797] [33] : 0x00 (0)
  3008. [2022-06-17 08:44:56.473453] [34] : 0x63 (99)
  3009. [2022-06-17 08:44:56.475107] [35] : 0x00 (0)
  3010. [2022-06-17 08:44:56.476737] [36] : 0x63 (99)
  3011. [2022-06-17 08:44:56.478386] [37] : 0x00 (0)
  3012. [2022-06-17 08:44:56.480039] [38] : 0x74 (116)
  3013. [2022-06-17 08:44:56.481677] [39] : 0x00 (0)
  3014. [2022-06-17 08:44:56.483362] [40] : 0x6c (108)
  3015. [2022-06-17 08:44:56.485014] [41] : 0x00 (0)
  3016. [2022-06-17 08:44:56.486652] [42] : 0x2f (47)
  3017. [2022-06-17 08:44:56.488279] [43] : 0x00 (0)
  3018. [2022-06-17 08:44:56.489910] [44] : 0x73 (115)
  3019. [2022-06-17 08:44:56.491566] [45] : 0x00 (0)
  3020. [2022-06-17 08:44:56.493263] [46] : 0x6d (109)
  3021. [2022-06-17 08:44:56.494926] [47] : 0x00 (0)
  3022. [2022-06-17 08:44:56.496553] [48] : 0x62 (98)
  3023. [2022-06-17 08:44:56.498198] [49] : 0x00 (0)
  3024. [2022-06-17 08:44:56.499830] [50] : 0x64 (100)
  3025. [2022-06-17 08:44:56.501468] [51] : 0x00 (0)
  3026. [2022-06-17 08:44:56.503121] [52] : 0x00 (0)
  3027. [2022-06-17 08:44:56.504785] [53] : 0x00 (0)
  3028. [2022-06-17 08:44:56.506446] size : 0x00000036 (54)
  3029. [2022-06-17 08:44:56.508091] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:ImagePath]
  3030. [2022-06-17 08:44:56.509753] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3031. [2022-06-17 08:44:56.511396] winreg_SetValue: struct winreg_SetValue
  3032. [2022-06-17 08:44:56.513078] out: struct winreg_SetValue
  3033. [2022-06-17 08:44:56.514609] result : WERR_OK
  3034. [2022-06-17 08:44:56.516112] winreg_SetValue: struct winreg_SetValue
  3035. [2022-06-17 08:44:56.517609] in: struct winreg_SetValue
  3036. [2022-06-17 08:44:56.519100] handle : *
  3037. [2022-06-17 08:44:56.520578] handle: struct policy_handle
  3038. [2022-06-17 08:44:56.522052] handle_type : 0x00000001 (1)
  3039. [2022-06-17 08:44:56.523600] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  3040. [2022-06-17 08:44:56.525122] name: struct winreg_String
  3041. [2022-06-17 08:44:56.526618] name_len : 0x0018 (24)
  3042. [2022-06-17 08:44:56.528110] name_size : 0x0018 (24)
  3043. [2022-06-17 08:44:56.529778] name : *
  3044. [2022-06-17 08:44:56.531303] name : 'Description'
  3045. [2022-06-17 08:44:56.532808] type : REG_SZ (1)
  3046. [2022-06-17 08:44:56.534368] data : *
  3047. [2022-06-17 08:44:56.535871] data: ARRAY(164)
  3048. [2022-06-17 08:44:56.537361] [0] : 0x46 (70)
  3049. [2022-06-17 08:44:56.539295] [1] : 0x00 (0)
  3050. [2022-06-17 08:44:56.540959] [2] : 0x69 (105)
  3051. [2022-06-17 08:44:56.542604] [3] : 0x00 (0)
  3052. [2022-06-17 08:44:56.544346] [4] : 0x6c (108)
  3053. [2022-06-17 08:44:56.553044] [5] : 0x00 (0)
  3054. [2022-06-17 08:44:56.554957] [6] : 0x65 (101)
  3055. [2022-06-17 08:44:56.556681] [7] : 0x00 (0)
  3056. [2022-06-17 08:44:56.558356] [8] : 0x20 (32)
  3057. [2022-06-17 08:44:56.560034] [9] : 0x00 (0)
  3058. [2022-06-17 08:44:56.565539] [10] : 0x73 (115)
  3059. [2022-06-17 08:44:56.567316] [11] : 0x00 (0)
  3060. [2022-06-17 08:44:56.568998] [12] : 0x65 (101)
  3061. [2022-06-17 08:44:56.570657] [13] : 0x00 (0)
  3062. [2022-06-17 08:44:56.572305] [14] : 0x72 (114)
  3063. [2022-06-17 08:44:56.574016] [15] : 0x00 (0)
  3064. [2022-06-17 08:44:56.575656] [16] : 0x76 (118)
  3065. [2022-06-17 08:44:56.577309] [17] : 0x00 (0)
  3066. [2022-06-17 08:44:56.578960] [18] : 0x69 (105)
  3067. [2022-06-17 08:44:56.580594] [19] : 0x00 (0)
  3068. [2022-06-17 08:44:56.582227] [20] : 0x63 (99)
  3069. [2022-06-17 08:44:56.583909] [21] : 0x00 (0)
  3070. [2022-06-17 08:44:56.585749] [22] : 0x65 (101)
  3071. [2022-06-17 08:44:56.587483] [23] : 0x00 (0)
  3072. [2022-06-17 08:44:56.589149] [24] : 0x20 (32)
  3073. [2022-06-17 08:44:56.590809] [25] : 0x00 (0)
  3074. [2022-06-17 08:44:56.592461] [26] : 0x70 (112)
  3075. [2022-06-17 08:44:56.594173] [27] : 0x00 (0)
  3076. [2022-06-17 08:44:56.595820] [28] : 0x72 (114)
  3077. [2022-06-17 08:44:56.597465] [29] : 0x00 (0)
  3078. [2022-06-17 08:44:56.599120] [30] : 0x6f (111)
  3079. [2022-06-17 08:44:56.600761] [31] : 0x00 (0)
  3080. [2022-06-17 08:44:56.602389] [32] : 0x76 (118)
  3081. [2022-06-17 08:44:56.604105] [33] : 0x00 (0)
  3082. [2022-06-17 08:44:56.605756] [34] : 0x69 (105)
  3083. [2022-06-17 08:44:56.607285] [35] : 0x00 (0)
  3084. [2022-06-17 08:44:56.608785] [36] : 0x64 (100)
  3085. [2022-06-17 08:44:56.610281] [37] : 0x00 (0)
  3086. [2022-06-17 08:44:56.611776] [38] : 0x69 (105)
  3087. [2022-06-17 08:44:56.613326] [39] : 0x00 (0)
  3088. [2022-06-17 08:44:56.614829] [40] : 0x6e (110)
  3089. [2022-06-17 08:44:56.616326] [41] : 0x00 (0)
  3090. [2022-06-17 08:44:56.617813] [42] : 0x67 (103)
  3091. [2022-06-17 08:44:56.619295] [43] : 0x00 (0)
  3092. [2022-06-17 08:44:56.620792] [44] : 0x20 (32)
  3093. [2022-06-17 08:44:56.622459] [45] : 0x00 (0)
  3094. [2022-06-17 08:44:56.624111] [46] : 0x61 (97)
  3095. [2022-06-17 08:44:56.625631] [47] : 0x00 (0)
  3096. [2022-06-17 08:44:56.627122] [48] : 0x63 (99)
  3097. [2022-06-17 08:44:56.628611] [49] : 0x00 (0)
  3098. [2022-06-17 08:44:56.630101] [50] : 0x63 (99)
  3099. [2022-06-17 08:44:56.631607] [51] : 0x00 (0)
  3100. [2022-06-17 08:44:56.633162] [52] : 0x65 (101)
  3101. [2022-06-17 08:44:56.634693] [53] : 0x00 (0)
  3102. [2022-06-17 08:44:56.636197] [54] : 0x73 (115)
  3103. [2022-06-17 08:44:56.637921] [55] : 0x00 (0)
  3104. [2022-06-17 08:44:56.639439] [56] : 0x73 (115)
  3105. [2022-06-17 08:44:56.640941] [57] : 0x00 (0)
  3106. [2022-06-17 08:44:56.642439] [58] : 0x20 (32)
  3107. [2022-06-17 08:44:56.644062] [59] : 0x00 (0)
  3108. [2022-06-17 08:44:56.645577] [60] : 0x74 (116)
  3109. [2022-06-17 08:44:56.647077] [61] : 0x00 (0)
  3110. [2022-06-17 08:44:56.648571] [62] : 0x6f (111)
  3111. [2022-06-17 08:44:56.650058] [63] : 0x00 (0)
  3112. [2022-06-17 08:44:56.651687] [64] : 0x20 (32)
  3113. [2022-06-17 08:44:56.653270] [65] : 0x00 (0)
  3114. [2022-06-17 08:44:56.654799] [66] : 0x70 (112)
  3115. [2022-06-17 08:44:56.656316] [67] : 0x00 (0)
  3116. [2022-06-17 08:44:56.657817] [68] : 0x6f (111)
  3117. [2022-06-17 08:44:56.659310] [69] : 0x00 (0)
  3118. [2022-06-17 08:44:56.660789] [70] : 0x6c (108)
  3119. [2022-06-17 08:44:56.662289] [71] : 0x00 (0)
  3120. [2022-06-17 08:44:56.663843] [72] : 0x69 (105)
  3121. [2022-06-17 08:44:56.665360] [73] : 0x00 (0)
  3122. [2022-06-17 08:44:56.667041] [74] : 0x63 (99)
  3123. [2022-06-17 08:44:56.668589] [75] : 0x00 (0)
  3124. [2022-06-17 08:44:56.670098] [76] : 0x79 (121)
  3125. [2022-06-17 08:44:56.671596] [77] : 0x00 (0)
  3126. [2022-06-17 08:44:56.673142] [78] : 0x20 (32)
  3127. [2022-06-17 08:44:56.674662] [79] : 0x00 (0)
  3128. [2022-06-17 08:44:56.676164] [80] : 0x61 (97)
  3129. [2022-06-17 08:44:56.677661] [81] : 0x00 (0)
  3130. [2022-06-17 08:44:56.679158] [82] : 0x6e (110)
  3131. [2022-06-17 08:44:56.680790] [83] : 0x00 (0)
  3132. [2022-06-17 08:44:56.682467] [84] : 0x64 (100)
  3133. [2022-06-17 08:44:56.684062] [85] : 0x00 (0)
  3134. [2022-06-17 08:44:56.685569] [86] : 0x20 (32)
  3135. [2022-06-17 08:44:56.687074] [87] : 0x00 (0)
  3136. [2022-06-17 08:44:56.688582] [88] : 0x70 (112)
  3137. [2022-06-17 08:44:56.690090] [89] : 0x00 (0)
  3138. [2022-06-17 08:44:56.691597] [90] : 0x72 (114)
  3139. [2022-06-17 08:44:56.693134] [91] : 0x00 (0)
  3140. [2022-06-17 08:44:56.694635] [92] : 0x6f (111)
  3141. [2022-06-17 08:44:56.696124] [93] : 0x00 (0)
  3142. [2022-06-17 08:44:56.697844] [94] : 0x66 (102)
  3143. [2022-06-17 08:44:56.699361] [95] : 0x00 (0)
  3144. [2022-06-17 08:44:56.700862] [96] : 0x69 (105)
  3145. [2022-06-17 08:44:56.702355] [97] : 0x00 (0)
  3146. [2022-06-17 08:44:56.703933] [98] : 0x6c (108)
  3147. [2022-06-17 08:44:56.705460] [99] : 0x00 (0)
  3148. [2022-06-17 08:44:56.706967] [100] : 0x65 (101)
  3149. [2022-06-17 08:44:56.708461] [101] : 0x00 (0)
  3150. [2022-06-17 08:44:56.709951] [102] : 0x20 (32)
  3151. [2022-06-17 08:44:56.711842] [103] : 0x00 (0)
  3152. [2022-06-17 08:44:56.714392] [104] : 0x64 (100)
  3153. [2022-06-17 08:44:56.716095] [105] : 0x00 (0)
  3154. [2022-06-17 08:44:56.717727] [106] : 0x61 (97)
  3155. [2022-06-17 08:44:56.719367] [107] : 0x00 (0)
  3156. [2022-06-17 08:44:56.721010] [108] : 0x74 (116)
  3157. [2022-06-17 08:44:56.722649] [109] : 0x00 (0)
  3158. [2022-06-17 08:44:56.724371] [110] : 0x61 (97)
  3159. [2022-06-17 08:44:56.726013] [111] : 0x00 (0)
  3160. [2022-06-17 08:44:56.727665] [112] : 0x20 (32)
  3161. [2022-06-17 08:44:56.729187] [113] : 0x00 (0)
  3162. [2022-06-17 08:44:56.730677] [114] : 0x28 (40)
  3163. [2022-06-17 08:44:56.732169] [115] : 0x00 (0)
  3164. [2022-06-17 08:44:56.733928] [116] : 0x6e (110)
  3165. [2022-06-17 08:44:56.735590] [117] : 0x00 (0)
  3166. [2022-06-17 08:44:56.737232] [118] : 0x6f (111)
  3167. [2022-06-17 08:44:56.738875] [119] : 0x00 (0)
  3168. [2022-06-17 08:44:56.740513] [120] : 0x74 (116)
  3169. [2022-06-17 08:44:56.742135] [121] : 0x00 (0)
  3170. [2022-06-17 08:44:56.743818] [122] : 0x72 (114)
  3171. [2022-06-17 08:44:56.745480] [123] : 0x00 (0)
  3172. [2022-06-17 08:44:56.747111] [124] : 0x65 (101)
  3173. [2022-06-17 08:44:56.748759] [125] : 0x00 (0)
  3174. [2022-06-17 08:44:56.750396] [126] : 0x6d (109)
  3175. [2022-06-17 08:44:56.752034] [127] : 0x00 (0)
  3176. [2022-06-17 08:44:56.753743] [128] : 0x6f (111)
  3177. [2022-06-17 08:44:56.755394] [129] : 0x00 (0)
  3178. [2022-06-17 08:44:56.757027] [130] : 0x74 (116)
  3179. [2022-06-17 08:44:56.758682] [131] : 0x00 (0)
  3180. [2022-06-17 08:44:56.760328] [132] : 0x65 (101)
  3181. [2022-06-17 08:44:56.761976] [133] : 0x00 (0)
  3182. [2022-06-17 08:44:56.763658] [134] : 0x6c (108)
  3183. [2022-06-17 08:44:56.765303] [135] : 0x00 (0)
  3184. [2022-06-17 08:44:56.766943] [136] : 0x79 (121)
  3185. [2022-06-17 08:44:56.768580] [137] : 0x00 (0)
  3186. [2022-06-17 08:44:56.770210] [138] : 0x20 (32)
  3187. [2022-06-17 08:44:56.771854] [139] : 0x00 (0)
  3188. [2022-06-17 08:44:56.773543] [140] : 0x6d (109)
  3189. [2022-06-17 08:44:56.775204] [141] : 0x00 (0)
  3190. [2022-06-17 08:44:56.776842] [142] : 0x61 (97)
  3191. [2022-06-17 08:44:56.778471] [143] : 0x00 (0)
  3192. [2022-06-17 08:44:56.780106] [144] : 0x6e (110)
  3193. [2022-06-17 08:44:56.781739] [145] : 0x00 (0)
  3194. [2022-06-17 08:44:56.783420] [146] : 0x61 (97)
  3195. [2022-06-17 08:44:56.785078] [147] : 0x00 (0)
  3196. [2022-06-17 08:44:56.786732] [148] : 0x67 (103)
  3197. [2022-06-17 08:44:56.793567] [149] : 0x00 (0)
  3198. [2022-06-17 08:44:56.795233] [150] : 0x65 (101)
  3199. [2022-06-17 08:44:56.803486] [151] : 0x00 (0)
  3200. [2022-06-17 08:44:56.805265] [152] : 0x61 (97)
  3201. [2022-06-17 08:44:56.806951] [153] : 0x00 (0)
  3202. [2022-06-17 08:44:56.808627] [154] : 0x62 (98)
  3203. [2022-06-17 08:44:56.810280] [155] : 0x00 (0)
  3204. [2022-06-17 08:44:56.811920] [156] : 0x6c (108)
  3205. [2022-06-17 08:44:56.813616] [157] : 0x00 (0)
  3206. [2022-06-17 08:44:56.815604] [158] : 0x65 (101)
  3207. [2022-06-17 08:44:56.817261] [159] : 0x00 (0)
  3208. [2022-06-17 08:44:56.818903] [160] : 0x29 (41)
  3209. [2022-06-17 08:44:56.820534] [161] : 0x00 (0)
  3210. [2022-06-17 08:44:56.822186] [162] : 0x00 (0)
  3211. [2022-06-17 08:44:56.823885] [163] : 0x00 (0)
  3212. [2022-06-17 08:44:56.825538] size : 0x000000a4 (164)
  3213. [2022-06-17 08:44:56.827053] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON:Description]
  3214. [2022-06-17 08:44:56.828578] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3215. [2022-06-17 08:44:56.830220] winreg_SetValue: struct winreg_SetValue
  3216. [2022-06-17 08:44:56.831868] out: struct winreg_SetValue
  3217. [2022-06-17 08:44:56.833595] result : WERR_OK
  3218. [2022-06-17 08:44:56.835259] winreg_CloseKey: struct winreg_CloseKey
  3219. [2022-06-17 08:44:56.836909] in: struct winreg_CloseKey
  3220. [2022-06-17 08:44:56.838539] handle : *
  3221. [2022-06-17 08:44:56.840181] handle: struct policy_handle
  3222. [2022-06-17 08:44:56.841825] handle_type : 0x00000001 (1)
  3223. [2022-06-17 08:44:56.843531] uuid : 45963cf1-0923-4e0f-a4fa-e9dbe2adbe37
  3224. [2022-06-17 08:44:56.845203] regdb_close: decrementing refcount (4->3)
  3225. [2022-06-17 08:44:56.846847] winreg_CloseKey: struct winreg_CloseKey
  3226. [2022-06-17 08:44:56.848488] out: struct winreg_CloseKey
  3227. [2022-06-17 08:44:56.849996] handle : *
  3228. [2022-06-17 08:44:56.851483] handle: struct policy_handle
  3229. [2022-06-17 08:44:56.853007] handle_type : 0x00000000 (0)
  3230. [2022-06-17 08:44:56.854522] uuid : 00000000-0000-0000-0000-000000000000
  3231. [2022-06-17 08:44:56.856044] result : WERR_OK
  3232. [2022-06-17 08:44:56.857549] winreg_CreateKey: struct winreg_CreateKey
  3233. [2022-06-17 08:44:56.859044] in: struct winreg_CreateKey
  3234. [2022-06-17 08:44:56.860525] handle : *
  3235. [2022-06-17 08:44:56.862008] handle: struct policy_handle
  3236. [2022-06-17 08:44:56.863556] handle_type : 0x00000001 (1)
  3237. [2022-06-17 08:44:56.865249] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  3238. [2022-06-17 08:44:56.866802] name: struct winreg_String
  3239. [2022-06-17 08:44:56.868315] name_len : 0x0068 (104)
  3240. [2022-06-17 08:44:56.869805] name_size : 0x0068 (104)
  3241. [2022-06-17 08:44:56.871303] name : *
  3242. [2022-06-17 08:44:56.872783] name : 'SYSTEM\CurrentControlSet\Services\NETLOGON\Security'
  3243. [2022-06-17 08:44:56.874373] keyclass: struct winreg_String
  3244. [2022-06-17 08:44:56.875871] name_len : 0x0002 (2)
  3245. [2022-06-17 08:44:56.877355] name_size : 0x0002 (2)
  3246. [2022-06-17 08:44:56.878851] name : *
  3247. [2022-06-17 08:44:56.880514] name : ''
  3248. [2022-06-17 08:44:56.882047] options : 0x00000000 (0)
  3249. [2022-06-17 08:44:56.883591] 0: REG_OPTION_VOLATILE
  3250. [2022-06-17 08:44:56.885090] 0: REG_OPTION_CREATE_LINK
  3251. [2022-06-17 08:44:56.886585] 0: REG_OPTION_BACKUP_RESTORE
  3252. [2022-06-17 08:44:56.888074] 0: REG_OPTION_OPEN_LINK
  3253. [2022-06-17 08:44:56.889579] access_mask : 0x02000000 (33554432)
  3254. [2022-06-17 08:44:56.891091] 0: KEY_QUERY_VALUE
  3255. [2022-06-17 08:44:56.892584] 0: KEY_SET_VALUE
  3256. [2022-06-17 08:44:56.894137] 0: KEY_CREATE_SUB_KEY
  3257. [2022-06-17 08:44:56.895838] 0: KEY_ENUMERATE_SUB_KEYS
  3258. [2022-06-17 08:44:56.897345] 0: KEY_NOTIFY
  3259. [2022-06-17 08:44:56.898853] 0: KEY_CREATE_LINK
  3260. [2022-06-17 08:44:56.900349] 0: KEY_WOW64_64KEY
  3261. [2022-06-17 08:44:56.901860] 0: KEY_WOW64_32KEY
  3262. [2022-06-17 08:44:56.903412] secdesc : NULL
  3263. [2022-06-17 08:44:56.904923] action_taken : *
  3264. [2022-06-17 08:44:56.906418] action_taken : REG_OPENED_EXISTING_KEY (2)
  3265. [2022-06-17 08:44:56.907930] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\NETLOGON\Security'
  3266. [2022-06-17 08:44:56.909452] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3267. [2022-06-17 08:44:56.911680] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3268. [2022-06-17 08:44:56.913277] regkey_open_onelevel: name = [SYSTEM]
  3269. [2022-06-17 08:44:56.914789] regdb_open: incrementing refcount (3->4)
  3270. [2022-06-17 08:44:56.916289] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  3271. [2022-06-17 08:44:56.917777] pathtree_find: Enter [\HKLM\SYSTEM]
  3272. [2022-06-17 08:44:56.919261] pathtree_find: Exit
  3273. [2022-06-17 08:44:56.920726] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  3274. [2022-06-17 08:44:56.922211] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3275. [2022-06-17 08:44:56.923748] regkey_open_onelevel: name = [CurrentControlSet]
  3276. [2022-06-17 08:44:56.925649] regdb_open: incrementing refcount (4->5)
  3277. [2022-06-17 08:44:56.927309] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  3278. [2022-06-17 08:44:56.928970] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  3279. [2022-06-17 08:44:56.930620] pathtree_find: Exit
  3280. [2022-06-17 08:44:56.932234] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  3281. [2022-06-17 08:44:56.933926] regdb_close: decrementing refcount (5->4)
  3282. [2022-06-17 08:44:56.935575] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3283. [2022-06-17 08:44:56.937236] regkey_open_onelevel: name = [Services]
  3284. [2022-06-17 08:44:56.938883] regdb_open: incrementing refcount (4->5)
  3285. [2022-06-17 08:44:56.940525] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  3286. [2022-06-17 08:44:56.942173] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  3287. [2022-06-17 08:44:56.943964] pathtree_find: Exit
  3288. [2022-06-17 08:44:56.945609] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  3289. [2022-06-17 08:44:56.947265] regdb_close: decrementing refcount (5->4)
  3290. [2022-06-17 08:44:56.948909] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3291. [2022-06-17 08:44:56.950570] regkey_open_onelevel: name = [NETLOGON]
  3292. [2022-06-17 08:44:56.952216] regdb_open: incrementing refcount (4->5)
  3293. [2022-06-17 08:44:56.953896] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  3294. [2022-06-17 08:44:56.955548] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  3295. [2022-06-17 08:44:56.957192] pathtree_find: Exit
  3296. [2022-06-17 08:44:56.958811] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
  3297. [2022-06-17 08:44:56.960479] regdb_close: decrementing refcount (5->4)
  3298. [2022-06-17 08:44:56.962119] regkey_open_onelevel: name = [Security]
  3299. [2022-06-17 08:44:56.963800] regdb_open: incrementing refcount (4->5)
  3300. [2022-06-17 08:44:56.965445] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
  3301. [2022-06-17 08:44:56.967127] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
  3302. [2022-06-17 08:44:56.968784] pathtree_find: Exit
  3303. [2022-06-17 08:44:56.970410] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
  3304. [2022-06-17 08:44:56.972082] regdb_close: decrementing refcount (5->4)
  3305. [2022-06-17 08:44:56.973785] winreg_CreateKey: struct winreg_CreateKey
  3306. [2022-06-17 08:44:56.975437] out: struct winreg_CreateKey
  3307. [2022-06-17 08:44:56.977079] new_handle : *
  3308. [2022-06-17 08:44:56.978711] new_handle: struct policy_handle
  3309. [2022-06-17 08:44:56.980348] handle_type : 0x00000001 (1)
  3310. [2022-06-17 08:44:56.982004] uuid : f40758ff-aad3-43fe-8a49-680faf22de43
  3311. [2022-06-17 08:44:56.983711] action_taken : *
  3312. [2022-06-17 08:44:56.985360] action_taken : REG_OPENED_EXISTING_KEY (2)
  3313. [2022-06-17 08:44:56.987017] result : WERR_OK
  3314. [2022-06-17 08:44:56.988659] winreg_SetValue: struct winreg_SetValue
  3315. [2022-06-17 08:44:56.990289] in: struct winreg_SetValue
  3316. [2022-06-17 08:44:56.991922] handle : *
  3317. [2022-06-17 08:44:56.993601] handle: struct policy_handle
  3318. [2022-06-17 08:44:56.995252] handle_type : 0x00000001 (1)
  3319. [2022-06-17 08:44:56.996917] uuid : f40758ff-aad3-43fe-8a49-680faf22de43
  3320. [2022-06-17 08:44:56.998577] name: struct winreg_String
  3321. [2022-06-17 08:44:57.000214] name_len : 0x0012 (18)
  3322. [2022-06-17 08:44:57.001847] name_size : 0x0012 (18)
  3323. [2022-06-17 08:44:57.003555] name : *
  3324. [2022-06-17 08:44:57.005213] name : 'Security'
  3325. [2022-06-17 08:44:57.006852] type : REG_BINARY (3)
  3326. [2022-06-17 08:44:57.008489] data : *
  3327. [2022-06-17 08:44:57.010135] data: ARRAY(120)
  3328. [2022-06-17 08:44:57.011761] [0] : 0x01 (1)
  3329. [2022-06-17 08:44:57.013456] [1] : 0x00 (0)
  3330. [2022-06-17 08:44:57.015100] [2] : 0x04 (4)
  3331. [2022-06-17 08:44:57.016732] [3] : 0x80 (128)
  3332. [2022-06-17 08:44:57.018365] [4] : 0x00 (0)
  3333. [2022-06-17 08:44:57.019996] [5] : 0x00 (0)
  3334. [2022-06-17 08:44:57.021642] [6] : 0x00 (0)
  3335. [2022-06-17 08:44:57.023353] [7] : 0x00 (0)
  3336. [2022-06-17 08:44:57.025008] [8] : 0x00 (0)
  3337. [2022-06-17 08:44:57.026644] [9] : 0x00 (0)
  3338. [2022-06-17 08:44:57.028281] [10] : 0x00 (0)
  3339. [2022-06-17 08:44:57.029916] [11] : 0x00 (0)
  3340. [2022-06-17 08:44:57.031806] [12] : 0x00 (0)
  3341. [2022-06-17 08:44:57.033512] [13] : 0x00 (0)
  3342. [2022-06-17 08:44:57.035179] [14] : 0x00 (0)
  3343. [2022-06-17 08:44:57.036836] [15] : 0x00 (0)
  3344. [2022-06-17 08:44:57.038490] [16] : 0x14 (20)
  3345. [2022-06-17 08:44:57.040138] [17] : 0x00 (0)
  3346. [2022-06-17 08:44:57.041772] [18] : 0x00 (0)
  3347. [2022-06-17 08:44:57.043472] [19] : 0x00 (0)
  3348. [2022-06-17 08:44:57.052978] [20] : 0x02 (2)
  3349. [2022-06-17 08:44:57.054833] [21] : 0x00 (0)
  3350. [2022-06-17 08:44:57.056550] [22] : 0x64 (100)
  3351. [2022-06-17 08:44:57.058232] [23] : 0x00 (0)
  3352. [2022-06-17 08:44:57.059884] [24] : 0x04 (4)
  3353. [2022-06-17 08:44:57.061584] [25] : 0x00 (0)
  3354. [2022-06-17 08:44:57.066011] [26] : 0x00 (0)
  3355. [2022-06-17 08:44:57.067695] [27] : 0x00 (0)
  3356. [2022-06-17 08:44:57.069349] [28] : 0x00 (0)
  3357. [2022-06-17 08:44:57.071001] [29] : 0x00 (0)
  3358. [2022-06-17 08:44:57.072647] [30] : 0x14 (20)
  3359. [2022-06-17 08:44:57.074366] [31] : 0x00 (0)
  3360. [2022-06-17 08:44:57.076015] [32] : 0x8d (141)
  3361. [2022-06-17 08:44:57.077536] [33] : 0x01 (1)
  3362. [2022-06-17 08:44:57.079039] [34] : 0x02 (2)
  3363. [2022-06-17 08:44:57.080540] [35] : 0x00 (0)
  3364. [2022-06-17 08:44:57.082039] [36] : 0x01 (1)
  3365. [2022-06-17 08:44:57.083606] [37] : 0x01 (1)
  3366. [2022-06-17 08:44:57.085116] [38] : 0x00 (0)
  3367. [2022-06-17 08:44:57.086608] [39] : 0x00 (0)
  3368. [2022-06-17 08:44:57.088092] [40] : 0x00 (0)
  3369. [2022-06-17 08:44:57.089573] [41] : 0x00 (0)
  3370. [2022-06-17 08:44:57.091069] [42] : 0x00 (0)
  3371. [2022-06-17 08:44:57.093124] [43] : 0x01 (1)
  3372. [2022-06-17 08:44:57.094802] [44] : 0x00 (0)
  3373. [2022-06-17 08:44:57.096449] [45] : 0x00 (0)
  3374. [2022-06-17 08:44:57.098092] [46] : 0x00 (0)
  3375. [2022-06-17 08:44:57.099734] [47] : 0x00 (0)
  3376. [2022-06-17 08:44:57.101376] [48] : 0x00 (0)
  3377. [2022-06-17 08:44:57.103060] [49] : 0x00 (0)
  3378. [2022-06-17 08:44:57.104723] [50] : 0x18 (24)
  3379. [2022-06-17 08:44:57.106366] [51] : 0x00 (0)
  3380. [2022-06-17 08:44:57.107998] [52] : 0xfd (253)
  3381. [2022-06-17 08:44:57.109629] [53] : 0x01 (1)
  3382. [2022-06-17 08:44:57.111267] [54] : 0x02 (2)
  3383. [2022-06-17 08:44:57.112951] [55] : 0x00 (0)
  3384. [2022-06-17 08:44:57.114595] [56] : 0x01 (1)
  3385. [2022-06-17 08:44:57.116253] [57] : 0x02 (2)
  3386. [2022-06-17 08:44:57.117904] [58] : 0x00 (0)
  3387. [2022-06-17 08:44:57.119545] [59] : 0x00 (0)
  3388. [2022-06-17 08:44:57.121178] [60] : 0x00 (0)
  3389. [2022-06-17 08:44:57.122811] [61] : 0x00 (0)
  3390. [2022-06-17 08:44:57.124507] [62] : 0x00 (0)
  3391. [2022-06-17 08:44:57.126168] [63] : 0x05 (5)
  3392. [2022-06-17 08:44:57.127697] [64] : 0x20 (32)
  3393. [2022-06-17 08:44:57.129479] [65] : 0x00 (0)
  3394. [2022-06-17 08:44:57.131124] [66] : 0x00 (0)
  3395. [2022-06-17 08:44:57.132759] [67] : 0x00 (0)
  3396. [2022-06-17 08:44:57.134449] [68] : 0x23 (35)
  3397. [2022-06-17 08:44:57.136097] [69] : 0x02 (2)
  3398. [2022-06-17 08:44:57.137741] [70] : 0x00 (0)
  3399. [2022-06-17 08:44:57.139379] [71] : 0x00 (0)
  3400. [2022-06-17 08:44:57.141028] [72] : 0x00 (0)
  3401. [2022-06-17 08:44:57.142661] [73] : 0x00 (0)
  3402. [2022-06-17 08:44:57.144365] [74] : 0x18 (24)
  3403. [2022-06-17 08:44:57.146018] [75] : 0x00 (0)
  3404. [2022-06-17 08:44:57.147662] [76] : 0xff (255)
  3405. [2022-06-17 08:44:57.149295] [77] : 0x01 (1)
  3406. [2022-06-17 08:44:57.150938] [78] : 0x0f (15)
  3407. [2022-06-17 08:44:57.152580] [79] : 0x00 (0)
  3408. [2022-06-17 08:44:57.154357] [80] : 0x01 (1)
  3409. [2022-06-17 08:44:57.156012] [81] : 0x02 (2)
  3410. [2022-06-17 08:44:57.157649] [82] : 0x00 (0)
  3411. [2022-06-17 08:44:57.159289] [83] : 0x00 (0)
  3412. [2022-06-17 08:44:57.160915] [84] : 0x00 (0)
  3413. [2022-06-17 08:44:57.162553] [85] : 0x00 (0)
  3414. [2022-06-17 08:44:57.164295] [86] : 0x00 (0)
  3415. [2022-06-17 08:44:57.165950] [87] : 0x05 (5)
  3416. [2022-06-17 08:44:57.167593] [88] : 0x20 (32)
  3417. [2022-06-17 08:44:57.169227] [89] : 0x00 (0)
  3418. [2022-06-17 08:44:57.170863] [90] : 0x00 (0)
  3419. [2022-06-17 08:44:57.172506] [91] : 0x00 (0)
  3420. [2022-06-17 08:44:57.174229] [92] : 0x25 (37)
  3421. [2022-06-17 08:44:57.175870] [93] : 0x02 (2)
  3422. [2022-06-17 08:44:57.177509] [94] : 0x00 (0)
  3423. [2022-06-17 08:44:57.179147] [95] : 0x00 (0)
  3424. [2022-06-17 08:44:57.180784] [96] : 0x00 (0)
  3425. [2022-06-17 08:44:57.182424] [97] : 0x00 (0)
  3426. [2022-06-17 08:44:57.184145] [98] : 0x18 (24)
  3427. [2022-06-17 08:44:57.185799] [99] : 0x00 (0)
  3428. [2022-06-17 08:44:57.187443] [100] : 0xff (255)
  3429. [2022-06-17 08:44:57.189087] [101] : 0x01 (1)
  3430. [2022-06-17 08:44:57.190733] [102] : 0x0f (15)
  3431. [2022-06-17 08:44:57.192366] [103] : 0x00 (0)
  3432. [2022-06-17 08:44:57.194086] [104] : 0x01 (1)
  3433. [2022-06-17 08:44:57.195727] [105] : 0x02 (2)
  3434. [2022-06-17 08:44:57.197368] [106] : 0x00 (0)
  3435. [2022-06-17 08:44:57.199008] [107] : 0x00 (0)
  3436. [2022-06-17 08:44:57.200646] [108] : 0x00 (0)
  3437. [2022-06-17 08:44:57.202287] [109] : 0x00 (0)
  3438. [2022-06-17 08:44:57.204001] [110] : 0x00 (0)
  3439. [2022-06-17 08:44:57.205661] [111] : 0x05 (5)
  3440. [2022-06-17 08:44:57.207291] [112] : 0x20 (32)
  3441. [2022-06-17 08:44:57.208924] [113] : 0x00 (0)
  3442. [2022-06-17 08:44:57.210569] [114] : 0x00 (0)
  3443. [2022-06-17 08:44:57.212205] [115] : 0x00 (0)
  3444. [2022-06-17 08:44:57.213889] [116] : 0x20 (32)
  3445. [2022-06-17 08:44:57.215550] [117] : 0x02 (2)
  3446. [2022-06-17 08:44:57.217198] [118] : 0x00 (0)
  3447. [2022-06-17 08:44:57.218841] [119] : 0x00 (0)
  3448. [2022-06-17 08:44:57.220477] size : 0x00000078 (120)
  3449. [2022-06-17 08:44:57.222109] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security:Security]
  3450. [2022-06-17 08:44:57.223835] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3451. [2022-06-17 08:44:57.225509] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security' (ops 0xb6ab32e8)
  3452. [2022-06-17 08:44:57.227197] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
  3453. [2022-06-17 08:44:57.228869] regdb_unpack_values: value[0]: name[Security] len[120]
  3454. [2022-06-17 08:44:57.230501] winreg_SetValue: struct winreg_SetValue
  3455. [2022-06-17 08:44:57.232137] out: struct winreg_SetValue
  3456. [2022-06-17 08:44:57.233813] result : WERR_OK
  3457. [2022-06-17 08:44:57.235469] winreg_CloseKey: struct winreg_CloseKey
  3458. [2022-06-17 08:44:57.237116] in: struct winreg_CloseKey
  3459. [2022-06-17 08:44:57.238763] handle : *
  3460. [2022-06-17 08:44:57.240390] handle: struct policy_handle
  3461. [2022-06-17 08:44:57.242024] handle_type : 0x00000001 (1)
  3462. [2022-06-17 08:44:57.243723] uuid : f40758ff-aad3-43fe-8a49-680faf22de43
  3463. [2022-06-17 08:44:57.245383] regdb_close: decrementing refcount (4->3)
  3464. [2022-06-17 08:44:57.247016] winreg_CloseKey: struct winreg_CloseKey
  3465. [2022-06-17 08:44:57.248648] out: struct winreg_CloseKey
  3466. [2022-06-17 08:44:57.250284] handle : *
  3467. [2022-06-17 08:44:57.251941] handle: struct policy_handle
  3468. [2022-06-17 08:44:57.253635] handle_type : 0x00000000 (0)
  3469. [2022-06-17 08:44:57.255285] uuid : 00000000-0000-0000-0000-000000000000
  3470. [2022-06-17 08:44:57.256923] result : WERR_OK
  3471. [2022-06-17 08:44:57.258567] winreg_CreateKey: struct winreg_CreateKey
  3472. [2022-06-17 08:44:57.260201] in: struct winreg_CreateKey
  3473. [2022-06-17 08:44:57.261831] handle : *
  3474. [2022-06-17 08:44:57.263511] handle: struct policy_handle
  3475. [2022-06-17 08:44:57.265169] handle_type : 0x00000001 (1)
  3476. [2022-06-17 08:44:57.266825] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  3477. [2022-06-17 08:44:57.268485] name: struct winreg_String
  3478. [2022-06-17 08:44:57.270119] name_len : 0x0062 (98)
  3479. [2022-06-17 08:44:57.271756] name_size : 0x0062 (98)
  3480. [2022-06-17 08:44:57.273444] name : *
  3481. [2022-06-17 08:44:57.275101] name : 'SYSTEM\CurrentControlSet\Services\RemoteRegistry'
  3482. [2022-06-17 08:44:57.276776] keyclass: struct winreg_String
  3483. [2022-06-17 08:44:57.278413] name_len : 0x0002 (2)
  3484. [2022-06-17 08:44:57.280050] name_size : 0x0002 (2)
  3485. [2022-06-17 08:44:57.281689] name : *
  3486. [2022-06-17 08:44:57.283370] name : ''
  3487. [2022-06-17 08:44:57.285027] options : 0x00000000 (0)
  3488. [2022-06-17 08:44:57.286667] 0: REG_OPTION_VOLATILE
  3489. [2022-06-17 08:44:57.288310] 0: REG_OPTION_CREATE_LINK
  3490. [2022-06-17 08:44:57.289949] 0: REG_OPTION_BACKUP_RESTORE
  3491. [2022-06-17 08:44:57.291574] 0: REG_OPTION_OPEN_LINK
  3492. [2022-06-17 08:44:57.293258] access_mask : 0x02000000 (33554432)
  3493. [2022-06-17 08:44:57.294922] 0: KEY_QUERY_VALUE
  3494. [2022-06-17 08:44:57.302957] 0: KEY_SET_VALUE
  3495. [2022-06-17 08:44:57.304682] 0: KEY_CREATE_SUB_KEY
  3496. [2022-06-17 08:44:57.306365] 0: KEY_ENUMERATE_SUB_KEYS
  3497. [2022-06-17 08:44:57.308020] 0: KEY_NOTIFY
  3498. [2022-06-17 08:44:57.313528] 0: KEY_CREATE_LINK
  3499. [2022-06-17 08:44:57.315340] 0: KEY_WOW64_64KEY
  3500. [2022-06-17 08:44:57.317030] 0: KEY_WOW64_32KEY
  3501. [2022-06-17 08:44:57.318698] secdesc : NULL
  3502. [2022-06-17 08:44:57.321174] action_taken : *
  3503. [2022-06-17 08:44:57.322849] action_taken : REG_ACTION_NONE (0)
  3504. [2022-06-17 08:44:57.324454] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\RemoteRegistry'
  3505. [2022-06-17 08:44:57.326005] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3506. [2022-06-17 08:44:57.327794] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3507. [2022-06-17 08:44:57.329447] regkey_open_onelevel: name = [SYSTEM]
  3508. [2022-06-17 08:44:57.331082] regdb_open: incrementing refcount (3->4)
  3509. [2022-06-17 08:44:57.332706] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  3510. [2022-06-17 08:44:57.334411] pathtree_find: Enter [\HKLM\SYSTEM]
  3511. [2022-06-17 08:44:57.336075] pathtree_find: Exit
  3512. [2022-06-17 08:44:57.337586] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  3513. [2022-06-17 08:44:57.339253] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3514. [2022-06-17 08:44:57.340902] regkey_open_onelevel: name = [CurrentControlSet]
  3515. [2022-06-17 08:44:57.342542] regdb_open: incrementing refcount (4->5)
  3516. [2022-06-17 08:44:57.344267] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  3517. [2022-06-17 08:44:57.345936] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  3518. [2022-06-17 08:44:57.347587] pathtree_find: Exit
  3519. [2022-06-17 08:44:57.349215] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  3520. [2022-06-17 08:44:57.350864] regdb_close: decrementing refcount (5->4)
  3521. [2022-06-17 08:44:57.352496] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  3522. [2022-06-17 08:44:57.354212] regkey_open_onelevel: name = [Services]
  3523. [2022-06-17 08:44:57.355840] regdb_open: incrementing refcount (4->5)
  3524. [2022-06-17 08:44:57.357470] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  3525. [2022-06-17 08:44:57.359137] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  3526. [2022-06-17 08:44:57.360788] pathtree_find: Exit
  3527. [2022-06-17 08:44:57.362411] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  3528. [2022-06-17 08:44:57.364161] regdb_close: decrementing refcount (5->4)
  3529. [2022-06-17 08:44:57.365804] regkey_open_onelevel: name = [RemoteRegistry]
  3530. [2022-06-17 08:44:57.367446] regdb_open: incrementing refcount (4->5)
  3531. [2022-06-17 08:44:57.369079] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  3532. [2022-06-17 08:44:57.370749] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  3533. [2022-06-17 08:44:57.372411] pathtree_find: Exit
  3534. [2022-06-17 08:44:57.374112] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  3535. [2022-06-17 08:44:57.375783] regdb_close: decrementing refcount (5->4)
  3536. [2022-06-17 08:44:57.377419] winreg_CreateKey: struct winreg_CreateKey
  3537. [2022-06-17 08:44:57.379052] out: struct winreg_CreateKey
  3538. [2022-06-17 08:44:57.380674] new_handle : *
  3539. [2022-06-17 08:44:57.382305] new_handle: struct policy_handle
  3540. [2022-06-17 08:44:57.384041] handle_type : 0x00000001 (1)
  3541. [2022-06-17 08:44:57.385700] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3542. [2022-06-17 08:44:57.387358] action_taken : *
  3543. [2022-06-17 08:44:57.388991] action_taken : REG_OPENED_EXISTING_KEY (2)
  3544. [2022-06-17 08:44:57.390616] result : WERR_OK
  3545. [2022-06-17 08:44:57.392250] winreg_SetValue: struct winreg_SetValue
  3546. [2022-06-17 08:44:57.393823] in: struct winreg_SetValue
  3547. [2022-06-17 08:44:57.395607] handle : *
  3548. [2022-06-17 08:44:57.397252] handle: struct policy_handle
  3549. [2022-06-17 08:44:57.398892] handle_type : 0x00000001 (1)
  3550. [2022-06-17 08:44:57.400520] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3551. [2022-06-17 08:44:57.402159] name: struct winreg_String
  3552. [2022-06-17 08:44:57.403852] name_len : 0x000c (12)
  3553. [2022-06-17 08:44:57.405505] name_size : 0x000c (12)
  3554. [2022-06-17 08:44:57.407155] name : *
  3555. [2022-06-17 08:44:57.408803] name : 'Start'
  3556. [2022-06-17 08:44:57.410324] type : REG_DWORD (4)
  3557. [2022-06-17 08:44:57.411829] data : *
  3558. [2022-06-17 08:44:57.413600] data: ARRAY(4)
  3559. [2022-06-17 08:44:57.415244] [0] : 0x02 (2)
  3560. [2022-06-17 08:44:57.416879] [1] : 0x00 (0)
  3561. [2022-06-17 08:44:57.418520] [2] : 0x00 (0)
  3562. [2022-06-17 08:44:57.420165] [3] : 0x00 (0)
  3563. [2022-06-17 08:44:57.421820] size : 0x00000004 (4)
  3564. [2022-06-17 08:44:57.423523] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:Start]
  3565. [2022-06-17 08:44:57.425198] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3566. [2022-06-17 08:44:57.426844] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry' (ops 0xb6ab32e8)
  3567. [2022-06-17 08:44:57.428512] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  3568. [2022-06-17 08:44:57.430183] regdb_unpack_values: value[0]: name[Start] len[4]
  3569. [2022-06-17 08:44:57.431830] regdb_unpack_values: value[1]: name[Type] len[4]
  3570. [2022-06-17 08:44:57.433525] regdb_unpack_values: value[2]: name[ErrorControl] len[4]
  3571. [2022-06-17 08:44:57.435193] regdb_unpack_values: value[3]: name[ObjectName] len[24]
  3572. [2022-06-17 08:44:57.436826] regdb_unpack_values: value[4]: name[DisplayName] len[48]
  3573. [2022-06-17 08:44:57.438464] regdb_unpack_values: value[5]: name[ImagePath] len[54]
  3574. [2022-06-17 08:44:57.440100] regdb_unpack_values: value[6]: name[Description] len[126]
  3575. [2022-06-17 08:44:57.441733] winreg_SetValue: struct winreg_SetValue
  3576. [2022-06-17 08:44:57.443417] out: struct winreg_SetValue
  3577. [2022-06-17 08:44:57.445057] result : WERR_OK
  3578. [2022-06-17 08:44:57.446702] winreg_SetValue: struct winreg_SetValue
  3579. [2022-06-17 08:44:57.448338] in: struct winreg_SetValue
  3580. [2022-06-17 08:44:57.449964] handle : *
  3581. [2022-06-17 08:44:57.451590] handle: struct policy_handle
  3582. [2022-06-17 08:44:57.453271] handle_type : 0x00000001 (1)
  3583. [2022-06-17 08:44:57.454931] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3584. [2022-06-17 08:44:57.456592] name: struct winreg_String
  3585. [2022-06-17 08:44:57.458228] name_len : 0x000a (10)
  3586. [2022-06-17 08:44:57.459865] name_size : 0x000a (10)
  3587. [2022-06-17 08:44:57.461494] name : *
  3588. [2022-06-17 08:44:57.463047] name : 'Type'
  3589. [2022-06-17 08:44:57.464843] type : REG_DWORD (4)
  3590. [2022-06-17 08:44:57.466487] data : *
  3591. [2022-06-17 08:44:57.468125] data: ARRAY(4)
  3592. [2022-06-17 08:44:57.469750] [0] : 0x10 (16)
  3593. [2022-06-17 08:44:57.471383] [1] : 0x00 (0)
  3594. [2022-06-17 08:44:57.473058] [2] : 0x00 (0)
  3595. [2022-06-17 08:44:57.474717] [3] : 0x00 (0)
  3596. [2022-06-17 08:44:57.476354] size : 0x00000004 (4)
  3597. [2022-06-17 08:44:57.478004] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:Type]
  3598. [2022-06-17 08:44:57.479669] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3599. [2022-06-17 08:44:57.481314] winreg_SetValue: struct winreg_SetValue
  3600. [2022-06-17 08:44:57.482993] out: struct winreg_SetValue
  3601. [2022-06-17 08:44:57.484643] result : WERR_OK
  3602. [2022-06-17 08:44:57.486164] winreg_SetValue: struct winreg_SetValue
  3603. [2022-06-17 08:44:57.487652] in: struct winreg_SetValue
  3604. [2022-06-17 08:44:57.489140] handle : *
  3605. [2022-06-17 08:44:57.490919] handle: struct policy_handle
  3606. [2022-06-17 08:44:57.492568] handle_type : 0x00000001 (1)
  3607. [2022-06-17 08:44:57.494314] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3608. [2022-06-17 08:44:57.495972] name: struct winreg_String
  3609. [2022-06-17 08:44:57.497603] name_len : 0x001a (26)
  3610. [2022-06-17 08:44:57.499251] name_size : 0x001a (26)
  3611. [2022-06-17 08:44:57.500897] name : *
  3612. [2022-06-17 08:44:57.502535] name : 'ErrorControl'
  3613. [2022-06-17 08:44:57.504273] type : REG_DWORD (4)
  3614. [2022-06-17 08:44:57.505919] data : *
  3615. [2022-06-17 08:44:57.507548] data: ARRAY(4)
  3616. [2022-06-17 08:44:57.509190] [0] : 0x01 (1)
  3617. [2022-06-17 08:44:57.510837] [1] : 0x00 (0)
  3618. [2022-06-17 08:44:57.512461] [2] : 0x00 (0)
  3619. [2022-06-17 08:44:57.514162] [3] : 0x00 (0)
  3620. [2022-06-17 08:44:57.515804] size : 0x00000004 (4)
  3621. [2022-06-17 08:44:57.517454] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:ErrorControl]
  3622. [2022-06-17 08:44:57.519133] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3623. [2022-06-17 08:44:57.520777] winreg_SetValue: struct winreg_SetValue
  3624. [2022-06-17 08:44:57.522289] out: struct winreg_SetValue
  3625. [2022-06-17 08:44:57.524108] result : WERR_OK
  3626. [2022-06-17 08:44:57.525755] winreg_SetValue: struct winreg_SetValue
  3627. [2022-06-17 08:44:57.527407] in: struct winreg_SetValue
  3628. [2022-06-17 08:44:57.529046] handle : *
  3629. [2022-06-17 08:44:57.530673] handle: struct policy_handle
  3630. [2022-06-17 08:44:57.532321] handle_type : 0x00000001 (1)
  3631. [2022-06-17 08:44:57.534049] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3632. [2022-06-17 08:44:57.535702] name: struct winreg_String
  3633. [2022-06-17 08:44:57.537344] name_len : 0x0016 (22)
  3634. [2022-06-17 08:44:57.538979] name_size : 0x0016 (22)
  3635. [2022-06-17 08:44:57.540622] name : *
  3636. [2022-06-17 08:44:57.542254] name : 'ObjectName'
  3637. [2022-06-17 08:44:57.543957] type : REG_SZ (1)
  3638. [2022-06-17 08:44:57.545604] data : *
  3639. [2022-06-17 08:44:57.547235] data: ARRAY(24)
  3640. [2022-06-17 08:44:57.548856] [0] : 0x4c (76)
  3641. [2022-06-17 08:44:57.550487] [1] : 0x00 (0)
  3642. [2022-06-17 08:44:57.552129] [2] : 0x6f (111)
  3643. [2022-06-17 08:44:57.553826] [3] : 0x00 (0)
  3644. [2022-06-17 08:44:57.555597] [4] : 0x63 (99)
  3645. [2022-06-17 08:44:57.557239] [5] : 0x00 (0)
  3646. [2022-06-17 08:44:57.562974] [6] : 0x61 (97)
  3647. [2022-06-17 08:44:57.571272] [7] : 0x00 (0)
  3648. [2022-06-17 08:44:57.573173] [8] : 0x6c (108)
  3649. [2022-06-17 08:44:57.574901] [9] : 0x00 (0)
  3650. [2022-06-17 08:44:57.576586] [10] : 0x53 (83)
  3651. [2022-06-17 08:44:57.578244] [11] : 0x00 (0)
  3652. [2022-06-17 08:44:57.579886] [12] : 0x79 (121)
  3653. [2022-06-17 08:44:57.581521] [13] : 0x00 (0)
  3654. [2022-06-17 08:44:57.583210] [14] : 0x73 (115)
  3655. [2022-06-17 08:44:57.584865] [15] : 0x00 (0)
  3656. [2022-06-17 08:44:57.586504] [16] : 0x74 (116)
  3657. [2022-06-17 08:44:57.588142] [17] : 0x00 (0)
  3658. [2022-06-17 08:44:57.589787] [18] : 0x65 (101)
  3659. [2022-06-17 08:44:57.591434] [19] : 0x00 (0)
  3660. [2022-06-17 08:44:57.593121] [20] : 0x6d (109)
  3661. [2022-06-17 08:44:57.594779] [21] : 0x00 (0)
  3662. [2022-06-17 08:44:57.596424] [22] : 0x00 (0)
  3663. [2022-06-17 08:44:57.598065] [23] : 0x00 (0)
  3664. [2022-06-17 08:44:57.599715] size : 0x00000018 (24)
  3665. [2022-06-17 08:44:57.601358] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:ObjectName]
  3666. [2022-06-17 08:44:57.603084] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3667. [2022-06-17 08:44:57.604760] winreg_SetValue: struct winreg_SetValue
  3668. [2022-06-17 08:44:57.606403] out: struct winreg_SetValue
  3669. [2022-06-17 08:44:57.608032] result : WERR_OK
  3670. [2022-06-17 08:44:57.609674] winreg_SetValue: struct winreg_SetValue
  3671. [2022-06-17 08:44:57.611196] in: struct winreg_SetValue
  3672. [2022-06-17 08:44:57.612983] handle : *
  3673. [2022-06-17 08:44:57.614617] handle: struct policy_handle
  3674. [2022-06-17 08:44:57.616266] handle_type : 0x00000001 (1)
  3675. [2022-06-17 08:44:57.617924] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3676. [2022-06-17 08:44:57.619572] name: struct winreg_String
  3677. [2022-06-17 08:44:57.621200] name_len : 0x0018 (24)
  3678. [2022-06-17 08:44:57.622844] name_size : 0x0018 (24)
  3679. [2022-06-17 08:44:57.624552] name : *
  3680. [2022-06-17 08:44:57.626206] name : 'DisplayName'
  3681. [2022-06-17 08:44:57.627853] type : REG_SZ (1)
  3682. [2022-06-17 08:44:57.629481] data : *
  3683. [2022-06-17 08:44:57.631102] data: ARRAY(48)
  3684. [2022-06-17 08:44:57.632731] [0] : 0x52 (82)
  3685. [2022-06-17 08:44:57.634440] [1] : 0x00 (0)
  3686. [2022-06-17 08:44:57.636088] [2] : 0x65 (101)
  3687. [2022-06-17 08:44:57.637729] [3] : 0x00 (0)
  3688. [2022-06-17 08:44:57.639365] [4] : 0x6d (109)
  3689. [2022-06-17 08:44:57.640997] [5] : 0x00 (0)
  3690. [2022-06-17 08:44:57.642638] [6] : 0x6f (111)
  3691. [2022-06-17 08:44:57.644352] [7] : 0x00 (0)
  3692. [2022-06-17 08:44:57.645995] [8] : 0x74 (116)
  3693. [2022-06-17 08:44:57.647642] [9] : 0x00 (0)
  3694. [2022-06-17 08:44:57.649165] [10] : 0x65 (101)
  3695. [2022-06-17 08:44:57.650668] [11] : 0x00 (0)
  3696. [2022-06-17 08:44:57.652164] [12] : 0x20 (32)
  3697. [2022-06-17 08:44:57.653708] [13] : 0x00 (0)
  3698. [2022-06-17 08:44:57.655206] [14] : 0x52 (82)
  3699. [2022-06-17 08:44:57.656705] [15] : 0x00 (0)
  3700. [2022-06-17 08:44:57.658196] [16] : 0x65 (101)
  3701. [2022-06-17 08:44:57.659698] [17] : 0x00 (0)
  3702. [2022-06-17 08:44:57.661198] [18] : 0x67 (103)
  3703. [2022-06-17 08:44:57.662689] [19] : 0x00 (0)
  3704. [2022-06-17 08:44:57.664501] [20] : 0x69 (105)
  3705. [2022-06-17 08:44:57.666027] [21] : 0x00 (0)
  3706. [2022-06-17 08:44:57.667524] [22] : 0x73 (115)
  3707. [2022-06-17 08:44:57.669022] [23] : 0x00 (0)
  3708. [2022-06-17 08:44:57.670524] [24] : 0x74 (116)
  3709. [2022-06-17 08:44:57.672029] [25] : 0x00 (0)
  3710. [2022-06-17 08:44:57.673579] [26] : 0x72 (114)
  3711. [2022-06-17 08:44:57.675084] [27] : 0x00 (0)
  3712. [2022-06-17 08:44:57.676579] [28] : 0x79 (121)
  3713. [2022-06-17 08:44:57.678080] [29] : 0x00 (0)
  3714. [2022-06-17 08:44:57.679777] [30] : 0x20 (32)
  3715. [2022-06-17 08:44:57.681434] [31] : 0x00 (0)
  3716. [2022-06-17 08:44:57.682991] [32] : 0x53 (83)
  3717. [2022-06-17 08:44:57.684507] [33] : 0x00 (0)
  3718. [2022-06-17 08:44:57.686011] [34] : 0x65 (101)
  3719. [2022-06-17 08:44:57.687507] [35] : 0x00 (0)
  3720. [2022-06-17 08:44:57.688992] [36] : 0x72 (114)
  3721. [2022-06-17 08:44:57.690485] [37] : 0x00 (0)
  3722. [2022-06-17 08:44:57.691976] [38] : 0x76 (118)
  3723. [2022-06-17 08:44:57.693712] [39] : 0x00 (0)
  3724. [2022-06-17 08:44:57.695254] [40] : 0x69 (105)
  3725. [2022-06-17 08:44:57.696761] [41] : 0x00 (0)
  3726. [2022-06-17 08:44:57.698247] [42] : 0x63 (99)
  3727. [2022-06-17 08:44:57.699742] [43] : 0x00 (0)
  3728. [2022-06-17 08:44:57.701231] [44] : 0x65 (101)
  3729. [2022-06-17 08:44:57.702721] [45] : 0x00 (0)
  3730. [2022-06-17 08:44:57.704423] [46] : 0x00 (0)
  3731. [2022-06-17 08:44:57.706512] [47] : 0x00 (0)
  3732. [2022-06-17 08:44:57.708168] size : 0x00000030 (48)
  3733. [2022-06-17 08:44:57.709816] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:DisplayName]
  3734. [2022-06-17 08:44:57.711492] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3735. [2022-06-17 08:44:57.713196] winreg_SetValue: struct winreg_SetValue
  3736. [2022-06-17 08:44:57.714840] out: struct winreg_SetValue
  3737. [2022-06-17 08:44:57.716485] result : WERR_OK
  3738. [2022-06-17 08:44:57.718141] winreg_SetValue: struct winreg_SetValue
  3739. [2022-06-17 08:44:57.719787] in: struct winreg_SetValue
  3740. [2022-06-17 08:44:57.721416] handle : *
  3741. [2022-06-17 08:44:57.723096] handle: struct policy_handle
  3742. [2022-06-17 08:44:57.724741] handle_type : 0x00000001 (1)
  3743. [2022-06-17 08:44:57.726387] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3744. [2022-06-17 08:44:57.728050] name: struct winreg_String
  3745. [2022-06-17 08:44:57.729699] name_len : 0x0014 (20)
  3746. [2022-06-17 08:44:57.731351] name_size : 0x0014 (20)
  3747. [2022-06-17 08:44:57.733032] name : *
  3748. [2022-06-17 08:44:57.734684] name : 'ImagePath'
  3749. [2022-06-17 08:44:57.736332] type : REG_SZ (1)
  3750. [2022-06-17 08:44:57.737966] data : *
  3751. [2022-06-17 08:44:57.739598] data: ARRAY(54)
  3752. [2022-06-17 08:44:57.741232] [0] : 0x2f (47)
  3753. [2022-06-17 08:44:57.742922] [1] : 0x00 (0)
  3754. [2022-06-17 08:44:57.744591] [2] : 0x75 (117)
  3755. [2022-06-17 08:44:57.746245] [3] : 0x00 (0)
  3756. [2022-06-17 08:44:57.747883] [4] : 0x73 (115)
  3757. [2022-06-17 08:44:57.749520] [5] : 0x00 (0)
  3758. [2022-06-17 08:44:57.751152] [6] : 0x72 (114)
  3759. [2022-06-17 08:44:57.752794] [7] : 0x00 (0)
  3760. [2022-06-17 08:44:57.754503] [8] : 0x2f (47)
  3761. [2022-06-17 08:44:57.756146] [9] : 0x00 (0)
  3762. [2022-06-17 08:44:57.757791] [10] : 0x6c (108)
  3763. [2022-06-17 08:44:57.759445] [11] : 0x00 (0)
  3764. [2022-06-17 08:44:57.760953] [12] : 0x69 (105)
  3765. [2022-06-17 08:44:57.762455] [13] : 0x00 (0)
  3766. [2022-06-17 08:44:57.764292] [14] : 0x62 (98)
  3767. [2022-06-17 08:44:57.765947] [15] : 0x00 (0)
  3768. [2022-06-17 08:44:57.767582] [16] : 0x2f (47)
  3769. [2022-06-17 08:44:57.769229] [17] : 0x00 (0)
  3770. [2022-06-17 08:44:57.770857] [18] : 0x73 (115)
  3771. [2022-06-17 08:44:57.772494] [19] : 0x00 (0)
  3772. [2022-06-17 08:44:57.774200] [20] : 0x61 (97)
  3773. [2022-06-17 08:44:57.775851] [21] : 0x00 (0)
  3774. [2022-06-17 08:44:57.777378] [22] : 0x6d (109)
  3775. [2022-06-17 08:44:57.779023] [23] : 0x00 (0)
  3776. [2022-06-17 08:44:57.780676] [24] : 0x62 (98)
  3777. [2022-06-17 08:44:57.782318] [25] : 0x00 (0)
  3778. [2022-06-17 08:44:57.784734] [26] : 0x61 (97)
  3779. [2022-06-17 08:44:57.786389] [27] : 0x00 (0)
  3780. [2022-06-17 08:44:57.788038] [28] : 0x2f (47)
  3781. [2022-06-17 08:44:57.789690] [29] : 0x00 (0)
  3782. [2022-06-17 08:44:57.791348] [30] : 0x73 (115)
  3783. [2022-06-17 08:44:57.793032] [31] : 0x00 (0)
  3784. [2022-06-17 08:44:57.794560] [32] : 0x76 (118)
  3785. [2022-06-17 08:44:57.796061] [33] : 0x00 (0)
  3786. [2022-06-17 08:44:57.797791] [34] : 0x63 (99)
  3787. [2022-06-17 08:44:57.799440] [35] : 0x00 (0)
  3788. [2022-06-17 08:44:57.801080] [36] : 0x63 (99)
  3789. [2022-06-17 08:44:57.802731] [37] : 0x00 (0)
  3790. [2022-06-17 08:44:57.804443] [38] : 0x74 (116)
  3791. [2022-06-17 08:44:57.806093] [39] : 0x00 (0)
  3792. [2022-06-17 08:44:57.807729] [40] : 0x6c (108)
  3793. [2022-06-17 08:44:57.809371] [41] : 0x00 (0)
  3794. [2022-06-17 08:44:57.823029] [42] : 0x2f (47)
  3795. [2022-06-17 08:44:57.824997] [43] : 0x00 (0)
  3796. [2022-06-17 08:44:57.826741] [44] : 0x73 (115)
  3797. [2022-06-17 08:44:57.828305] [45] : 0x00 (0)
  3798. [2022-06-17 08:44:57.830085] [46] : 0x6d (109)
  3799. [2022-06-17 08:44:57.831740] [47] : 0x00 (0)
  3800. [2022-06-17 08:44:57.833433] [48] : 0x62 (98)
  3801. [2022-06-17 08:44:57.835093] [49] : 0x00 (0)
  3802. [2022-06-17 08:44:57.836742] [50] : 0x64 (100)
  3803. [2022-06-17 08:44:57.838399] [51] : 0x00 (0)
  3804. [2022-06-17 08:44:57.841039] [52] : 0x00 (0)
  3805. [2022-06-17 08:44:57.842705] [53] : 0x00 (0)
  3806. [2022-06-17 08:44:57.844418] size : 0x00000036 (54)
  3807. [2022-06-17 08:44:57.846070] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:ImagePath]
  3808. [2022-06-17 08:44:57.847734] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3809. [2022-06-17 08:44:57.849387] winreg_SetValue: struct winreg_SetValue
  3810. [2022-06-17 08:44:57.851026] out: struct winreg_SetValue
  3811. [2022-06-17 08:44:57.852678] result : WERR_OK
  3812. [2022-06-17 08:44:57.854378] winreg_SetValue: struct winreg_SetValue
  3813. [2022-06-17 08:44:57.856040] in: struct winreg_SetValue
  3814. [2022-06-17 08:44:57.857676] handle : *
  3815. [2022-06-17 08:44:57.859315] handle: struct policy_handle
  3816. [2022-06-17 08:44:57.860945] handle_type : 0x00000001 (1)
  3817. [2022-06-17 08:44:57.862586] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3818. [2022-06-17 08:44:57.864336] name: struct winreg_String
  3819. [2022-06-17 08:44:57.865982] name_len : 0x0018 (24)
  3820. [2022-06-17 08:44:57.867629] name_size : 0x0018 (24)
  3821. [2022-06-17 08:44:57.869264] name : *
  3822. [2022-06-17 08:44:57.870907] name : 'Description'
  3823. [2022-06-17 08:44:57.872541] type : REG_SZ (1)
  3824. [2022-06-17 08:44:57.874269] data : *
  3825. [2022-06-17 08:44:57.875922] data: ARRAY(126)
  3826. [2022-06-17 08:44:57.877567] [0] : 0x49 (73)
  3827. [2022-06-17 08:44:57.879215] [1] : 0x00 (0)
  3828. [2022-06-17 08:44:57.880856] [2] : 0x6e (110)
  3829. [2022-06-17 08:44:57.882487] [3] : 0x00 (0)
  3830. [2022-06-17 08:44:57.884186] [4] : 0x74 (116)
  3831. [2022-06-17 08:44:57.885828] [5] : 0x00 (0)
  3832. [2022-06-17 08:44:57.887481] [6] : 0x65 (101)
  3833. [2022-06-17 08:44:57.889126] [7] : 0x00 (0)
  3834. [2022-06-17 08:44:57.890770] [8] : 0x72 (114)
  3835. [2022-06-17 08:44:57.892417] [9] : 0x00 (0)
  3836. [2022-06-17 08:44:57.894135] [10] : 0x6e (110)
  3837. [2022-06-17 08:44:57.895653] [11] : 0x00 (0)
  3838. [2022-06-17 08:44:57.897144] [12] : 0x61 (97)
  3839. [2022-06-17 08:44:57.898775] [13] : 0x00 (0)
  3840. [2022-06-17 08:44:57.900431] [14] : 0x6c (108)
  3841. [2022-06-17 08:44:57.902075] [15] : 0x00 (0)
  3842. [2022-06-17 08:44:57.903784] [16] : 0x20 (32)
  3843. [2022-06-17 08:44:57.905438] [17] : 0x00 (0)
  3844. [2022-06-17 08:44:57.907069] [18] : 0x73 (115)
  3845. [2022-06-17 08:44:57.908710] [19] : 0x00 (0)
  3846. [2022-06-17 08:44:57.910343] [20] : 0x65 (101)
  3847. [2022-06-17 08:44:57.911988] [21] : 0x00 (0)
  3848. [2022-06-17 08:44:57.913677] [22] : 0x72 (114)
  3849. [2022-06-17 08:44:57.915329] [23] : 0x00 (0)
  3850. [2022-06-17 08:44:57.916966] [24] : 0x76 (118)
  3851. [2022-06-17 08:44:57.918620] [25] : 0x00 (0)
  3852. [2022-06-17 08:44:57.920254] [26] : 0x69 (105)
  3853. [2022-06-17 08:44:57.921898] [27] : 0x00 (0)
  3854. [2022-06-17 08:44:57.923584] [28] : 0x63 (99)
  3855. [2022-06-17 08:44:57.925240] [29] : 0x00 (0)
  3856. [2022-06-17 08:44:57.926883] [30] : 0x65 (101)
  3857. [2022-06-17 08:44:57.928519] [31] : 0x00 (0)
  3858. [2022-06-17 08:44:57.930146] [32] : 0x20 (32)
  3859. [2022-06-17 08:44:57.931784] [33] : 0x00 (0)
  3860. [2022-06-17 08:44:57.933474] [34] : 0x70 (112)
  3861. [2022-06-17 08:44:57.935125] [35] : 0x00 (0)
  3862. [2022-06-17 08:44:57.936776] [36] : 0x72 (114)
  3863. [2022-06-17 08:44:57.938418] [37] : 0x00 (0)
  3864. [2022-06-17 08:44:57.940059] [38] : 0x6f (111)
  3865. [2022-06-17 08:44:57.941691] [39] : 0x00 (0)
  3866. [2022-06-17 08:44:57.943400] [40] : 0x76 (118)
  3867. [2022-06-17 08:44:57.945069] [41] : 0x00 (0)
  3868. [2022-06-17 08:44:57.946719] [42] : 0x69 (105)
  3869. [2022-06-17 08:44:57.948363] [43] : 0x00 (0)
  3870. [2022-06-17 08:44:57.950004] [44] : 0x64 (100)
  3871. [2022-06-17 08:44:57.951649] [45] : 0x00 (0)
  3872. [2022-06-17 08:44:57.953328] [46] : 0x69 (105)
  3873. [2022-06-17 08:44:57.954976] [47] : 0x00 (0)
  3874. [2022-06-17 08:44:57.956605] [48] : 0x6e (110)
  3875. [2022-06-17 08:44:57.958240] [49] : 0x00 (0)
  3876. [2022-06-17 08:44:57.959871] [50] : 0x67 (103)
  3877. [2022-06-17 08:44:57.961526] [51] : 0x00 (0)
  3878. [2022-06-17 08:44:57.963213] [52] : 0x20 (32)
  3879. [2022-06-17 08:44:57.964866] [53] : 0x00 (0)
  3880. [2022-06-17 08:44:57.966497] [54] : 0x72 (114)
  3881. [2022-06-17 08:44:57.968140] [55] : 0x00 (0)
  3882. [2022-06-17 08:44:57.969791] [56] : 0x65 (101)
  3883. [2022-06-17 08:44:57.971433] [57] : 0x00 (0)
  3884. [2022-06-17 08:44:57.973121] [58] : 0x6d (109)
  3885. [2022-06-17 08:44:57.974800] [59] : 0x00 (0)
  3886. [2022-06-17 08:44:57.976442] [60] : 0x6f (111)
  3887. [2022-06-17 08:44:57.978074] [61] : 0x00 (0)
  3888. [2022-06-17 08:44:57.979704] [62] : 0x74 (116)
  3889. [2022-06-17 08:44:57.981338] [63] : 0x00 (0)
  3890. [2022-06-17 08:44:57.983076] [64] : 0x65 (101)
  3891. [2022-06-17 08:44:57.984781] [65] : 0x00 (0)
  3892. [2022-06-17 08:44:57.986438] [66] : 0x20 (32)
  3893. [2022-06-17 08:44:57.988085] [67] : 0x00 (0)
  3894. [2022-06-17 08:44:57.989732] [68] : 0x61 (97)
  3895. [2022-06-17 08:44:57.991370] [69] : 0x00 (0)
  3896. [2022-06-17 08:44:57.993042] [70] : 0x63 (99)
  3897. [2022-06-17 08:44:57.994689] [71] : 0x00 (0)
  3898. [2022-06-17 08:44:57.996330] [72] : 0x63 (99)
  3899. [2022-06-17 08:44:57.997978] [73] : 0x00 (0)
  3900. [2022-06-17 08:44:57.999620] [74] : 0x65 (101)
  3901. [2022-06-17 08:44:58.001254] [75] : 0x00 (0)
  3902. [2022-06-17 08:44:58.002940] [76] : 0x73 (115)
  3903. [2022-06-17 08:44:58.004597] [77] : 0x00 (0)
  3904. [2022-06-17 08:44:58.006241] [78] : 0x73 (115)
  3905. [2022-06-17 08:44:58.007881] [79] : 0x00 (0)
  3906. [2022-06-17 08:44:58.009653] [80] : 0x20 (32)
  3907. [2022-06-17 08:44:58.011311] [81] : 0x00 (0)
  3908. [2022-06-17 08:44:58.012993] [82] : 0x74 (116)
  3909. [2022-06-17 08:44:58.014655] [83] : 0x00 (0)
  3910. [2022-06-17 08:44:58.016306] [84] : 0x6f (111)
  3911. [2022-06-17 08:44:58.017935] [85] : 0x00 (0)
  3912. [2022-06-17 08:44:58.019560] [86] : 0x20 (32)
  3913. [2022-06-17 08:44:58.021195] [87] : 0x00 (0)
  3914. [2022-06-17 08:44:58.022838] [88] : 0x74 (116)
  3915. [2022-06-17 08:44:58.024563] [89] : 0x00 (0)
  3916. [2022-06-17 08:44:58.026206] [90] : 0x68 (104)
  3917. [2022-06-17 08:44:58.027834] [91] : 0x00 (0)
  3918. [2022-06-17 08:44:58.029472] [92] : 0x65 (101)
  3919. [2022-06-17 08:44:58.031107] [93] : 0x00 (0)
  3920. [2022-06-17 08:44:58.032742] [94] : 0x20 (32)
  3921. [2022-06-17 08:44:58.034461] [95] : 0x00 (0)
  3922. [2022-06-17 08:44:58.036109] [96] : 0x53 (83)
  3923. [2022-06-17 08:44:58.037757] [97] : 0x00 (0)
  3924. [2022-06-17 08:44:58.039388] [98] : 0x61 (97)
  3925. [2022-06-17 08:44:58.041027] [99] : 0x00 (0)
  3926. [2022-06-17 08:44:58.042667] [100] : 0x6d (109)
  3927. [2022-06-17 08:44:58.044363] [101] : 0x00 (0)
  3928. [2022-06-17 08:44:58.046014] [102] : 0x62 (98)
  3929. [2022-06-17 08:44:58.047855] [103] : 0x00 (0)
  3930. [2022-06-17 08:44:58.049536] [104] : 0x61 (97)
  3931. [2022-06-17 08:44:58.051192] [105] : 0x00 (0)
  3932. [2022-06-17 08:44:58.052831] [106] : 0x20 (32)
  3933. [2022-06-17 08:44:58.054531] [107] : 0x00 (0)
  3934. [2022-06-17 08:44:58.056177] [108] : 0x72 (114)
  3935. [2022-06-17 08:44:58.057828] [109] : 0x00 (0)
  3936. [2022-06-17 08:44:58.059474] [110] : 0x65 (101)
  3937. [2022-06-17 08:44:58.061118] [111] : 0x00 (0)
  3938. [2022-06-17 08:44:58.062747] [112] : 0x67 (103)
  3939. [2022-06-17 08:44:58.064513] [113] : 0x00 (0)
  3940. [2022-06-17 08:44:58.072993] [114] : 0x69 (105)
  3941. [2022-06-17 08:44:58.074921] [115] : 0x00 (0)
  3942. [2022-06-17 08:44:58.076654] [116] : 0x73 (115)
  3943. [2022-06-17 08:44:58.078330] [117] : 0x00 (0)
  3944. [2022-06-17 08:44:58.089382] [118] : 0x74 (116)
  3945. [2022-06-17 08:44:58.091299] [119] : 0x00 (0)
  3946. [2022-06-17 08:44:58.093067] [120] : 0x72 (114)
  3947. [2022-06-17 08:44:58.094762] [121] : 0x00 (0)
  3948. [2022-06-17 08:44:58.096408] [122] : 0x79 (121)
  3949. [2022-06-17 08:44:58.098064] [123] : 0x00 (0)
  3950. [2022-06-17 08:44:58.099721] [124] : 0x00 (0)
  3951. [2022-06-17 08:44:58.101362] [125] : 0x00 (0)
  3952. [2022-06-17 08:44:58.103055] size : 0x0000007e (126)
  3953. [2022-06-17 08:44:58.104716] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry:Description]
  3954. [2022-06-17 08:44:58.106376] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  3955. [2022-06-17 08:44:58.108016] winreg_SetValue: struct winreg_SetValue
  3956. [2022-06-17 08:44:58.109650] out: struct winreg_SetValue
  3957. [2022-06-17 08:44:58.111287] result : WERR_OK
  3958. [2022-06-17 08:44:58.112979] winreg_CloseKey: struct winreg_CloseKey
  3959. [2022-06-17 08:44:58.114635] in: struct winreg_CloseKey
  3960. [2022-06-17 08:44:58.116281] handle : *
  3961. [2022-06-17 08:44:58.117798] handle: struct policy_handle
  3962. [2022-06-17 08:44:58.119543] handle_type : 0x00000001 (1)
  3963. [2022-06-17 08:44:58.121182] uuid : 1a3e1e5e-fd26-4094-9542-6003d1e4aeb8
  3964. [2022-06-17 08:44:58.122842] regdb_close: decrementing refcount (4->3)
  3965. [2022-06-17 08:44:58.124543] winreg_CloseKey: struct winreg_CloseKey
  3966. [2022-06-17 08:44:58.126191] out: struct winreg_CloseKey
  3967. [2022-06-17 08:44:58.127698] handle : *
  3968. [2022-06-17 08:44:58.129355] handle: struct policy_handle
  3969. [2022-06-17 08:44:58.131023] handle_type : 0x00000000 (0)
  3970. [2022-06-17 08:44:58.132784] uuid : 00000000-0000-0000-0000-000000000000
  3971. [2022-06-17 08:44:58.134504] result : WERR_OK
  3972. [2022-06-17 08:44:58.136160] winreg_CreateKey: struct winreg_CreateKey
  3973. [2022-06-17 08:44:58.137804] in: struct winreg_CreateKey
  3974. [2022-06-17 08:44:58.139437] handle : *
  3975. [2022-06-17 08:44:58.141071] handle: struct policy_handle
  3976. [2022-06-17 08:44:58.142683] handle_type : 0x00000001 (1)
  3977. [2022-06-17 08:44:58.144265] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  3978. [2022-06-17 08:44:58.146027] name: struct winreg_String
  3979. [2022-06-17 08:44:58.147677] name_len : 0x0074 (116)
  3980. [2022-06-17 08:44:58.149328] name_size : 0x0074 (116)
  3981. [2022-06-17 08:44:58.150976] name : *
  3982. [2022-06-17 08:44:58.152616] name : 'SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security'
  3983. [2022-06-17 08:44:58.154380] keyclass: struct winreg_String
  3984. [2022-06-17 08:44:58.156031] name_len : 0x0002 (2)
  3985. [2022-06-17 08:44:58.157675] name_size : 0x0002 (2)
  3986. [2022-06-17 08:44:58.159311] name : *
  3987. [2022-06-17 08:44:58.160948] name : ''
  3988. [2022-06-17 08:44:58.162578] options : 0x00000000 (0)
  3989. [2022-06-17 08:44:58.164310] 0: REG_OPTION_VOLATILE
  3990. [2022-06-17 08:44:58.165955] 0: REG_OPTION_CREATE_LINK
  3991. [2022-06-17 08:44:58.167578] 0: REG_OPTION_BACKUP_RESTORE
  3992. [2022-06-17 08:44:58.169212] 0: REG_OPTION_OPEN_LINK
  3993. [2022-06-17 08:44:58.170833] access_mask : 0x02000000 (33554432)
  3994. [2022-06-17 08:44:58.172479] 0: KEY_QUERY_VALUE
  3995. [2022-06-17 08:44:58.174231] 0: KEY_SET_VALUE
  3996. [2022-06-17 08:44:58.175874] 0: KEY_CREATE_SUB_KEY
  3997. [2022-06-17 08:44:58.177506] 0: KEY_ENUMERATE_SUB_KEYS
  3998. [2022-06-17 08:44:58.179137] 0: KEY_NOTIFY
  3999. [2022-06-17 08:44:58.180776] 0: KEY_CREATE_LINK
  4000. [2022-06-17 08:44:58.182413] 0: KEY_WOW64_64KEY
  4001. [2022-06-17 08:44:58.184170] 0: KEY_WOW64_32KEY
  4002. [2022-06-17 08:44:58.185831] secdesc : NULL
  4003. [2022-06-17 08:44:58.187464] action_taken : *
  4004. [2022-06-17 08:44:58.189088] action_taken : REG_OPENED_EXISTING_KEY (2)
  4005. [2022-06-17 08:44:58.190730] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security'
  4006. [2022-06-17 08:44:58.192389] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4007. [2022-06-17 08:44:58.194099] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4008. [2022-06-17 08:44:58.195751] regkey_open_onelevel: name = [SYSTEM]
  4009. [2022-06-17 08:44:58.197393] regdb_open: incrementing refcount (3->4)
  4010. [2022-06-17 08:44:58.199038] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  4011. [2022-06-17 08:44:58.200677] pathtree_find: Enter [\HKLM\SYSTEM]
  4012. [2022-06-17 08:44:58.202308] pathtree_find: Exit
  4013. [2022-06-17 08:44:58.203990] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  4014. [2022-06-17 08:44:58.205639] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4015. [2022-06-17 08:44:58.207289] regkey_open_onelevel: name = [CurrentControlSet]
  4016. [2022-06-17 08:44:58.208934] regdb_open: incrementing refcount (4->5)
  4017. [2022-06-17 08:44:58.210567] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  4018. [2022-06-17 08:44:58.212227] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  4019. [2022-06-17 08:44:58.213905] pathtree_find: Exit
  4020. [2022-06-17 08:44:58.215529] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  4021. [2022-06-17 08:44:58.217189] regdb_close: decrementing refcount (5->4)
  4022. [2022-06-17 08:44:58.218819] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4023. [2022-06-17 08:44:58.220469] regkey_open_onelevel: name = [Services]
  4024. [2022-06-17 08:44:58.222105] regdb_open: incrementing refcount (4->5)
  4025. [2022-06-17 08:44:58.223823] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  4026. [2022-06-17 08:44:58.225488] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  4027. [2022-06-17 08:44:58.227030] pathtree_find: Exit
  4028. [2022-06-17 08:44:58.228630] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  4029. [2022-06-17 08:44:58.230290] regdb_close: decrementing refcount (5->4)
  4030. [2022-06-17 08:44:58.231919] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4031. [2022-06-17 08:44:58.233625] regkey_open_onelevel: name = [RemoteRegistry]
  4032. [2022-06-17 08:44:58.235288] regdb_open: incrementing refcount (4->5)
  4033. [2022-06-17 08:44:58.236928] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  4034. [2022-06-17 08:44:58.238589] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  4035. [2022-06-17 08:44:58.240239] pathtree_find: Exit
  4036. [2022-06-17 08:44:58.241858] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
  4037. [2022-06-17 08:44:58.243581] regdb_close: decrementing refcount (5->4)
  4038. [2022-06-17 08:44:58.245233] regkey_open_onelevel: name = [Security]
  4039. [2022-06-17 08:44:58.246880] regdb_open: incrementing refcount (4->5)
  4040. [2022-06-17 08:44:58.248506] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
  4041. [2022-06-17 08:44:58.250171] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
  4042. [2022-06-17 08:44:58.251813] pathtree_find: Exit
  4043. [2022-06-17 08:44:58.253479] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
  4044. [2022-06-17 08:44:58.255169] regdb_close: decrementing refcount (5->4)
  4045. [2022-06-17 08:44:58.256812] winreg_CreateKey: struct winreg_CreateKey
  4046. [2022-06-17 08:44:58.258457] out: struct winreg_CreateKey
  4047. [2022-06-17 08:44:58.260095] new_handle : *
  4048. [2022-06-17 08:44:58.261731] new_handle: struct policy_handle
  4049. [2022-06-17 08:44:58.263437] handle_type : 0x00000001 (1)
  4050. [2022-06-17 08:44:58.265754] uuid : ffd8734b-5dee-4869-b02a-395d21f08529
  4051. [2022-06-17 08:44:58.268233] action_taken : *
  4052. [2022-06-17 08:44:58.269936] action_taken : REG_OPENED_EXISTING_KEY (2)
  4053. [2022-06-17 08:44:58.272718] result : WERR_OK
  4054. [2022-06-17 08:44:58.274608] winreg_SetValue: struct winreg_SetValue
  4055. [2022-06-17 08:44:58.276314] in: struct winreg_SetValue
  4056. [2022-06-17 08:44:58.277972] handle : *
  4057. [2022-06-17 08:44:58.279609] handle: struct policy_handle
  4058. [2022-06-17 08:44:58.281254] handle_type : 0x00000001 (1)
  4059. [2022-06-17 08:44:58.282946] uuid : ffd8734b-5dee-4869-b02a-395d21f08529
  4060. [2022-06-17 08:44:58.284626] name: struct winreg_String
  4061. [2022-06-17 08:44:58.286265] name_len : 0x0012 (18)
  4062. [2022-06-17 08:44:58.287929] name_size : 0x0012 (18)
  4063. [2022-06-17 08:44:58.289580] name : *
  4064. [2022-06-17 08:44:58.291203] name : 'Security'
  4065. [2022-06-17 08:44:58.292840] type : REG_BINARY (3)
  4066. [2022-06-17 08:44:58.294551] data : *
  4067. [2022-06-17 08:44:58.296194] data: ARRAY(120)
  4068. [2022-06-17 08:44:58.297835] [0] : 0x01 (1)
  4069. [2022-06-17 08:44:58.299489] [1] : 0x00 (0)
  4070. [2022-06-17 08:44:58.301134] [2] : 0x04 (4)
  4071. [2022-06-17 08:44:58.302767] [3] : 0x80 (128)
  4072. [2022-06-17 08:44:58.304456] [4] : 0x00 (0)
  4073. [2022-06-17 08:44:58.306096] [5] : 0x00 (0)
  4074. [2022-06-17 08:44:58.307744] [6] : 0x00 (0)
  4075. [2022-06-17 08:44:58.309395] [7] : 0x00 (0)
  4076. [2022-06-17 08:44:58.311041] [8] : 0x00 (0)
  4077. [2022-06-17 08:44:58.312687] [9] : 0x00 (0)
  4078. [2022-06-17 08:44:58.314372] [10] : 0x00 (0)
  4079. [2022-06-17 08:44:58.316021] [11] : 0x00 (0)
  4080. [2022-06-17 08:44:58.317660] [12] : 0x00 (0)
  4081. [2022-06-17 08:44:58.319292] [13] : 0x00 (0)
  4082. [2022-06-17 08:44:58.320936] [14] : 0x00 (0)
  4083. [2022-06-17 08:44:58.322587] [15] : 0x00 (0)
  4084. [2022-06-17 08:44:58.324315] [16] : 0x14 (20)
  4085. [2022-06-17 08:44:58.325971] [17] : 0x00 (0)
  4086. [2022-06-17 08:44:58.327612] [18] : 0x00 (0)
  4087. [2022-06-17 08:44:58.329124] [19] : 0x00 (0)
  4088. [2022-06-17 08:44:58.330619] [20] : 0x02 (2)
  4089. [2022-06-17 08:44:58.339863] [21] : 0x00 (0)
  4090. [2022-06-17 08:44:58.341802] [22] : 0x64 (100)
  4091. [2022-06-17 08:44:58.343602] [23] : 0x00 (0)
  4092. [2022-06-17 08:44:58.345178] [24] : 0x04 (4)
  4093. [2022-06-17 08:44:58.346938] [25] : 0x00 (0)
  4094. [2022-06-17 08:44:58.349624] [26] : 0x00 (0)
  4095. [2022-06-17 08:44:58.356967] [27] : 0x00 (0)
  4096. [2022-06-17 08:44:58.360624] [28] : 0x00 (0)
  4097. [2022-06-17 08:44:58.364217] [29] : 0x00 (0)
  4098. [2022-06-17 08:44:58.369527] [30] : 0x14 (20)
  4099. [2022-06-17 08:44:58.373661] [31] : 0x00 (0)
  4100. [2022-06-17 08:44:58.376792] [32] : 0x8d (141)
  4101. [2022-06-17 08:44:58.380702] [33] : 0x01 (1)
  4102. [2022-06-17 08:44:58.384953] [34] : 0x02 (2)
  4103. [2022-06-17 08:44:58.389902] [35] : 0x00 (0)
  4104. [2022-06-17 08:44:58.395208] [36] : 0x01 (1)
  4105. [2022-06-17 08:44:58.399580] [37] : 0x01 (1)
  4106. [2022-06-17 08:44:58.404155] [38] : 0x00 (0)
  4107. [2022-06-17 08:44:58.408643] [39] : 0x00 (0)
  4108. [2022-06-17 08:44:58.410551] [40] : 0x00 (0)
  4109. [2022-06-17 08:44:58.412264] [41] : 0x00 (0)
  4110. [2022-06-17 08:44:58.414007] [42] : 0x00 (0)
  4111. [2022-06-17 08:44:58.415682] [43] : 0x01 (1)
  4112. [2022-06-17 08:44:58.417350] [44] : 0x00 (0)
  4113. [2022-06-17 08:44:58.418997] [45] : 0x00 (0)
  4114. [2022-06-17 08:44:58.420646] [46] : 0x00 (0)
  4115. [2022-06-17 08:44:58.422282] [47] : 0x00 (0)
  4116. [2022-06-17 08:44:58.424000] [48] : 0x00 (0)
  4117. [2022-06-17 08:44:58.425676] [49] : 0x00 (0)
  4118. [2022-06-17 08:44:58.427214] [50] : 0x18 (24)
  4119. [2022-06-17 08:44:58.428992] [51] : 0x00 (0)
  4120. [2022-06-17 08:44:58.430640] [52] : 0xfd (253)
  4121. [2022-06-17 08:44:58.432281] [53] : 0x01 (1)
  4122. [2022-06-17 08:44:58.433996] [54] : 0x02 (2)
  4123. [2022-06-17 08:44:58.435649] [55] : 0x00 (0)
  4124. [2022-06-17 08:44:58.437293] [56] : 0x01 (1)
  4125. [2022-06-17 08:44:58.438940] [57] : 0x02 (2)
  4126. [2022-06-17 08:44:58.440594] [58] : 0x00 (0)
  4127. [2022-06-17 08:44:58.442246] [59] : 0x00 (0)
  4128. [2022-06-17 08:44:58.443908] [60] : 0x00 (0)
  4129. [2022-06-17 08:44:58.445573] [61] : 0x00 (0)
  4130. [2022-06-17 08:44:58.447216] [62] : 0x00 (0)
  4131. [2022-06-17 08:44:58.448846] [63] : 0x05 (5)
  4132. [2022-06-17 08:44:58.450486] [64] : 0x20 (32)
  4133. [2022-06-17 08:44:58.452129] [65] : 0x00 (0)
  4134. [2022-06-17 08:44:58.453844] [66] : 0x00 (0)
  4135. [2022-06-17 08:44:58.455502] [67] : 0x00 (0)
  4136. [2022-06-17 08:44:58.457143] [68] : 0x23 (35)
  4137. [2022-06-17 08:44:58.458782] [69] : 0x02 (2)
  4138. [2022-06-17 08:44:58.460425] [70] : 0x00 (0)
  4139. [2022-06-17 08:44:58.462081] [71] : 0x00 (0)
  4140. [2022-06-17 08:44:58.463768] [72] : 0x00 (0)
  4141. [2022-06-17 08:44:58.465434] [73] : 0x00 (0)
  4142. [2022-06-17 08:44:58.467090] [74] : 0x18 (24)
  4143. [2022-06-17 08:44:58.468730] [75] : 0x00 (0)
  4144. [2022-06-17 08:44:58.470375] [76] : 0xff (255)
  4145. [2022-06-17 08:44:58.472018] [77] : 0x01 (1)
  4146. [2022-06-17 08:44:58.473701] [78] : 0x0f (15)
  4147. [2022-06-17 08:44:58.475354] [79] : 0x00 (0)
  4148. [2022-06-17 08:44:58.476875] [80] : 0x01 (1)
  4149. [2022-06-17 08:44:58.478549] [81] : 0x02 (2)
  4150. [2022-06-17 08:44:58.480206] [82] : 0x00 (0)
  4151. [2022-06-17 08:44:58.481853] [83] : 0x00 (0)
  4152. [2022-06-17 08:44:58.483554] [84] : 0x00 (0)
  4153. [2022-06-17 08:44:58.485213] [85] : 0x00 (0)
  4154. [2022-06-17 08:44:58.486858] [86] : 0x00 (0)
  4155. [2022-06-17 08:44:58.488494] [87] : 0x05 (5)
  4156. [2022-06-17 08:44:58.490153] [88] : 0x20 (32)
  4157. [2022-06-17 08:44:58.491796] [89] : 0x00 (0)
  4158. [2022-06-17 08:44:58.493478] [90] : 0x00 (0)
  4159. [2022-06-17 08:44:58.495019] [91] : 0x00 (0)
  4160. [2022-06-17 08:44:58.496785] [92] : 0x25 (37)
  4161. [2022-06-17 08:44:58.498424] [93] : 0x02 (2)
  4162. [2022-06-17 08:44:58.500069] [94] : 0x00 (0)
  4163. [2022-06-17 08:44:58.501719] [95] : 0x00 (0)
  4164. [2022-06-17 08:44:58.503394] [96] : 0x00 (0)
  4165. [2022-06-17 08:44:58.505040] [97] : 0x00 (0)
  4166. [2022-06-17 08:44:58.506672] [98] : 0x18 (24)
  4167. [2022-06-17 08:44:58.508301] [99] : 0x00 (0)
  4168. [2022-06-17 08:44:58.509954] [100] : 0xff (255)
  4169. [2022-06-17 08:44:58.511467] [101] : 0x01 (1)
  4170. [2022-06-17 08:44:58.513229] [102] : 0x0f (15)
  4171. [2022-06-17 08:44:58.514894] [103] : 0x00 (0)
  4172. [2022-06-17 08:44:58.516549] [104] : 0x01 (1)
  4173. [2022-06-17 08:44:58.518183] [105] : 0x02 (2)
  4174. [2022-06-17 08:44:58.519813] [106] : 0x00 (0)
  4175. [2022-06-17 08:44:58.521439] [107] : 0x00 (0)
  4176. [2022-06-17 08:44:58.523127] [108] : 0x00 (0)
  4177. [2022-06-17 08:44:58.524796] [109] : 0x00 (0)
  4178. [2022-06-17 08:44:58.526448] [110] : 0x00 (0)
  4179. [2022-06-17 08:44:58.527972] [111] : 0x05 (5)
  4180. [2022-06-17 08:44:58.529709] [112] : 0x20 (32)
  4181. [2022-06-17 08:44:58.531359] [113] : 0x00 (0)
  4182. [2022-06-17 08:44:58.533034] [114] : 0x00 (0)
  4183. [2022-06-17 08:44:58.534690] [115] : 0x00 (0)
  4184. [2022-06-17 08:44:58.536326] [116] : 0x20 (32)
  4185. [2022-06-17 08:44:58.537973] [117] : 0x02 (2)
  4186. [2022-06-17 08:44:58.539619] [118] : 0x00 (0)
  4187. [2022-06-17 08:44:58.541263] [119] : 0x00 (0)
  4188. [2022-06-17 08:44:58.542930] size : 0x00000078 (120)
  4189. [2022-06-17 08:44:58.544464] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security:Security]
  4190. [2022-06-17 08:44:58.546135] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4191. [2022-06-17 08:44:58.547780] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security' (ops 0xb6ab32e8)
  4192. [2022-06-17 08:44:58.549468] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
  4193. [2022-06-17 08:44:58.551144] regdb_unpack_values: value[0]: name[Security] len[120]
  4194. [2022-06-17 08:44:58.552794] winreg_SetValue: struct winreg_SetValue
  4195. [2022-06-17 08:44:58.554496] out: struct winreg_SetValue
  4196. [2022-06-17 08:44:58.556279] result : WERR_OK
  4197. [2022-06-17 08:44:58.557916] winreg_CloseKey: struct winreg_CloseKey
  4198. [2022-06-17 08:44:58.559553] in: struct winreg_CloseKey
  4199. [2022-06-17 08:44:58.561195] handle : *
  4200. [2022-06-17 08:44:58.562834] handle: struct policy_handle
  4201. [2022-06-17 08:44:58.564530] handle_type : 0x00000001 (1)
  4202. [2022-06-17 08:44:58.566176] uuid : ffd8734b-5dee-4869-b02a-395d21f08529
  4203. [2022-06-17 08:44:58.567844] regdb_close: decrementing refcount (4->3)
  4204. [2022-06-17 08:44:58.569363] winreg_CloseKey: struct winreg_CloseKey
  4205. [2022-06-17 08:44:58.570859] out: struct winreg_CloseKey
  4206. [2022-06-17 08:44:58.572341] handle : *
  4207. [2022-06-17 08:44:58.573931] handle: struct policy_handle
  4208. [2022-06-17 08:44:58.575448] handle_type : 0x00000000 (0)
  4209. [2022-06-17 08:44:58.576949] uuid : 00000000-0000-0000-0000-000000000000
  4210. [2022-06-17 08:44:58.578454] result : WERR_OK
  4211. [2022-06-17 08:44:58.579953] winreg_CreateKey: struct winreg_CreateKey
  4212. [2022-06-17 08:44:58.581444] in: struct winreg_CreateKey
  4213. [2022-06-17 08:44:58.582979] handle : *
  4214. [2022-06-17 08:44:58.584692] handle: struct policy_handle
  4215. [2022-06-17 08:44:58.586229] handle_type : 0x00000001 (1)
  4216. [2022-06-17 08:44:58.587754] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  4217. [2022-06-17 08:44:58.590442] name: struct winreg_String
  4218. [2022-06-17 08:44:58.591966] name_len : 0x004e (78)
  4219. [2022-06-17 08:44:58.593536] name_size : 0x004e (78)
  4220. [2022-06-17 08:44:58.595058] name : *
  4221. [2022-06-17 08:44:58.596556] name : 'SYSTEM\CurrentControlSet\Services\WINS'
  4222. [2022-06-17 08:44:58.598076] keyclass: struct winreg_String
  4223. [2022-06-17 08:44:58.599793] name_len : 0x0002 (2)
  4224. [2022-06-17 08:44:58.601323] name_size : 0x0002 (2)
  4225. [2022-06-17 08:44:58.602836] name : *
  4226. [2022-06-17 08:44:58.604401] name : ''
  4227. [2022-06-17 08:44:58.605903] options : 0x00000000 (0)
  4228. [2022-06-17 08:44:58.607410] 0: REG_OPTION_VOLATILE
  4229. [2022-06-17 08:44:58.608919] 0: REG_OPTION_CREATE_LINK
  4230. [2022-06-17 08:44:58.610410] 0: REG_OPTION_BACKUP_RESTORE
  4231. [2022-06-17 08:44:58.611915] 0: REG_OPTION_OPEN_LINK
  4232. [2022-06-17 08:44:58.613461] access_mask : 0x02000000 (33554432)
  4233. [2022-06-17 08:44:58.615178] 0: KEY_QUERY_VALUE
  4234. [2022-06-17 08:44:58.616695] 0: KEY_SET_VALUE
  4235. [2022-06-17 08:44:58.618195] 0: KEY_CREATE_SUB_KEY
  4236. [2022-06-17 08:44:58.619784] 0: KEY_ENUMERATE_SUB_KEYS
  4237. [2022-06-17 08:44:58.621324] 0: KEY_NOTIFY
  4238. [2022-06-17 08:44:58.622836] 0: KEY_CREATE_LINK
  4239. [2022-06-17 08:44:58.624431] 0: KEY_WOW64_64KEY
  4240. [2022-06-17 08:44:58.625935] 0: KEY_WOW64_32KEY
  4241. [2022-06-17 08:44:58.627442] secdesc : NULL
  4242. [2022-06-17 08:44:58.629093] action_taken : *
  4243. [2022-06-17 08:44:58.630632] action_taken : REG_ACTION_NONE (0)
  4244. [2022-06-17 08:44:58.632156] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\WINS'
  4245. [2022-06-17 08:44:58.633733] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4246. [2022-06-17 08:44:58.635259] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4247. [2022-06-17 08:44:58.636772] regkey_open_onelevel: name = [SYSTEM]
  4248. [2022-06-17 08:44:58.638265] regdb_open: incrementing refcount (3->4)
  4249. [2022-06-17 08:44:58.643863] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  4250. [2022-06-17 08:44:58.646770] pathtree_find: Enter [\HKLM\SYSTEM]
  4251. [2022-06-17 08:44:58.648538] pathtree_find: Exit
  4252. [2022-06-17 08:44:58.650080] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  4253. [2022-06-17 08:44:58.651608] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4254. [2022-06-17 08:44:58.653162] regkey_open_onelevel: name = [CurrentControlSet]
  4255. [2022-06-17 08:44:58.654982] regdb_open: incrementing refcount (4->5)
  4256. [2022-06-17 08:44:58.656641] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  4257. [2022-06-17 08:44:58.658303] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  4258. [2022-06-17 08:44:58.659955] pathtree_find: Exit
  4259. [2022-06-17 08:44:58.661458] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  4260. [2022-06-17 08:44:58.663285] regdb_close: decrementing refcount (5->4)
  4261. [2022-06-17 08:44:58.664945] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4262. [2022-06-17 08:44:58.666598] regkey_open_onelevel: name = [Services]
  4263. [2022-06-17 08:44:58.668236] regdb_open: incrementing refcount (4->5)
  4264. [2022-06-17 08:44:58.669862] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  4265. [2022-06-17 08:44:58.671535] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  4266. [2022-06-17 08:44:58.673243] pathtree_find: Exit
  4267. [2022-06-17 08:44:58.674903] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  4268. [2022-06-17 08:44:58.676557] regdb_close: decrementing refcount (5->4)
  4269. [2022-06-17 08:44:58.678188] regkey_open_onelevel: name = [WINS]
  4270. [2022-06-17 08:44:58.679818] regdb_open: incrementing refcount (4->5)
  4271. [2022-06-17 08:44:58.681537] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4272. [2022-06-17 08:44:58.683314] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4273. [2022-06-17 08:44:58.685024] pathtree_find: Exit
  4274. [2022-06-17 08:44:58.686677] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4275. [2022-06-17 08:44:58.688351] regdb_close: decrementing refcount (5->4)
  4276. [2022-06-17 08:44:58.689987] winreg_CreateKey: struct winreg_CreateKey
  4277. [2022-06-17 08:44:58.691635] out: struct winreg_CreateKey
  4278. [2022-06-17 08:44:58.693319] new_handle : *
  4279. [2022-06-17 08:44:58.694855] new_handle: struct policy_handle
  4280. [2022-06-17 08:44:58.696366] handle_type : 0x00000001 (1)
  4281. [2022-06-17 08:44:58.697873] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4282. [2022-06-17 08:44:58.699393] action_taken : *
  4283. [2022-06-17 08:44:58.701020] action_taken : REG_OPENED_EXISTING_KEY (2)
  4284. [2022-06-17 08:44:58.702792] result : WERR_OK
  4285. [2022-06-17 08:44:58.704511] winreg_SetValue: struct winreg_SetValue
  4286. [2022-06-17 08:44:58.706037] in: struct winreg_SetValue
  4287. [2022-06-17 08:44:58.707770] handle : *
  4288. [2022-06-17 08:44:58.709411] handle: struct policy_handle
  4289. [2022-06-17 08:44:58.711056] handle_type : 0x00000001 (1)
  4290. [2022-06-17 08:44:58.712695] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4291. [2022-06-17 08:44:58.714412] name: struct winreg_String
  4292. [2022-06-17 08:44:58.716044] name_len : 0x000c (12)
  4293. [2022-06-17 08:44:58.717702] name_size : 0x000c (12)
  4294. [2022-06-17 08:44:58.719356] name : *
  4295. [2022-06-17 08:44:58.721018] name : 'Start'
  4296. [2022-06-17 08:44:58.722666] type : REG_DWORD (4)
  4297. [2022-06-17 08:44:58.724442] data : *
  4298. [2022-06-17 08:44:58.726098] data: ARRAY(4)
  4299. [2022-06-17 08:44:58.727738] [0] : 0x02 (2)
  4300. [2022-06-17 08:44:58.729385] [1] : 0x00 (0)
  4301. [2022-06-17 08:44:58.731020] [2] : 0x00 (0)
  4302. [2022-06-17 08:44:58.732672] [3] : 0x00 (0)
  4303. [2022-06-17 08:44:58.734379] size : 0x00000004 (4)
  4304. [2022-06-17 08:44:58.736017] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:Start]
  4305. [2022-06-17 08:44:58.737670] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4306. [2022-06-17 08:44:58.739314] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\WINS' (ops 0xb6ab32e8)
  4307. [2022-06-17 08:44:58.740972] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4308. [2022-06-17 08:44:58.742833] regdb_unpack_values: value[0]: name[Start] len[4]
  4309. [2022-06-17 08:44:58.744591] regdb_unpack_values: value[1]: name[Type] len[4]
  4310. [2022-06-17 08:44:58.746587] regdb_unpack_values: value[2]: name[ErrorControl] len[4]
  4311. [2022-06-17 08:44:58.748272] regdb_unpack_values: value[3]: name[ObjectName] len[24]
  4312. [2022-06-17 08:44:58.749937] regdb_unpack_values: value[4]: name[DisplayName] len[74]
  4313. [2022-06-17 08:44:58.751579] regdb_unpack_values: value[5]: name[ImagePath] len[54]
  4314. [2022-06-17 08:44:58.753260] regdb_unpack_values: value[6]: name[Description] len[178]
  4315. [2022-06-17 08:44:58.754921] winreg_SetValue: struct winreg_SetValue
  4316. [2022-06-17 08:44:58.756564] out: struct winreg_SetValue
  4317. [2022-06-17 08:44:58.758201] result : WERR_OK
  4318. [2022-06-17 08:44:58.759851] winreg_SetValue: struct winreg_SetValue
  4319. [2022-06-17 08:44:58.761499] in: struct winreg_SetValue
  4320. [2022-06-17 08:44:58.763179] handle : *
  4321. [2022-06-17 08:44:58.764828] handle: struct policy_handle
  4322. [2022-06-17 08:44:58.766465] handle_type : 0x00000001 (1)
  4323. [2022-06-17 08:44:58.768118] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4324. [2022-06-17 08:44:58.769784] name: struct winreg_String
  4325. [2022-06-17 08:44:58.771416] name_len : 0x000a (10)
  4326. [2022-06-17 08:44:58.773095] name_size : 0x000a (10)
  4327. [2022-06-17 08:44:58.774765] name : *
  4328. [2022-06-17 08:44:58.776408] name : 'Type'
  4329. [2022-06-17 08:44:58.778034] type : REG_DWORD (4)
  4330. [2022-06-17 08:44:58.779671] data : *
  4331. [2022-06-17 08:44:58.781303] data: ARRAY(4)
  4332. [2022-06-17 08:44:58.783002] [0] : 0x10 (16)
  4333. [2022-06-17 08:44:58.784680] [1] : 0x00 (0)
  4334. [2022-06-17 08:44:58.786332] [2] : 0x00 (0)
  4335. [2022-06-17 08:44:58.787986] [3] : 0x00 (0)
  4336. [2022-06-17 08:44:58.789615] size : 0x00000004 (4)
  4337. [2022-06-17 08:44:58.792235] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:Type]
  4338. [2022-06-17 08:44:58.793990] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4339. [2022-06-17 08:44:58.795674] winreg_SetValue: struct winreg_SetValue
  4340. [2022-06-17 08:44:58.797322] out: struct winreg_SetValue
  4341. [2022-06-17 08:44:58.798950] result : WERR_OK
  4342. [2022-06-17 08:44:58.800588] winreg_SetValue: struct winreg_SetValue
  4343. [2022-06-17 08:44:58.802221] in: struct winreg_SetValue
  4344. [2022-06-17 08:44:58.803901] handle : *
  4345. [2022-06-17 08:44:58.805547] handle: struct policy_handle
  4346. [2022-06-17 08:44:58.807192] handle_type : 0x00000001 (1)
  4347. [2022-06-17 08:44:58.808840] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4348. [2022-06-17 08:44:58.810500] name: struct winreg_String
  4349. [2022-06-17 08:44:58.812127] name_len : 0x001a (26)
  4350. [2022-06-17 08:44:58.813817] name_size : 0x001a (26)
  4351. [2022-06-17 08:44:58.815479] name : *
  4352. [2022-06-17 08:44:58.817129] name : 'ErrorControl'
  4353. [2022-06-17 08:44:58.818762] type : REG_DWORD (4)
  4354. [2022-06-17 08:44:58.820416] data : *
  4355. [2022-06-17 08:44:58.822752] data: ARRAY(4)
  4356. [2022-06-17 08:44:58.824460] [0] : 0x01 (1)
  4357. [2022-06-17 08:44:58.826113] [1] : 0x00 (0)
  4358. [2022-06-17 08:44:58.827757] [2] : 0x00 (0)
  4359. [2022-06-17 08:44:58.829414] [3] : 0x00 (0)
  4360. [2022-06-17 08:44:58.831064] size : 0x00000004 (4)
  4361. [2022-06-17 08:44:58.832708] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:ErrorControl]
  4362. [2022-06-17 08:44:58.834436] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4363. [2022-06-17 08:44:58.836110] winreg_SetValue: struct winreg_SetValue
  4364. [2022-06-17 08:44:58.837750] out: struct winreg_SetValue
  4365. [2022-06-17 08:44:58.840566] result : WERR_OK
  4366. [2022-06-17 08:44:58.842227] winreg_SetValue: struct winreg_SetValue
  4367. [2022-06-17 08:44:58.843930] in: struct winreg_SetValue
  4368. [2022-06-17 08:44:58.845603] handle : *
  4369. [2022-06-17 08:44:58.847241] handle: struct policy_handle
  4370. [2022-06-17 08:44:58.848878] handle_type : 0x00000001 (1)
  4371. [2022-06-17 08:44:58.850528] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4372. [2022-06-17 08:44:58.852171] name: struct winreg_String
  4373. [2022-06-17 08:44:58.853860] name_len : 0x0016 (22)
  4374. [2022-06-17 08:44:58.855522] name_size : 0x0016 (22)
  4375. [2022-06-17 08:44:58.857170] name : *
  4376. [2022-06-17 08:44:58.858823] name : 'ObjectName'
  4377. [2022-06-17 08:44:58.860361] type : REG_SZ (1)
  4378. [2022-06-17 08:44:58.862131] data : *
  4379. [2022-06-17 08:44:58.863858] data: ARRAY(24)
  4380. [2022-06-17 08:44:58.865508] [0] : 0x4c (76)
  4381. [2022-06-17 08:44:58.867150] [1] : 0x00 (0)
  4382. [2022-06-17 08:44:58.868782] [2] : 0x6f (111)
  4383. [2022-06-17 08:44:58.870432] [3] : 0x00 (0)
  4384. [2022-06-17 08:44:58.872085] [4] : 0x63 (99)
  4385. [2022-06-17 08:44:58.873788] [5] : 0x00 (0)
  4386. [2022-06-17 08:44:58.875434] [6] : 0x61 (97)
  4387. [2022-06-17 08:44:58.877068] [7] : 0x00 (0)
  4388. [2022-06-17 08:44:58.878698] [8] : 0x6c (108)
  4389. [2022-06-17 08:44:58.880418] [9] : 0x00 (0)
  4390. [2022-06-17 08:44:58.882096] [10] : 0x53 (83)
  4391. [2022-06-17 08:44:58.883819] [11] : 0x00 (0)
  4392. [2022-06-17 08:44:58.885483] [12] : 0x79 (121)
  4393. [2022-06-17 08:44:58.887136] [13] : 0x00 (0)
  4394. [2022-06-17 08:44:58.888785] [14] : 0x73 (115)
  4395. [2022-06-17 08:44:58.894742] [15] : 0x00 (0)
  4396. [2022-06-17 08:44:58.896498] [16] : 0x74 (116)
  4397. [2022-06-17 08:44:58.898192] [17] : 0x00 (0)
  4398. [2022-06-17 08:44:58.899858] [18] : 0x65 (101)
  4399. [2022-06-17 08:44:58.901510] [19] : 0x00 (0)
  4400. [2022-06-17 08:44:58.903212] [20] : 0x6d (109)
  4401. [2022-06-17 08:44:58.904891] [21] : 0x00 (0)
  4402. [2022-06-17 08:44:58.906550] [22] : 0x00 (0)
  4403. [2022-06-17 08:44:58.908187] [23] : 0x00 (0)
  4404. [2022-06-17 08:44:58.909825] size : 0x00000018 (24)
  4405. [2022-06-17 08:44:58.911467] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:ObjectName]
  4406. [2022-06-17 08:44:58.913197] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4407. [2022-06-17 08:44:58.914873] winreg_SetValue: struct winreg_SetValue
  4408. [2022-06-17 08:44:58.916508] out: struct winreg_SetValue
  4409. [2022-06-17 08:44:58.918139] result : WERR_OK
  4410. [2022-06-17 08:44:58.919794] winreg_SetValue: struct winreg_SetValue
  4411. [2022-06-17 08:44:58.921431] in: struct winreg_SetValue
  4412. [2022-06-17 08:44:58.923121] handle : *
  4413. [2022-06-17 08:44:58.924782] handle: struct policy_handle
  4414. [2022-06-17 08:44:58.926429] handle_type : 0x00000001 (1)
  4415. [2022-06-17 08:44:58.928074] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4416. [2022-06-17 08:44:58.929732] name: struct winreg_String
  4417. [2022-06-17 08:44:58.931365] name_len : 0x0018 (24)
  4418. [2022-06-17 08:44:58.933056] name_size : 0x0018 (24)
  4419. [2022-06-17 08:44:58.934723] name : *
  4420. [2022-06-17 08:44:58.936372] name : 'DisplayName'
  4421. [2022-06-17 08:44:58.938032] type : REG_SZ (1)
  4422. [2022-06-17 08:44:58.939563] data : *
  4423. [2022-06-17 08:44:58.941053] data: ARRAY(74)
  4424. [2022-06-17 08:44:58.942541] [0] : 0x57 (87)
  4425. [2022-06-17 08:44:58.944407] [1] : 0x00 (0)
  4426. [2022-06-17 08:44:58.946070] [2] : 0x69 (105)
  4427. [2022-06-17 08:44:58.947732] [3] : 0x00 (0)
  4428. [2022-06-17 08:44:58.949378] [4] : 0x6e (110)
  4429. [2022-06-17 08:44:58.951031] [5] : 0x00 (0)
  4430. [2022-06-17 08:44:58.952671] [6] : 0x64 (100)
  4431. [2022-06-17 08:44:58.954377] [7] : 0x00 (0)
  4432. [2022-06-17 08:44:58.956038] [8] : 0x6f (111)
  4433. [2022-06-17 08:44:58.957684] [9] : 0x00 (0)
  4434. [2022-06-17 08:44:58.959338] [10] : 0x77 (119)
  4435. [2022-06-17 08:44:58.960988] [11] : 0x00 (0)
  4436. [2022-06-17 08:44:58.962634] [12] : 0x73 (115)
  4437. [2022-06-17 08:44:58.964358] [13] : 0x00 (0)
  4438. [2022-06-17 08:44:58.966008] [14] : 0x20 (32)
  4439. [2022-06-17 08:44:58.967648] [15] : 0x00 (0)
  4440. [2022-06-17 08:44:58.969282] [16] : 0x49 (73)
  4441. [2022-06-17 08:44:58.970811] [17] : 0x00 (0)
  4442. [2022-06-17 08:44:58.972321] [18] : 0x6e (110)
  4443. [2022-06-17 08:44:58.973908] [19] : 0x00 (0)
  4444. [2022-06-17 08:44:58.975693] [20] : 0x74 (116)
  4445. [2022-06-17 08:44:58.977220] [21] : 0x00 (0)
  4446. [2022-06-17 08:44:58.978716] [22] : 0x65 (101)
  4447. [2022-06-17 08:44:58.980208] [23] : 0x00 (0)
  4448. [2022-06-17 08:44:58.981709] [24] : 0x72 (114)
  4449. [2022-06-17 08:44:58.983272] [25] : 0x00 (0)
  4450. [2022-06-17 08:44:58.985035] [26] : 0x6e (110)
  4451. [2022-06-17 08:44:58.986670] [27] : 0x00 (0)
  4452. [2022-06-17 08:44:58.988330] [28] : 0x65 (101)
  4453. [2022-06-17 08:44:58.989977] [29] : 0x00 (0)
  4454. [2022-06-17 08:44:58.991626] [30] : 0x74 (116)
  4455. [2022-06-17 08:44:58.993759] [31] : 0x00 (0)
  4456. [2022-06-17 08:44:58.995461] [32] : 0x20 (32)
  4457. [2022-06-17 08:44:58.997126] [33] : 0x00 (0)
  4458. [2022-06-17 08:44:58.998781] [34] : 0x4e (78)
  4459. [2022-06-17 08:44:59.000423] [35] : 0x00 (0)
  4460. [2022-06-17 08:44:59.002075] [36] : 0x61 (97)
  4461. [2022-06-17 08:44:59.003780] [37] : 0x00 (0)
  4462. [2022-06-17 08:44:59.005429] [38] : 0x6d (109)
  4463. [2022-06-17 08:44:59.007087] [39] : 0x00 (0)
  4464. [2022-06-17 08:44:59.008740] [40] : 0x65 (101)
  4465. [2022-06-17 08:44:59.010384] [41] : 0x00 (0)
  4466. [2022-06-17 08:44:59.012029] [42] : 0x20 (32)
  4467. [2022-06-17 08:44:59.013729] [43] : 0x00 (0)
  4468. [2022-06-17 08:44:59.015371] [44] : 0x53 (83)
  4469. [2022-06-17 08:44:59.017040] [45] : 0x00 (0)
  4470. [2022-06-17 08:44:59.018698] [46] : 0x65 (101)
  4471. [2022-06-17 08:44:59.020354] [47] : 0x00 (0)
  4472. [2022-06-17 08:44:59.022007] [48] : 0x72 (114)
  4473. [2022-06-17 08:44:59.023805] [49] : 0x00 (0)
  4474. [2022-06-17 08:44:59.025465] [50] : 0x76 (118)
  4475. [2022-06-17 08:44:59.027122] [51] : 0x00 (0)
  4476. [2022-06-17 08:44:59.028771] [52] : 0x69 (105)
  4477. [2022-06-17 08:44:59.030419] [53] : 0x00 (0)
  4478. [2022-06-17 08:44:59.032074] [54] : 0x63 (99)
  4479. [2022-06-17 08:44:59.033786] [55] : 0x00 (0)
  4480. [2022-06-17 08:44:59.035453] [56] : 0x65 (101)
  4481. [2022-06-17 08:44:59.037103] [57] : 0x00 (0)
  4482. [2022-06-17 08:44:59.038735] [58] : 0x20 (32)
  4483. [2022-06-17 08:44:59.040964] [59] : 0x00 (0)
  4484. [2022-06-17 08:44:59.042989] [60] : 0x28 (40)
  4485. [2022-06-17 08:44:59.044700] [61] : 0x00 (0)
  4486. [2022-06-17 08:44:59.046396] [62] : 0x57 (87)
  4487. [2022-06-17 08:44:59.048050] [63] : 0x00 (0)
  4488. [2022-06-17 08:44:59.054323] [64] : 0x49 (73)
  4489. [2022-06-17 08:44:59.063614] [65] : 0x00 (0)
  4490. [2022-06-17 08:44:59.065430] [66] : 0x4e (78)
  4491. [2022-06-17 08:44:59.067308] [67] : 0x00 (0)
  4492. [2022-06-17 08:44:59.068978] [68] : 0x53 (83)
  4493. [2022-06-17 08:44:59.070638] [69] : 0x00 (0)
  4494. [2022-06-17 08:44:59.072270] [70] : 0x29 (41)
  4495. [2022-06-17 08:44:59.074004] [71] : 0x00 (0)
  4496. [2022-06-17 08:44:59.075657] [72] : 0x00 (0)
  4497. [2022-06-17 08:44:59.079384] [73] : 0x00 (0)
  4498. [2022-06-17 08:44:59.081136] size : 0x0000004a (74)
  4499. [2022-06-17 08:44:59.082802] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:DisplayName]
  4500. [2022-06-17 08:44:59.084553] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4501. [2022-06-17 08:44:59.086227] winreg_SetValue: struct winreg_SetValue
  4502. [2022-06-17 08:44:59.087889] out: struct winreg_SetValue
  4503. [2022-06-17 08:44:59.090626] result : WERR_OK
  4504. [2022-06-17 08:44:59.092319] winreg_SetValue: struct winreg_SetValue
  4505. [2022-06-17 08:44:59.093949] in: struct winreg_SetValue
  4506. [2022-06-17 08:44:59.095589] handle : *
  4507. [2022-06-17 08:44:59.097247] handle: struct policy_handle
  4508. [2022-06-17 08:44:59.098913] handle_type : 0x00000001 (1)
  4509. [2022-06-17 08:44:59.100566] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4510. [2022-06-17 08:44:59.102222] name: struct winreg_String
  4511. [2022-06-17 08:44:59.103908] name_len : 0x0014 (20)
  4512. [2022-06-17 08:44:59.105558] name_size : 0x0014 (20)
  4513. [2022-06-17 08:44:59.107193] name : *
  4514. [2022-06-17 08:44:59.108840] name : 'ImagePath'
  4515. [2022-06-17 08:44:59.110369] type : REG_SZ (1)
  4516. [2022-06-17 08:44:59.112121] data : *
  4517. [2022-06-17 08:44:59.113820] data: ARRAY(54)
  4518. [2022-06-17 08:44:59.115485] [0] : 0x2f (47)
  4519. [2022-06-17 08:44:59.117123] [1] : 0x00 (0)
  4520. [2022-06-17 08:44:59.118766] [2] : 0x75 (117)
  4521. [2022-06-17 08:44:59.120403] [3] : 0x00 (0)
  4522. [2022-06-17 08:44:59.122051] [4] : 0x73 (115)
  4523. [2022-06-17 08:44:59.123756] [5] : 0x00 (0)
  4524. [2022-06-17 08:44:59.125420] [6] : 0x72 (114)
  4525. [2022-06-17 08:44:59.126940] [7] : 0x00 (0)
  4526. [2022-06-17 08:44:59.128436] [8] : 0x2f (47)
  4527. [2022-06-17 08:44:59.130203] [9] : 0x00 (0)
  4528. [2022-06-17 08:44:59.131844] [10] : 0x6c (108)
  4529. [2022-06-17 08:44:59.133532] [11] : 0x00 (0)
  4530. [2022-06-17 08:44:59.135193] [12] : 0x69 (105)
  4531. [2022-06-17 08:44:59.136855] [13] : 0x00 (0)
  4532. [2022-06-17 08:44:59.138507] [14] : 0x62 (98)
  4533. [2022-06-17 08:44:59.140153] [15] : 0x00 (0)
  4534. [2022-06-17 08:44:59.146101] [16] : 0x2f (47)
  4535. [2022-06-17 08:44:59.147858] [17] : 0x00 (0)
  4536. [2022-06-17 08:44:59.149544] [18] : 0x73 (115)
  4537. [2022-06-17 08:44:59.151292] [19] : 0x00 (0)
  4538. [2022-06-17 08:44:59.153009] [20] : 0x61 (97)
  4539. [2022-06-17 08:44:59.154690] [21] : 0x00 (0)
  4540. [2022-06-17 08:44:59.156210] [22] : 0x6d (109)
  4541. [2022-06-17 08:44:59.157703] [23] : 0x00 (0)
  4542. [2022-06-17 08:44:59.159197] [24] : 0x62 (98)
  4543. [2022-06-17 08:44:59.160694] [25] : 0x00 (0)
  4544. [2022-06-17 08:44:59.162191] [26] : 0x61 (97)
  4545. [2022-06-17 08:44:59.163992] [27] : 0x00 (0)
  4546. [2022-06-17 08:44:59.165670] [28] : 0x2f (47)
  4547. [2022-06-17 08:44:59.167318] [29] : 0x00 (0)
  4548. [2022-06-17 08:44:59.168960] [30] : 0x73 (115)
  4549. [2022-06-17 08:44:59.170600] [31] : 0x00 (0)
  4550. [2022-06-17 08:44:59.172239] [32] : 0x76 (118)
  4551. [2022-06-17 08:44:59.173964] [33] : 0x00 (0)
  4552. [2022-06-17 08:44:59.175504] [34] : 0x63 (99)
  4553. [2022-06-17 08:44:59.177143] [35] : 0x00 (0)
  4554. [2022-06-17 08:44:59.178807] [36] : 0x63 (99)
  4555. [2022-06-17 08:44:59.180446] [37] : 0x00 (0)
  4556. [2022-06-17 08:44:59.182096] [38] : 0x74 (116)
  4557. [2022-06-17 08:44:59.183804] [39] : 0x00 (0)
  4558. [2022-06-17 08:44:59.185457] [40] : 0x6c (108)
  4559. [2022-06-17 08:44:59.187109] [41] : 0x00 (0)
  4560. [2022-06-17 08:44:59.188642] [42] : 0x2f (47)
  4561. [2022-06-17 08:44:59.190146] [43] : 0x00 (0)
  4562. [2022-06-17 08:44:59.191631] [44] : 0x6e (110)
  4563. [2022-06-17 08:44:59.193208] [45] : 0x00 (0)
  4564. [2022-06-17 08:44:59.195017] [46] : 0x6d (109)
  4565. [2022-06-17 08:44:59.196671] [47] : 0x00 (0)
  4566. [2022-06-17 08:44:59.198340] [48] : 0x62 (98)
  4567. [2022-06-17 08:44:59.199989] [49] : 0x00 (0)
  4568. [2022-06-17 08:44:59.201626] [50] : 0x64 (100)
  4569. [2022-06-17 08:44:59.203308] [51] : 0x00 (0)
  4570. [2022-06-17 08:44:59.204964] [52] : 0x00 (0)
  4571. [2022-06-17 08:44:59.206598] [53] : 0x00 (0)
  4572. [2022-06-17 08:44:59.208248] size : 0x00000036 (54)
  4573. [2022-06-17 08:44:59.209779] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:ImagePath]
  4574. [2022-06-17 08:44:59.211448] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4575. [2022-06-17 08:44:59.213147] winreg_SetValue: struct winreg_SetValue
  4576. [2022-06-17 08:44:59.214906] out: struct winreg_SetValue
  4577. [2022-06-17 08:44:59.216550] result : WERR_OK
  4578. [2022-06-17 08:44:59.218194] winreg_SetValue: struct winreg_SetValue
  4579. [2022-06-17 08:44:59.219831] in: struct winreg_SetValue
  4580. [2022-06-17 08:44:59.221342] handle : *
  4581. [2022-06-17 08:44:59.222850] handle: struct policy_handle
  4582. [2022-06-17 08:44:59.224634] handle_type : 0x00000001 (1)
  4583. [2022-06-17 08:44:59.226298] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4584. [2022-06-17 08:44:59.227951] name: struct winreg_String
  4585. [2022-06-17 08:44:59.229580] name_len : 0x0018 (24)
  4586. [2022-06-17 08:44:59.231221] name_size : 0x0018 (24)
  4587. [2022-06-17 08:44:59.232902] name : *
  4588. [2022-06-17 08:44:59.234568] name : 'Description'
  4589. [2022-06-17 08:44:59.236227] type : REG_SZ (1)
  4590. [2022-06-17 08:44:59.237883] data : *
  4591. [2022-06-17 08:44:59.239513] data: ARRAY(178)
  4592. [2022-06-17 08:44:59.241149] [0] : 0x49 (73)
  4593. [2022-06-17 08:44:59.242784] [1] : 0x00 (0)
  4594. [2022-06-17 08:44:59.244887] [2] : 0x6e (110)
  4595. [2022-06-17 08:44:59.246795] [3] : 0x00 (0)
  4596. [2022-06-17 08:44:59.248466] [4] : 0x74 (116)
  4597. [2022-06-17 08:44:59.250124] [5] : 0x00 (0)
  4598. [2022-06-17 08:44:59.251778] [6] : 0x65 (101)
  4599. [2022-06-17 08:44:59.253482] [7] : 0x00 (0)
  4600. [2022-06-17 08:44:59.255129] [8] : 0x72 (114)
  4601. [2022-06-17 08:44:59.256771] [9] : 0x00 (0)
  4602. [2022-06-17 08:44:59.258300] [10] : 0x6e (110)
  4603. [2022-06-17 08:44:59.259821] [11] : 0x00 (0)
  4604. [2022-06-17 08:44:59.261594] [12] : 0x61 (97)
  4605. [2022-06-17 08:44:59.263291] [13] : 0x00 (0)
  4606. [2022-06-17 08:44:59.264946] [14] : 0x6c (108)
  4607. [2022-06-17 08:44:59.266594] [15] : 0x00 (0)
  4608. [2022-06-17 08:44:59.268234] [16] : 0x20 (32)
  4609. [2022-06-17 08:44:59.269880] [17] : 0x00 (0)
  4610. [2022-06-17 08:44:59.271536] [18] : 0x73 (115)
  4611. [2022-06-17 08:44:59.273229] [19] : 0x00 (0)
  4612. [2022-06-17 08:44:59.274769] [20] : 0x65 (101)
  4613. [2022-06-17 08:44:59.276559] [21] : 0x00 (0)
  4614. [2022-06-17 08:44:59.278208] [22] : 0x72 (114)
  4615. [2022-06-17 08:44:59.279854] [23] : 0x00 (0)
  4616. [2022-06-17 08:44:59.281489] [24] : 0x76 (118)
  4617. [2022-06-17 08:44:59.283181] [25] : 0x00 (0)
  4618. [2022-06-17 08:44:59.284852] [26] : 0x69 (105)
  4619. [2022-06-17 08:44:59.286505] [27] : 0x00 (0)
  4620. [2022-06-17 08:44:59.288152] [28] : 0x63 (99)
  4621. [2022-06-17 08:44:59.289788] [29] : 0x00 (0)
  4622. [2022-06-17 08:44:59.291423] [30] : 0x65 (101)
  4623. [2022-06-17 08:44:59.293962] [31] : 0x00 (0)
  4624. [2022-06-17 08:44:59.295788] [32] : 0x20 (32)
  4625. [2022-06-17 08:44:59.297449] [33] : 0x00 (0)
  4626. [2022-06-17 08:44:59.299103] [34] : 0x70 (112)
  4627. [2022-06-17 08:44:59.300755] [35] : 0x00 (0)
  4628. [2022-06-17 08:44:59.302388] [36] : 0x72 (114)
  4629. [2022-06-17 08:44:59.304103] [37] : 0x00 (0)
  4630. [2022-06-17 08:44:59.305758] [38] : 0x6f (111)
  4631. [2022-06-17 08:44:59.307405] [39] : 0x00 (0)
  4632. [2022-06-17 08:44:59.309047] [40] : 0x76 (118)
  4633. [2022-06-17 08:44:59.310694] [41] : 0x00 (0)
  4634. [2022-06-17 08:44:59.312341] [42] : 0x69 (105)
  4635. [2022-06-17 08:44:59.314085] [43] : 0x00 (0)
  4636. [2022-06-17 08:44:59.315725] [44] : 0x64 (100)
  4637. [2022-06-17 08:44:59.317370] [45] : 0x00 (0)
  4638. [2022-06-17 08:44:59.319012] [46] : 0x69 (105)
  4639. [2022-06-17 08:44:59.320658] [47] : 0x00 (0)
  4640. [2022-06-17 08:44:59.322313] [48] : 0x6e (110)
  4641. [2022-06-17 08:44:59.324038] [49] : 0x00 (0)
  4642. [2022-06-17 08:44:59.325683] [50] : 0x67 (103)
  4643. [2022-06-17 08:44:59.327203] [51] : 0x00 (0)
  4644. [2022-06-17 08:44:59.328914] [52] : 0x20 (32)
  4645. [2022-06-17 08:44:59.330556] [53] : 0x00 (0)
  4646. [2022-06-17 08:44:59.332216] [54] : 0x61 (97)
  4647. [2022-06-17 08:44:59.333913] [55] : 0x00 (0)
  4648. [2022-06-17 08:44:59.335562] [56] : 0x20 (32)
  4649. [2022-06-17 08:44:59.337213] [57] : 0x00 (0)
  4650. [2022-06-17 08:44:59.338849] [58] : 0x4e (78)
  4651. [2022-06-17 08:44:59.340480] [59] : 0x00 (0)
  4652. [2022-06-17 08:44:59.354873] [60] : 0x65 (101)
  4653. [2022-06-17 08:44:59.356627] [61] : 0x00 (0)
  4654. [2022-06-17 08:44:59.358314] [62] : 0x74 (116)
  4655. [2022-06-17 08:44:59.359989] [63] : 0x00 (0)
  4656. [2022-06-17 08:44:59.361653] [64] : 0x42 (66)
  4657. [2022-06-17 08:44:59.363365] [65] : 0x00 (0)
  4658. [2022-06-17 08:44:59.365027] [66] : 0x49 (73)
  4659. [2022-06-17 08:44:59.366684] [67] : 0x00 (0)
  4660. [2022-06-17 08:44:59.369780] [68] : 0x4f (79)
  4661. [2022-06-17 08:44:59.371528] [69] : 0x00 (0)
  4662. [2022-06-17 08:44:59.373269] [70] : 0x53 (83)
  4663. [2022-06-17 08:44:59.374962] [71] : 0x00 (0)
  4664. [2022-06-17 08:44:59.376624] [72] : 0x20 (32)
  4665. [2022-06-17 08:44:59.378282] [73] : 0x00 (0)
  4666. [2022-06-17 08:44:59.379915] [74] : 0x70 (112)
  4667. [2022-06-17 08:44:59.381570] [75] : 0x00 (0)
  4668. [2022-06-17 08:44:59.383262] [76] : 0x6f (111)
  4669. [2022-06-17 08:44:59.384914] [77] : 0x00 (0)
  4670. [2022-06-17 08:44:59.386559] [78] : 0x69 (105)
  4671. [2022-06-17 08:44:59.388212] [79] : 0x00 (0)
  4672. [2022-06-17 08:44:59.389967] [80] : 0x6e (110)
  4673. [2022-06-17 08:44:59.391630] [81] : 0x00 (0)
  4674. [2022-06-17 08:44:59.393324] [82] : 0x74 (116)
  4675. [2022-06-17 08:44:59.394983] [83] : 0x00 (0)
  4676. [2022-06-17 08:44:59.396633] [84] : 0x2d (45)
  4677. [2022-06-17 08:44:59.398291] [85] : 0x00 (0)
  4678. [2022-06-17 08:44:59.399930] [86] : 0x74 (116)
  4679. [2022-06-17 08:44:59.401589] [87] : 0x00 (0)
  4680. [2022-06-17 08:44:59.403275] [88] : 0x6f (111)
  4681. [2022-06-17 08:44:59.404935] [89] : 0x00 (0)
  4682. [2022-06-17 08:44:59.406589] [90] : 0x2d (45)
  4683. [2022-06-17 08:44:59.408625] [91] : 0x00 (0)
  4684. [2022-06-17 08:44:59.410370] [92] : 0x70 (112)
  4685. [2022-06-17 08:44:59.411920] [93] : 0x00 (0)
  4686. [2022-06-17 08:44:59.413481] [94] : 0x6f (111)
  4687. [2022-06-17 08:44:59.414990] [95] : 0x00 (0)
  4688. [2022-06-17 08:44:59.416680] [96] : 0x69 (105)
  4689. [2022-06-17 08:44:59.418202] [97] : 0x00 (0)
  4690. [2022-06-17 08:44:59.419691] [98] : 0x6e (110)
  4691. [2022-06-17 08:44:59.421199] [99] : 0x00 (0)
  4692. [2022-06-17 08:44:59.422687] [100] : 0x74 (116)
  4693. [2022-06-17 08:44:59.424253] [101] : 0x00 (0)
  4694. [2022-06-17 08:44:59.425752] [102] : 0x20 (32)
  4695. [2022-06-17 08:44:59.427250] [103] : 0x00 (0)
  4696. [2022-06-17 08:44:59.429048] [104] : 0x6e (110)
  4697. [2022-06-17 08:44:59.430726] [105] : 0x00 (0)
  4698. [2022-06-17 08:44:59.432385] [106] : 0x61 (97)
  4699. [2022-06-17 08:44:59.434130] [107] : 0x00 (0)
  4700. [2022-06-17 08:44:59.435785] [108] : 0x6d (109)
  4701. [2022-06-17 08:44:59.437427] [109] : 0x00 (0)
  4702. [2022-06-17 08:44:59.439074] [110] : 0x65 (101)
  4703. [2022-06-17 08:44:59.440593] [111] : 0x00 (0)
  4704. [2022-06-17 08:44:59.442088] [112] : 0x20 (32)
  4705. [2022-06-17 08:44:59.443924] [113] : 0x00 (0)
  4706. [2022-06-17 08:44:59.445594] [114] : 0x73 (115)
  4707. [2022-06-17 08:44:59.447243] [115] : 0x00 (0)
  4708. [2022-06-17 08:44:59.448879] [116] : 0x65 (101)
  4709. [2022-06-17 08:44:59.450520] [117] : 0x00 (0)
  4710. [2022-06-17 08:44:59.452171] [118] : 0x72 (114)
  4711. [2022-06-17 08:44:59.453869] [119] : 0x00 (0)
  4712. [2022-06-17 08:44:59.455521] [120] : 0x76 (118)
  4713. [2022-06-17 08:44:59.457188] [121] : 0x00 (0)
  4714. [2022-06-17 08:44:59.458842] [122] : 0x65 (101)
  4715. [2022-06-17 08:44:59.460498] [123] : 0x00 (0)
  4716. [2022-06-17 08:44:59.462132] [124] : 0x72 (114)
  4717. [2022-06-17 08:44:59.463834] [125] : 0x00 (0)
  4718. [2022-06-17 08:44:59.465483] [126] : 0x28 (40)
  4719. [2022-06-17 08:44:59.467240] [127] : 0x00 (0)
  4720. [2022-06-17 08:44:59.468905] [128] : 0x6e (110)
  4721. [2022-06-17 08:44:59.470574] [129] : 0x00 (0)
  4722. [2022-06-17 08:44:59.472227] [130] : 0x6f (111)
  4723. [2022-06-17 08:44:59.473914] [131] : 0x00 (0)
  4724. [2022-06-17 08:44:59.475551] [132] : 0x74 (116)
  4725. [2022-06-17 08:44:59.477204] [133] : 0x00 (0)
  4726. [2022-06-17 08:44:59.478853] [134] : 0x20 (32)
  4727. [2022-06-17 08:44:59.480496] [135] : 0x00 (0)
  4728. [2022-06-17 08:44:59.482143] [136] : 0x72 (114)
  4729. [2022-06-17 08:44:59.483859] [137] : 0x00 (0)
  4730. [2022-06-17 08:44:59.485524] [138] : 0x65 (101)
  4731. [2022-06-17 08:44:59.487173] [139] : 0x00 (0)
  4732. [2022-06-17 08:44:59.488816] [140] : 0x6d (109)
  4733. [2022-06-17 08:44:59.490339] [141] : 0x00 (0)
  4734. [2022-06-17 08:44:59.492064] [142] : 0x6f (111)
  4735. [2022-06-17 08:44:59.493780] [143] : 0x00 (0)
  4736. [2022-06-17 08:44:59.495313] [144] : 0x74 (116)
  4737. [2022-06-17 08:44:59.496821] [145] : 0x00 (0)
  4738. [2022-06-17 08:44:59.498309] [146] : 0x65 (101)
  4739. [2022-06-17 08:44:59.499797] [147] : 0x00 (0)
  4740. [2022-06-17 08:44:59.501501] [148] : 0x6c (108)
  4741. [2022-06-17 08:44:59.503216] [149] : 0x00 (0)
  4742. [2022-06-17 08:44:59.504897] [150] : 0x79 (121)
  4743. [2022-06-17 08:44:59.506555] [151] : 0x00 (0)
  4744. [2022-06-17 08:44:59.508201] [152] : 0x20 (32)
  4745. [2022-06-17 08:44:59.509832] [153] : 0x00 (0)
  4746. [2022-06-17 08:44:59.511476] [154] : 0x6d (109)
  4747. [2022-06-17 08:44:59.513168] [155] : 0x00 (0)
  4748. [2022-06-17 08:44:59.514818] [156] : 0x61 (97)
  4749. [2022-06-17 08:44:59.516477] [157] : 0x00 (0)
  4750. [2022-06-17 08:44:59.518126] [158] : 0x6e (110)
  4751. [2022-06-17 08:44:59.519762] [159] : 0x00 (0)
  4752. [2022-06-17 08:44:59.521405] [160] : 0x61 (97)
  4753. [2022-06-17 08:44:59.523087] [161] : 0x00 (0)
  4754. [2022-06-17 08:44:59.524730] [162] : 0x67 (103)
  4755. [2022-06-17 08:44:59.526382] [163] : 0x00 (0)
  4756. [2022-06-17 08:44:59.527902] [164] : 0x65 (101)
  4757. [2022-06-17 08:44:59.529697] [165] : 0x00 (0)
  4758. [2022-06-17 08:44:59.531369] [166] : 0x61 (97)
  4759. [2022-06-17 08:44:59.533065] [167] : 0x00 (0)
  4760. [2022-06-17 08:44:59.534720] [168] : 0x62 (98)
  4761. [2022-06-17 08:44:59.536371] [169] : 0x00 (0)
  4762. [2022-06-17 08:44:59.538013] [170] : 0x6c (108)
  4763. [2022-06-17 08:44:59.539655] [171] : 0x00 (0)
  4764. [2022-06-17 08:44:59.541304] [172] : 0x65 (101)
  4765. [2022-06-17 08:44:59.542993] [173] : 0x00 (0)
  4766. [2022-06-17 08:44:59.544646] [174] : 0x29 (41)
  4767. [2022-06-17 08:44:59.546295] [175] : 0x00 (0)
  4768. [2022-06-17 08:44:59.547941] [176] : 0x00 (0)
  4769. [2022-06-17 08:44:59.549575] [177] : 0x00 (0)
  4770. [2022-06-17 08:44:59.552250] size : 0x000000b2 (178)
  4771. [2022-06-17 08:44:59.554339] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS:Description]
  4772. [2022-06-17 08:44:59.556141] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4773. [2022-06-17 08:44:59.558078] winreg_SetValue: struct winreg_SetValue
  4774. [2022-06-17 08:44:59.560426] out: struct winreg_SetValue
  4775. [2022-06-17 08:44:59.562543] result : WERR_OK
  4776. [2022-06-17 08:44:59.564401] winreg_CloseKey: struct winreg_CloseKey
  4777. [2022-06-17 08:44:59.565922] in: struct winreg_CloseKey
  4778. [2022-06-17 08:44:59.567427] handle : *
  4779. [2022-06-17 08:44:59.568945] handle: struct policy_handle
  4780. [2022-06-17 08:44:59.570678] handle_type : 0x00000001 (1)
  4781. [2022-06-17 08:44:59.572202] uuid : 70909e2a-31dd-4270-8e39-1d9498055cc2
  4782. [2022-06-17 08:44:59.573753] regdb_close: decrementing refcount (4->3)
  4783. [2022-06-17 08:44:59.575258] winreg_CloseKey: struct winreg_CloseKey
  4784. [2022-06-17 08:44:59.576752] out: struct winreg_CloseKey
  4785. [2022-06-17 08:44:59.578237] handle : *
  4786. [2022-06-17 08:44:59.580370] handle: struct policy_handle
  4787. [2022-06-17 08:44:59.581919] handle_type : 0x00000000 (0)
  4788. [2022-06-17 08:44:59.583499] uuid : 00000000-0000-0000-0000-000000000000
  4789. [2022-06-17 08:44:59.585193] result : WERR_OK
  4790. [2022-06-17 08:44:59.586727] winreg_CreateKey: struct winreg_CreateKey
  4791. [2022-06-17 08:44:59.588242] in: struct winreg_CreateKey
  4792. [2022-06-17 08:44:59.589724] handle : *
  4793. [2022-06-17 08:44:59.591214] handle: struct policy_handle
  4794. [2022-06-17 08:44:59.592724] handle_type : 0x00000001 (1)
  4795. [2022-06-17 08:44:59.594304] uuid : 3564441c-52f4-47de-a43c-e15155f8a4c8
  4796. [2022-06-17 08:44:59.595827] name: struct winreg_String
  4797. [2022-06-17 08:44:59.597319] name_len : 0x0060 (96)
  4798. [2022-06-17 08:44:59.598828] name_size : 0x0060 (96)
  4799. [2022-06-17 08:44:59.600549] name : *
  4800. [2022-06-17 08:44:59.602072] name : 'SYSTEM\CurrentControlSet\Services\WINS\Security'
  4801. [2022-06-17 08:44:59.603665] keyclass: struct winreg_String
  4802. [2022-06-17 08:44:59.605181] name_len : 0x0002 (2)
  4803. [2022-06-17 08:44:59.606687] name_size : 0x0002 (2)
  4804. [2022-06-17 08:44:59.608180] name : *
  4805. [2022-06-17 08:44:59.609674] name : ''
  4806. [2022-06-17 08:44:59.611166] options : 0x00000000 (0)
  4807. [2022-06-17 08:44:59.612668] 0: REG_OPTION_VOLATILE
  4808. [2022-06-17 08:44:59.614379] 0: REG_OPTION_CREATE_LINK
  4809. [2022-06-17 08:44:59.615935] 0: REG_OPTION_BACKUP_RESTORE
  4810. [2022-06-17 08:44:59.617450] 0: REG_OPTION_OPEN_LINK
  4811. [2022-06-17 08:44:59.618945] access_mask : 0x02000000 (33554432)
  4812. [2022-06-17 08:44:59.620441] 0: KEY_QUERY_VALUE
  4813. [2022-06-17 08:44:59.621945] 0: KEY_SET_VALUE
  4814. [2022-06-17 08:44:59.623486] 0: KEY_CREATE_SUB_KEY
  4815. [2022-06-17 08:44:59.625011] 0: KEY_ENUMERATE_SUB_KEYS
  4816. [2022-06-17 08:44:59.626515] 0: KEY_NOTIFY
  4817. [2022-06-17 08:44:59.628015] 0: KEY_CREATE_LINK
  4818. [2022-06-17 08:44:59.629691] 0: KEY_WOW64_64KEY
  4819. [2022-06-17 08:44:59.631226] 0: KEY_WOW64_32KEY
  4820. [2022-06-17 08:44:59.632725] secdesc : NULL
  4821. [2022-06-17 08:44:59.634390] action_taken : *
  4822. [2022-06-17 08:44:59.635901] action_taken : REG_OPENED_EXISTING_KEY (2)
  4823. [2022-06-17 08:44:59.637426] _winreg_CreateKey called with parent key 'HKLM' and subkey name 'SYSTEM\CurrentControlSet\Services\WINS\Security'
  4824. [2022-06-17 08:44:59.638970] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  4825. [2022-06-17 08:44:59.640472] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4826. [2022-06-17 08:44:59.641974] regkey_open_onelevel: name = [SYSTEM]
  4827. [2022-06-17 08:44:59.643519] regdb_open: incrementing refcount (3->4)
  4828. [2022-06-17 08:44:59.645832] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  4829. [2022-06-17 08:44:59.647384] pathtree_find: Enter [\HKLM\SYSTEM]
  4830. [2022-06-17 08:44:59.648896] pathtree_find: Exit
  4831. [2022-06-17 08:44:59.650384] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  4832. [2022-06-17 08:44:59.652138] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4833. [2022-06-17 08:44:59.654015] regkey_open_onelevel: name = [CurrentControlSet]
  4834. [2022-06-17 08:44:59.655683] regdb_open: incrementing refcount (4->5)
  4835. [2022-06-17 08:44:59.657324] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  4836. [2022-06-17 08:44:59.658977] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  4837. [2022-06-17 08:44:59.660631] pathtree_find: Exit
  4838. [2022-06-17 08:44:59.662264] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  4839. [2022-06-17 08:44:59.664008] regdb_close: decrementing refcount (5->4)
  4840. [2022-06-17 08:44:59.665661] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4841. [2022-06-17 08:44:59.667308] regkey_open_onelevel: name = [Services]
  4842. [2022-06-17 08:44:59.668936] regdb_open: incrementing refcount (4->5)
  4843. [2022-06-17 08:44:59.670575] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  4844. [2022-06-17 08:44:59.672229] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  4845. [2022-06-17 08:44:59.673923] pathtree_find: Exit
  4846. [2022-06-17 08:44:59.675563] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  4847. [2022-06-17 08:44:59.677239] regdb_close: decrementing refcount (5->4)
  4848. [2022-06-17 08:44:59.678874] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 2
  4849. [2022-06-17 08:44:59.680524] regkey_open_onelevel: name = [WINS]
  4850. [2022-06-17 08:44:59.682157] regdb_open: incrementing refcount (4->5)
  4851. [2022-06-17 08:44:59.683984] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4852. [2022-06-17 08:44:59.685657] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4853. [2022-06-17 08:44:59.687306] pathtree_find: Exit
  4854. [2022-06-17 08:44:59.688938] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\WINS]
  4855. [2022-06-17 08:44:59.690603] regdb_close: decrementing refcount (5->4)
  4856. [2022-06-17 08:44:59.692239] regkey_open_onelevel: name = [Security]
  4857. [2022-06-17 08:44:59.693795] regdb_open: incrementing refcount (4->5)
  4858. [2022-06-17 08:44:59.695301] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
  4859. [2022-06-17 08:44:59.697120] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
  4860. [2022-06-17 08:44:59.698794] pathtree_find: Exit
  4861. [2022-06-17 08:44:59.700414] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
  4862. [2022-06-17 08:44:59.702097] regdb_close: decrementing refcount (5->4)
  4863. [2022-06-17 08:44:59.703832] winreg_CreateKey: struct winreg_CreateKey
  4864. [2022-06-17 08:44:59.705487] out: struct winreg_CreateKey
  4865. [2022-06-17 08:44:59.707124] new_handle : *
  4866. [2022-06-17 08:44:59.708771] new_handle: struct policy_handle
  4867. [2022-06-17 08:44:59.710426] handle_type : 0x00000001 (1)
  4868. [2022-06-17 08:44:59.712064] uuid : d50d4dd8-c0d3-48d7-9646-9ee598d8b132
  4869. [2022-06-17 08:44:59.713778] action_taken : *
  4870. [2022-06-17 08:44:59.715425] action_taken : REG_OPENED_EXISTING_KEY (2)
  4871. [2022-06-17 08:44:59.717077] result : WERR_OK
  4872. [2022-06-17 08:44:59.718713] winreg_SetValue: struct winreg_SetValue
  4873. [2022-06-17 08:44:59.720342] in: struct winreg_SetValue
  4874. [2022-06-17 08:44:59.721870] handle : *
  4875. [2022-06-17 08:44:59.723423] handle: struct policy_handle
  4876. [2022-06-17 08:44:59.725151] handle_type : 0x00000001 (1)
  4877. [2022-06-17 08:44:59.726785] uuid : d50d4dd8-c0d3-48d7-9646-9ee598d8b132
  4878. [2022-06-17 08:44:59.728446] name: struct winreg_String
  4879. [2022-06-17 08:44:59.730089] name_len : 0x0012 (18)
  4880. [2022-06-17 08:44:59.731725] name_size : 0x0012 (18)
  4881. [2022-06-17 08:44:59.733428] name : *
  4882. [2022-06-17 08:44:59.735098] name : 'Security'
  4883. [2022-06-17 08:44:59.736747] type : REG_BINARY (3)
  4884. [2022-06-17 08:44:59.738387] data : *
  4885. [2022-06-17 08:44:59.740019] data: ARRAY(120)
  4886. [2022-06-17 08:44:59.741648] [0] : 0x01 (1)
  4887. [2022-06-17 08:44:59.743349] [1] : 0x00 (0)
  4888. [2022-06-17 08:44:59.745005] [2] : 0x04 (4)
  4889. [2022-06-17 08:44:59.746655] [3] : 0x80 (128)
  4890. [2022-06-17 08:44:59.748316] [4] : 0x00 (0)
  4891. [2022-06-17 08:44:59.749968] [5] : 0x00 (0)
  4892. [2022-06-17 08:44:59.751611] [6] : 0x00 (0)
  4893. [2022-06-17 08:44:59.753298] [7] : 0x00 (0)
  4894. [2022-06-17 08:44:59.754949] [8] : 0x00 (0)
  4895. [2022-06-17 08:44:59.756590] [9] : 0x00 (0)
  4896. [2022-06-17 08:44:59.758238] [10] : 0x00 (0)
  4897. [2022-06-17 08:44:59.759888] [11] : 0x00 (0)
  4898. [2022-06-17 08:44:59.761536] [12] : 0x00 (0)
  4899. [2022-06-17 08:44:59.763228] [13] : 0x00 (0)
  4900. [2022-06-17 08:44:59.764879] [14] : 0x00 (0)
  4901. [2022-06-17 08:44:59.766398] [15] : 0x00 (0)
  4902. [2022-06-17 08:44:59.767906] [16] : 0x14 (20)
  4903. [2022-06-17 08:44:59.769409] [17] : 0x00 (0)
  4904. [2022-06-17 08:44:59.771154] [18] : 0x00 (0)
  4905. [2022-06-17 08:44:59.772802] [19] : 0x00 (0)
  4906. [2022-06-17 08:44:59.774509] [20] : 0x02 (2)
  4907. [2022-06-17 08:44:59.776035] [21] : 0x00 (0)
  4908. [2022-06-17 08:44:59.777768] [22] : 0x64 (100)
  4909. [2022-06-17 08:44:59.779413] [23] : 0x00 (0)
  4910. [2022-06-17 08:44:59.780938] [24] : 0x04 (4)
  4911. [2022-06-17 08:44:59.782457] [25] : 0x00 (0)
  4912. [2022-06-17 08:44:59.784042] [26] : 0x00 (0)
  4913. [2022-06-17 08:44:59.785551] [27] : 0x00 (0)
  4914. [2022-06-17 08:44:59.787043] [28] : 0x00 (0)
  4915. [2022-06-17 08:44:59.788538] [29] : 0x00 (0)
  4916. [2022-06-17 08:44:59.790017] [30] : 0x14 (20)
  4917. [2022-06-17 08:44:59.791512] [31] : 0x00 (0)
  4918. [2022-06-17 08:44:59.793456] [32] : 0x8d (141)
  4919. [2022-06-17 08:44:59.795152] [33] : 0x01 (1)
  4920. [2022-06-17 08:44:59.796814] [34] : 0x02 (2)
  4921. [2022-06-17 08:44:59.798445] [35] : 0x00 (0)
  4922. [2022-06-17 08:44:59.800079] [36] : 0x01 (1)
  4923. [2022-06-17 08:44:59.801716] [37] : 0x01 (1)
  4924. [2022-06-17 08:44:59.803412] [38] : 0x00 (0)
  4925. [2022-06-17 08:44:59.805070] [39] : 0x00 (0)
  4926. [2022-06-17 08:44:59.806732] [40] : 0x00 (0)
  4927. [2022-06-17 08:44:59.808398] [41] : 0x00 (0)
  4928. [2022-06-17 08:44:59.810041] [42] : 0x00 (0)
  4929. [2022-06-17 08:44:59.811684] [43] : 0x01 (1)
  4930. [2022-06-17 08:44:59.813253] [44] : 0x00 (0)
  4931. [2022-06-17 08:44:59.814982] [45] : 0x00 (0)
  4932. [2022-06-17 08:44:59.816626] [46] : 0x00 (0)
  4933. [2022-06-17 08:44:59.818271] [47] : 0x00 (0)
  4934. [2022-06-17 08:44:59.819928] [48] : 0x00 (0)
  4935. [2022-06-17 08:44:59.822190] [49] : 0x00 (0)
  4936. [2022-06-17 08:44:59.823939] [50] : 0x18 (24)
  4937. [2022-06-17 08:44:59.825697] [51] : 0x00 (0)
  4938. [2022-06-17 08:44:59.827329] [52] : 0xfd (253)
  4939. [2022-06-17 08:44:59.828983] [53] : 0x01 (1)
  4940. [2022-06-17 08:44:59.830633] [54] : 0x02 (2)
  4941. [2022-06-17 08:44:59.832282] [55] : 0x00 (0)
  4942. [2022-06-17 08:44:59.833998] [56] : 0x01 (1)
  4943. [2022-06-17 08:44:59.835653] [57] : 0x02 (2)
  4944. [2022-06-17 08:44:59.837303] [58] : 0x00 (0)
  4945. [2022-06-17 08:44:59.838954] [59] : 0x00 (0)
  4946. [2022-06-17 08:44:59.840594] [60] : 0x00 (0)
  4947. [2022-06-17 08:44:59.842241] [61] : 0x00 (0)
  4948. [2022-06-17 08:44:59.843930] [62] : 0x00 (0)
  4949. [2022-06-17 08:44:59.845601] [63] : 0x05 (5)
  4950. [2022-06-17 08:44:59.847250] [64] : 0x20 (32)
  4951. [2022-06-17 08:44:59.849459] [65] : 0x00 (0)
  4952. [2022-06-17 08:44:59.851623] [66] : 0x00 (0)
  4953. [2022-06-17 08:44:59.853797] [67] : 0x00 (0)
  4954. [2022-06-17 08:44:59.855630] [68] : 0x23 (35)
  4955. [2022-06-17 08:44:59.857306] [69] : 0x02 (2)
  4956. [2022-06-17 08:44:59.858957] [70] : 0x00 (0)
  4957. [2022-06-17 08:44:59.860605] [71] : 0x00 (0)
  4958. [2022-06-17 08:44:59.862253] [72] : 0x00 (0)
  4959. [2022-06-17 08:44:59.863971] [73] : 0x00 (0)
  4960. [2022-06-17 08:44:59.865631] [74] : 0x18 (24)
  4961. [2022-06-17 08:44:59.867278] [75] : 0x00 (0)
  4962. [2022-06-17 08:44:59.868915] [76] : 0xff (255)
  4963. [2022-06-17 08:44:59.871216] [77] : 0x01 (1)
  4964. [2022-06-17 08:44:59.872930] [78] : 0x0f (15)
  4965. [2022-06-17 08:44:59.874597] [79] : 0x00 (0)
  4966. [2022-06-17 08:44:59.876268] [80] : 0x01 (1)
  4967. [2022-06-17 08:44:59.877925] [81] : 0x02 (2)
  4968. [2022-06-17 08:44:59.879556] [82] : 0x00 (0)
  4969. [2022-06-17 08:44:59.881194] [83] : 0x00 (0)
  4970. [2022-06-17 08:44:59.882844] [84] : 0x00 (0)
  4971. [2022-06-17 08:44:59.884551] [85] : 0x00 (0)
  4972. [2022-06-17 08:44:59.886203] [86] : 0x00 (0)
  4973. [2022-06-17 08:44:59.887840] [87] : 0x05 (5)
  4974. [2022-06-17 08:44:59.889481] [88] : 0x20 (32)
  4975. [2022-06-17 08:44:59.891138] [89] : 0x00 (0)
  4976. [2022-06-17 08:44:59.892781] [90] : 0x00 (0)
  4977. [2022-06-17 08:44:59.894493] [91] : 0x00 (0)
  4978. [2022-06-17 08:44:59.896143] [92] : 0x25 (37)
  4979. [2022-06-17 08:44:59.897791] [93] : 0x02 (2)
  4980. [2022-06-17 08:44:59.899382] [94] : 0x00 (0)
  4981. [2022-06-17 08:44:59.900918] [95] : 0x00 (0)
  4982. [2022-06-17 08:44:59.902428] [96] : 0x00 (0)
  4983. [2022-06-17 08:44:59.904317] [97] : 0x00 (0)
  4984. [2022-06-17 08:44:59.905982] [98] : 0x18 (24)
  4985. [2022-06-17 08:44:59.907637] [99] : 0x00 (0)
  4986. [2022-06-17 08:44:59.909296] [100] : 0xff (255)
  4987. [2022-06-17 08:44:59.910822] [101] : 0x01 (1)
  4988. [2022-06-17 08:44:59.912315] [102] : 0x0f (15)
  4989. [2022-06-17 08:44:59.913887] [103] : 0x00 (0)
  4990. [2022-06-17 08:44:59.915673] [104] : 0x01 (1)
  4991. [2022-06-17 08:44:59.917335] [105] : 0x02 (2)
  4992. [2022-06-17 08:44:59.918986] [106] : 0x00 (0)
  4993. [2022-06-17 08:44:59.920625] [107] : 0x00 (0)
  4994. [2022-06-17 08:44:59.922277] [108] : 0x00 (0)
  4995. [2022-06-17 08:44:59.923999] [109] : 0x00 (0)
  4996. [2022-06-17 08:44:59.925649] [110] : 0x00 (0)
  4997. [2022-06-17 08:44:59.927171] [111] : 0x05 (5)
  4998. [2022-06-17 08:44:59.928883] [112] : 0x20 (32)
  4999. [2022-06-17 08:44:59.930533] [113] : 0x00 (0)
  5000. [2022-06-17 08:44:59.932177] [114] : 0x00 (0)
  5001. [2022-06-17 08:44:59.933870] [115] : 0x00 (0)
  5002. [2022-06-17 08:44:59.935514] [116] : 0x20 (32)
  5003. [2022-06-17 08:44:59.937162] [117] : 0x02 (2)
  5004. [2022-06-17 08:44:59.938817] [118] : 0x00 (0)
  5005. [2022-06-17 08:44:59.940458] [119] : 0x00 (0)
  5006. [2022-06-17 08:44:59.942097] size : 0x00000078 (120)
  5007. [2022-06-17 08:44:59.943801] _winreg_SetValue: Setting value for [HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security:Security]
  5008. [2022-06-17 08:44:59.945492] tdb(/var/lib/samba/registry.tdb): tdb_transaction_start: nesting 1
  5009. [2022-06-17 08:44:59.947143] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security' (ops 0xb6ab32e8)
  5010. [2022-06-17 08:44:59.948808] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
  5011. [2022-06-17 08:44:59.950470] regdb_unpack_values: value[0]: name[Security] len[120]
  5012. [2022-06-17 08:44:59.952125] winreg_SetValue: struct winreg_SetValue
  5013. [2022-06-17 08:44:59.953822] out: struct winreg_SetValue
  5014. [2022-06-17 08:44:59.955491] result : WERR_OK
  5015. [2022-06-17 08:44:59.957137] winreg_CloseKey: struct winreg_CloseKey
  5016. [2022-06-17 08:44:59.958785] in: struct winreg_CloseKey
  5017. [2022-06-17 08:44:59.960411] handle : *
  5018. [2022-06-17 08:44:59.962034] handle: struct policy_handle
  5019. [2022-06-17 08:44:59.963738] handle_type : 0x00000001 (1)
  5020. [2022-06-17 08:44:59.965394] uuid : d50d4dd8-c0d3-48d7-9646-9ee598d8b132
  5021. [2022-06-17 08:44:59.967074] regdb_close: decrementing refcount (4->3)
  5022. [2022-06-17 08:44:59.968709] winreg_CloseKey: struct winreg_CloseKey
  5023. [2022-06-17 08:44:59.970368] out: struct winreg_CloseKey
  5024. [2022-06-17 08:44:59.972001] handle : *
  5025. [2022-06-17 08:44:59.973692] handle: struct policy_handle
  5026. [2022-06-17 08:44:59.975339] handle_type : 0x00000000 (0)
  5027. [2022-06-17 08:44:59.976867] uuid : 00000000-0000-0000-0000-000000000000
  5028. [2022-06-17 08:44:59.978650] result : WERR_OK
  5029. [2022-06-17 08:44:59.980295] winreg_CloseKey: struct winreg_CloseKey
  5030. [2022-06-17 08:44:59.981943] in: struct winreg_CloseKey
  5031. [2022-06-17 08:44:59.983643] handle : *
  5032. [2022-06-17 08:44:59.985288] handle: struct policy_handle
  5033. [2022-06-17 08:44:59.986916] handle_type : 0x00000001 (1)
  5034. [2022-06-17 08:44:59.988562] uuid : 2db84861-daa1-4392-93ae-d86a8560d69c
  5035. [2022-06-17 08:44:59.990227] regdb_close: decrementing refcount (3->2)
  5036. [2022-06-17 08:44:59.991878] winreg_CloseKey: struct winreg_CloseKey
  5037. [2022-06-17 08:44:59.993570] out: struct winreg_CloseKey
  5038. [2022-06-17 08:44:59.995233] handle : *
  5039. [2022-06-17 08:44:59.996888] handle: struct policy_handle
  5040. [2022-06-17 08:44:59.998538] handle_type : 0x00000000 (0)
  5041. [2022-06-17 08:45:00.000189] uuid : 00000000-0000-0000-0000-000000000000
  5042. [2022-06-17 08:45:00.001849] result : WERR_OK
  5043. [2022-06-17 08:45:00.003561] regdb_close: decrementing refcount (2->1)
  5044. [2022-06-17 08:45:00.005100] regdb_close: decrementing refcount (1->0)
  5045. [2022-06-17 08:45:00.006828] dcesrv_interface_register: Interface 'svcctl' registered on endpoint 'ncacn_np:[\pipe\svcctl]' (single process required)
  5046. [2022-06-17 08:45:00.008519] dcesrv_interface_register: Interface 'svcctl' registered on endpoint 'ncalrpc:' (single process required)
  5047. [2022-06-17 08:45:00.010191] dcesrv_interface_register: Interface 'ntsvcs' registered on endpoint 'ncacn_np:[\pipe\ntsvcs]' (single process required)
  5048. [2022-06-17 08:45:00.011869] dcesrv_interface_register: Interface 'ntsvcs' registered on endpoint 'ncacn_np:[\pipe\plugplay]' (single process required)
  5049. [2022-06-17 08:45:00.013577] Initialise the eventlog registry keys if needed.
  5050. [2022-06-17 08:45:00.015235] make_internal_ncacn_conn: Create pipe requested winreg
  5051. [2022-06-17 08:45:00.016897] Created internal pipe winreg
  5052. [2022-06-17 08:45:00.018513] winreg_OpenHKLM: struct winreg_OpenHKLM
  5053. [2022-06-17 08:45:00.020780] in: struct winreg_OpenHKLM
  5054. [2022-06-17 08:45:00.022460] system_name : NULL
  5055. [2022-06-17 08:45:00.025422] access_mask : 0x02000000 (33554432)
  5056. [2022-06-17 08:45:00.033642] 0: KEY_QUERY_VALUE
  5057. [2022-06-17 08:45:00.035506] 0: KEY_SET_VALUE
  5058. [2022-06-17 08:45:00.037233] 0: KEY_CREATE_SUB_KEY
  5059. [2022-06-17 08:45:00.038910] 0: KEY_ENUMERATE_SUB_KEYS
  5060. [2022-06-17 08:45:00.040442] 0: KEY_NOTIFY
  5061. [2022-06-17 08:45:00.041946] 0: KEY_CREATE_LINK
  5062. [2022-06-17 08:45:00.043495] 0: KEY_WOW64_64KEY
  5063. [2022-06-17 08:45:00.046978] 0: KEY_WOW64_32KEY
  5064. [2022-06-17 08:45:00.048650] regkey_open_onelevel: name = [HKLM]
  5065. [2022-06-17 08:45:00.052137] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  5066. [2022-06-17 08:45:00.053979] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  5067. [2022-06-17 08:45:00.056204] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  5068. [2022-06-17 08:45:00.059795] Security token: (NULL)
  5069. [2022-06-17 08:45:00.061582] UNIX token of user 0
  5070. [2022-06-17 08:45:00.065348] Primary group is 0 and contains 0 supplementary groups
  5071. [2022-06-17 08:45:00.067178] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  5072. [2022-06-17 08:45:00.073204] regdb_open: registry db opened. refcount reset (1)
  5073. [2022-06-17 08:45:00.075067] reghook_cache_find: Searching for keyname [\HKLM]
  5074. [2022-06-17 08:45:00.076783] pathtree_find: Enter [\HKLM]
  5075. [2022-06-17 08:45:00.078464] pathtree_find: Exit
  5076. [2022-06-17 08:45:00.080187] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM]
  5077. [2022-06-17 08:45:00.083613] winreg_OpenHKLM: struct winreg_OpenHKLM
  5078. [2022-06-17 08:45:00.087146] out: struct winreg_OpenHKLM
  5079. [2022-06-17 08:45:00.088958] handle : *
  5080. [2022-06-17 08:45:00.094806] handle: struct policy_handle
  5081. [2022-06-17 08:45:00.096736] handle_type : 0x00000001 (1)
  5082. [2022-06-17 08:45:00.098467] uuid : f67da3e6-6b71-4d9b-a5a0-05a0ca660933
  5083. [2022-06-17 08:45:00.100152] result : WERR_OK
  5084. [2022-06-17 08:45:00.101796] winreg_OpenKey: struct winreg_OpenKey
  5085. [2022-06-17 08:45:00.103493] in: struct winreg_OpenKey
  5086. [2022-06-17 08:45:00.105148] parent_handle : *
  5087. [2022-06-17 08:45:00.106921] parent_handle: struct policy_handle
  5088. [2022-06-17 08:45:00.108600] handle_type : 0x00000001 (1)
  5089. [2022-06-17 08:45:00.110250] uuid : f67da3e6-6b71-4d9b-a5a0-05a0ca660933
  5090. [2022-06-17 08:45:00.111896] keyname: struct winreg_String
  5091. [2022-06-17 08:45:00.113588] name_len : 0x0056 (86)
  5092. [2022-06-17 08:45:00.115240] name_size : 0x0056 (86)
  5093. [2022-06-17 08:45:00.116881] name : *
  5094. [2022-06-17 08:45:00.118538] name : 'SYSTEM\CurrentControlSet\Services\Eventlog'
  5095. [2022-06-17 08:45:00.120201] options : 0x00000000 (0)
  5096. [2022-06-17 08:45:00.121843] 0: REG_OPTION_VOLATILE
  5097. [2022-06-17 08:45:00.123535] 0: REG_OPTION_CREATE_LINK
  5098. [2022-06-17 08:45:00.125190] 0: REG_OPTION_BACKUP_RESTORE
  5099. [2022-06-17 08:45:00.126812] 0: REG_OPTION_OPEN_LINK
  5100. [2022-06-17 08:45:00.128463] access_mask : 0x02000000 (33554432)
  5101. [2022-06-17 08:45:00.130111] 0: KEY_QUERY_VALUE
  5102. [2022-06-17 08:45:00.131759] 0: KEY_SET_VALUE
  5103. [2022-06-17 08:45:00.133478] 0: KEY_CREATE_SUB_KEY
  5104. [2022-06-17 08:45:00.135142] 0: KEY_ENUMERATE_SUB_KEYS
  5105. [2022-06-17 08:45:00.136786] 0: KEY_NOTIFY
  5106. [2022-06-17 08:45:00.138418] 0: KEY_CREATE_LINK
  5107. [2022-06-17 08:45:00.140050] 0: KEY_WOW64_64KEY
  5108. [2022-06-17 08:45:00.141694] 0: KEY_WOW64_32KEY
  5109. [2022-06-17 08:45:00.143388] regkey_open_onelevel: name = [SYSTEM]
  5110. [2022-06-17 08:45:00.145039] regdb_open: incrementing refcount (1->2)
  5111. [2022-06-17 08:45:00.146678] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM]
  5112. [2022-06-17 08:45:00.148307] pathtree_find: Enter [\HKLM\SYSTEM]
  5113. [2022-06-17 08:45:00.149926] pathtree_find: Exit
  5114. [2022-06-17 08:45:00.151551] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM]
  5115. [2022-06-17 08:45:00.153238] regkey_open_onelevel: name = [CurrentControlSet]
  5116. [2022-06-17 08:45:00.154910] regdb_open: incrementing refcount (2->3)
  5117. [2022-06-17 08:45:00.156550] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet]
  5118. [2022-06-17 08:45:00.158185] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet]
  5119. [2022-06-17 08:45:00.159824] pathtree_find: Exit
  5120. [2022-06-17 08:45:00.161437] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet]
  5121. [2022-06-17 08:45:00.163140] regkey_open_onelevel: name = [Services]
  5122. [2022-06-17 08:45:00.164795] regdb_open: incrementing refcount (3->4)
  5123. [2022-06-17 08:45:00.166428] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services]
  5124. [2022-06-17 08:45:00.168097] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services]
  5125. [2022-06-17 08:45:00.169756] pathtree_find: Exit
  5126. [2022-06-17 08:45:00.171378] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services]
  5127. [2022-06-17 08:45:00.173074] regkey_open_onelevel: name = [Eventlog]
  5128. [2022-06-17 08:45:00.174713] regdb_open: incrementing refcount (4->5)
  5129. [2022-06-17 08:45:00.176354] reghook_cache_find: Searching for keyname [\HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  5130. [2022-06-17 08:45:00.178020] pathtree_find: Enter [\HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  5131. [2022-06-17 08:45:00.179671] pathtree_find: Exit
  5132. [2022-06-17 08:45:00.181389] reghook_cache_find: found ops 0xb6ab32e8 for key [\HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  5133. [2022-06-17 08:45:00.183175] regdb_close: decrementing refcount (5->4)
  5134. [2022-06-17 08:45:00.184853] regdb_close: decrementing refcount (4->3)
  5135. [2022-06-17 08:45:00.186497] regdb_close: decrementing refcount (3->2)
  5136. [2022-06-17 08:45:00.188121] winreg_OpenKey: struct winreg_OpenKey
  5137. [2022-06-17 08:45:00.189757] out: struct winreg_OpenKey
  5138. [2022-06-17 08:45:00.191386] handle : *
  5139. [2022-06-17 08:45:00.193069] handle: struct policy_handle
  5140. [2022-06-17 08:45:00.194723] handle_type : 0x00000001 (1)
  5141. [2022-06-17 08:45:00.196370] uuid : d3a7ffb5-076b-4a8c-9b97-30015f6cce9b
  5142. [2022-06-17 08:45:00.198039] result : WERR_OK
  5143. [2022-06-17 08:45:00.199674] winreg_QueryInfoKey: struct winreg_QueryInfoKey
  5144. [2022-06-17 08:45:00.201302] in: struct winreg_QueryInfoKey
  5145. [2022-06-17 08:45:00.202977] handle : *
  5146. [2022-06-17 08:45:00.204624] handle: struct policy_handle
  5147. [2022-06-17 08:45:00.206151] handle_type : 0x00000001 (1)
  5148. [2022-06-17 08:45:00.207662] uuid : d3a7ffb5-076b-4a8c-9b97-30015f6cce9b
  5149. [2022-06-17 08:45:00.209414] classname : *
  5150. [2022-06-17 08:45:00.211039] classname: struct winreg_String
  5151. [2022-06-17 08:45:00.212680] name_len : 0x0000 (0)
  5152. [2022-06-17 08:45:00.214424] name_size : 0x0000 (0)
  5153. [2022-06-17 08:45:00.216066] name : NULL
  5154. [2022-06-17 08:45:00.217716] fetch_reg_values called for key 'HKLM\SYSTEM\CurrentControlSet\Services\Eventlog' (ops 0xb6ab32e8)
  5155. [2022-06-17 08:45:00.219394] regdb_fetch_values: Looking for values of key [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  5156. [2022-06-17 08:45:00.220934] regdb_unpack_values: value[0]: name[DisplayName] len[20]
  5157. [2022-06-17 08:45:00.222434] regdb_unpack_values: value[1]: name[ErrorControl] len[4]
  5158. [2022-06-17 08:45:00.224257] regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
  5159. [2022-06-17 08:45:00.225923] winreg_QueryInfoKey: struct winreg_QueryInfoKey
  5160. [2022-06-17 08:45:00.227457] out: struct winreg_QueryInfoKey
  5161. [2022-06-17 08:45:00.228959] classname : *
  5162. [2022-06-17 08:45:00.230617] classname: struct winreg_String
  5163. [2022-06-17 08:45:00.232114] name_len : 0x0000 (0)
  5164. [2022-06-17 08:45:00.233656] name_size : 0x0000 (0)
  5165. [2022-06-17 08:45:00.235160] name : NULL
  5166. [2022-06-17 08:45:00.236653] num_subkeys : *
  5167. [2022-06-17 08:45:00.238144] num_subkeys : 0x00000000 (0)
  5168. [2022-06-17 08:45:00.239636] max_subkeylen : *
  5169. [2022-06-17 08:45:00.241126] max_subkeylen : 0x00000000 (0)
  5170. [2022-06-17 08:45:00.242616] max_classlen : *
  5171. [2022-06-17 08:45:00.244330] max_classlen : 0x00000000 (0)
  5172. [2022-06-17 08:45:00.245879] num_values : *
  5173. [2022-06-17 08:45:00.247388] num_values : 0x00000002 (2)
  5174. [2022-06-17 08:45:00.248888] max_valnamelen : *
  5175. [2022-06-17 08:45:00.250383] max_valnamelen : 0x0000001a (26)
  5176. [2022-06-17 08:45:00.252243] max_valbufsize : *
  5177. [2022-06-17 08:45:00.253980] max_valbufsize : 0x00000014 (20)
  5178. [2022-06-17 08:45:00.255743] secdescsize : *
  5179. [2022-06-17 08:45:00.257262] secdescsize : 0x00000078 (120)
  5180. [2022-06-17 08:45:00.258977] last_changed_time : *
  5181. [2022-06-17 08:45:00.260489] last_changed_time : NTTIME(0)
  5182. [2022-06-17 08:45:00.262154] result : WERR_OK
  5183. [2022-06-17 08:45:00.263734] winreg_CloseKey: struct winreg_CloseKey
  5184. [2022-06-17 08:45:00.265258] in: struct winreg_CloseKey
  5185. [2022-06-17 08:45:00.266740] handle : *
  5186. [2022-06-17 08:45:00.268522] handle: struct policy_handle
  5187. [2022-06-17 08:45:00.270154] handle_type : 0x00000001 (1)
  5188. [2022-06-17 08:45:00.271786] uuid : d3a7ffb5-076b-4a8c-9b97-30015f6cce9b
  5189. [2022-06-17 08:45:00.273377] regdb_close: decrementing refcount (2->1)
  5190. [2022-06-17 08:45:00.274899] winreg_CloseKey: struct winreg_CloseKey
  5191. [2022-06-17 08:45:00.276661] out: struct winreg_CloseKey
  5192. [2022-06-17 08:45:00.278297] handle : *
  5193. [2022-06-17 08:45:00.279952] handle: struct policy_handle
  5194. [2022-06-17 08:45:00.281586] handle_type : 0x00000000 (0)
  5195. [2022-06-17 08:45:00.283165] uuid : 00000000-0000-0000-0000-000000000000
  5196. [2022-06-17 08:45:00.284704] result : WERR_OK
  5197. [2022-06-17 08:45:00.286348] regdb_close: decrementing refcount (1->0)
  5198. [2022-06-17 08:45:00.288117] dcesrv_interface_register: Interface 'eventlog' registered on endpoint 'ncacn_np:[\pipe\eventlog]' (single process required)
  5199. [2022-06-17 08:45:00.289800] dcesrv_interface_register: Interface 'initshutdown' registered on endpoint 'ncacn_np:[\pipe\InitShutdown]' (single process required)
  5200. [2022-06-17 08:45:00.291491] dcesrv_init: Initializing DCE/RPC connection endpoints
  5201. [2022-06-17 08:45:00.293173] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\InitShutdown]'
  5202. [2022-06-17 08:45:00.294860] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 25 for initshutdown
  5203. [2022-06-17 08:45:00.296508] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\InitShutdown]' for 'initshutdown' 'mgmt'
  5204. [2022-06-17 08:45:00.298190] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\eventlog]'
  5205. [2022-06-17 08:45:00.299850] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 26 for eventlog
  5206. [2022-06-17 08:45:00.301387] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\eventlog]' for 'eventlog' 'mgmt'
  5207. [2022-06-17 08:45:00.303221] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\plugplay]'
  5208. [2022-06-17 08:45:00.304888] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 27 for plugplay
  5209. [2022-06-17 08:45:00.306538] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\plugplay]' for 'ntsvcs' 'mgmt'
  5210. [2022-06-17 08:45:00.308216] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\ntsvcs]'
  5211. [2022-06-17 08:45:00.309887] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 28 for ntsvcs
  5212. [2022-06-17 08:45:00.311539] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\ntsvcs]' for 'ntsvcs' 'mgmt'
  5213. [2022-06-17 08:45:00.313259] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\svcctl]'
  5214. [2022-06-17 08:45:00.314926] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 29 for svcctl
  5215. [2022-06-17 08:45:00.316578] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\svcctl]' for 'svcctl' 'mgmt'
  5216. [2022-06-17 08:45:00.318250] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\wkssvc]'
  5217. [2022-06-17 08:45:00.319905] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 30 for wkssvc
  5218. [2022-06-17 08:45:00.321555] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\wkssvc]' for 'wkssvc' 'mgmt'
  5219. [2022-06-17 08:45:00.323287] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\netdfs]'
  5220. [2022-06-17 08:45:00.324965] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 31 for netdfs
  5221. [2022-06-17 08:45:00.326626] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\netdfs]' for 'netdfs' 'mgmt'
  5222. [2022-06-17 08:45:00.328305] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\samr]'
  5223. [2022-06-17 08:45:00.329956] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 32 for samr
  5224. [2022-06-17 08:45:00.331610] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\samr]' for 'samr' 'mgmt'
  5225. [2022-06-17 08:45:00.333325] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\lsass]'
  5226. [2022-06-17 08:45:00.334972] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 33 for lsass
  5227. [2022-06-17 08:45:00.336642] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\lsass]' for 'dssetup' 'lsarpc' 'mgmt'
  5228. [2022-06-17 08:45:00.338337] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\lsarpc]'
  5229. [2022-06-17 08:45:00.340002] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 34 for lsarpc
  5230. [2022-06-17 08:45:00.341641] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\lsarpc]' for 'dssetup' 'lsarpc' 'mgmt'
  5231. [2022-06-17 08:45:00.343356] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\netlogon]'
  5232. [2022-06-17 08:45:00.344910] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 35 for netlogon
  5233. [2022-06-17 08:45:00.346430] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\netlogon]' for 'lsarpc' 'mgmt'
  5234. [2022-06-17 08:45:00.347960] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\srvsvc]'
  5235. [2022-06-17 08:45:00.349709] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 36 for srvsvc
  5236. [2022-06-17 08:45:00.351353] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\srvsvc]' for 'srvsvc' 'mgmt'
  5237. [2022-06-17 08:45:00.353074] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncalrpc:'
  5238. [2022-06-17 08:45:00.354736] dcesrv_create_ncalrpc_socket: Opened ncalrpc socket fd '37' for '/var/run/samba/ncalrpc/DEFAULT'
  5239. [2022-06-17 08:45:00.356290] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncalrpc:[DEFAULT]' for 'svcctl' 'wkssvc' 'dssetup' 'netdfs' 'samr' 'lsarpc' 'srvsvc' 'winreg' 'mgmt'
  5240. [2022-06-17 08:45:00.358006] dcesrv_setup_endpoint_sockets: Setting up endpoint 'ncacn_np:[\pipe\winreg]'
  5241. [2022-06-17 08:45:00.359664] dcesrv_create_ncacn_np_socket: Opened pipe socket fd 38 for winreg
  5242. [2022-06-17 08:45:00.361305] dcesrv_setup_endpoint_sockets: Successfully listening on 'ncacn_np:[\pipe\winreg]' for 'winreg' 'mgmt'
  5243. [2022-06-17 08:45:00.362914] daemon_ready: daemon 'smbd' finished starting up and ready to serve connections
  5244. [2022-06-17 08:45:00.364446] bind succeeded on port 445
  5245. [2022-06-17 08:45:00.366098] Socket options:
  5246. [2022-06-17 08:45:00.367573] SO_KEEPALIVE = 1
  5247. [2022-06-17 08:45:00.369037] SO_REUSEADDR = 1
  5248. [2022-06-17 08:45:00.370518] SO_BROADCAST = 0
  5249. [2022-06-17 08:45:00.372186] TCP_NODELAY = 0
  5250. [2022-06-17 08:45:00.373720] TCP_KEEPCNT = 9
  5251. [2022-06-17 08:45:00.375195] TCP_KEEPIDLE = 120
  5252. [2022-06-17 08:45:00.376902] TCP_KEEPINTVL = 75
  5253. [2022-06-17 08:45:00.378517] IPTOS_LOWDELAY = 0
  5254. [2022-06-17 08:45:00.380015] IPTOS_THROUGHPUT = 0
  5255. [2022-06-17 08:45:00.381609] SO_REUSEPORT = 1
  5256. [2022-06-17 08:45:00.383291] SO_SNDBUF = 16384
  5257. [2022-06-17 08:45:00.384935] SO_RCVBUF = 131072
  5258. [2022-06-17 08:45:00.386554] SO_SNDLOWAT = 1
  5259. [2022-06-17 08:45:00.388176] SO_RCVLOWAT = 1
  5260. [2022-06-17 08:45:00.389793] SO_SNDTIMEO = 0
  5261. [2022-06-17 08:45:00.391408] SO_RCVTIMEO = 0
  5262. [2022-06-17 08:45:00.393183] TCP_QUICKACK = 1
  5263. [2022-06-17 08:45:00.394837] TCP_DEFER_ACCEPT = 0
  5264. [2022-06-17 08:45:00.396467] TCP_USER_TIMEOUT = 0
  5265. [2022-06-17 08:45:00.398090] Socket options:
  5266. [2022-06-17 08:45:00.399704] SO_KEEPALIVE = 1
  5267. [2022-06-17 08:45:00.401314] SO_REUSEADDR = 1
  5268. [2022-06-17 08:45:00.402960] SO_BROADCAST = 0
  5269. [2022-06-17 08:45:00.404590] TCP_NODELAY = 1
  5270. [2022-06-17 08:45:00.406214] TCP_KEEPCNT = 9
  5271. [2022-06-17 08:45:00.407847] TCP_KEEPIDLE = 120
  5272. [2022-06-17 08:45:00.409456] TCP_KEEPINTVL = 75
  5273. [2022-06-17 08:45:00.411060] IPTOS_LOWDELAY = 16
  5274. [2022-06-17 08:45:00.412671] IPTOS_THROUGHPUT = 16
  5275. [2022-06-17 08:45:00.414351] SO_REUSEPORT = 1
  5276. [2022-06-17 08:45:00.415958] SO_SNDBUF = 16384
  5277. [2022-06-17 08:45:00.417578] SO_RCVBUF = 131072
  5278. [2022-06-17 08:45:00.419195] SO_SNDLOWAT = 1
  5279. [2022-06-17 08:45:00.420830] SO_RCVLOWAT = 1
  5280. [2022-06-17 08:45:00.422449] SO_SNDTIMEO = 0
  5281. [2022-06-17 08:45:00.424161] SO_RCVTIMEO = 0
  5282. [2022-06-17 08:45:00.425779] TCP_QUICKACK = 1
  5283. [2022-06-17 08:45:00.427409] TCP_DEFER_ACCEPT = 0
  5284. [2022-06-17 08:45:00.429016] TCP_USER_TIMEOUT = 0
  5285. [2022-06-17 08:45:00.430704] bind succeeded on port 139
  5286. [2022-06-17 08:45:00.432348] Socket options:
  5287. [2022-06-17 08:45:00.434052] SO_KEEPALIVE = 1
  5288. [2022-06-17 08:45:00.435554] SO_REUSEADDR = 1
  5289. [2022-06-17 08:45:00.437243] SO_BROADCAST = 0
  5290. [2022-06-17 08:45:00.438737] TCP_NODELAY = 0
  5291. [2022-06-17 08:45:00.440486] TCP_KEEPCNT = 9
  5292. [2022-06-17 08:45:00.441988] TCP_KEEPIDLE = 120
  5293. [2022-06-17 08:45:00.443660] TCP_KEEPINTVL = 75
  5294. [2022-06-17 08:45:00.445303] IPTOS_LOWDELAY = 0
  5295. [2022-06-17 08:45:00.446920] IPTOS_THROUGHPUT = 0
  5296. [2022-06-17 08:45:00.448526] SO_REUSEPORT = 1
  5297. [2022-06-17 08:45:00.450143] SO_SNDBUF = 16384
  5298. [2022-06-17 08:45:00.451750] SO_RCVBUF = 131072
  5299. [2022-06-17 08:45:00.453298] SO_SNDLOWAT = 1
  5300. [2022-06-17 08:45:00.455014] SO_RCVLOWAT = 1
  5301. [2022-06-17 08:45:00.456640] SO_SNDTIMEO = 0
  5302. [2022-06-17 08:45:00.458260] SO_RCVTIMEO = 0
  5303. [2022-06-17 08:45:00.459881] TCP_QUICKACK = 1
  5304. [2022-06-17 08:45:00.461486] TCP_DEFER_ACCEPT = 0
  5305. [2022-06-17 08:45:00.463156] TCP_USER_TIMEOUT = 0
  5306. [2022-06-17 08:45:00.464799] Socket options:
  5307. [2022-06-17 08:45:00.466427] SO_KEEPALIVE = 1
  5308. [2022-06-17 08:45:00.468035] SO_REUSEADDR = 1
  5309. [2022-06-17 08:45:00.469648] SO_BROADCAST = 0
  5310. [2022-06-17 08:45:00.471249] TCP_NODELAY = 1
  5311. [2022-06-17 08:45:00.472899] TCP_KEEPCNT = 9
  5312. [2022-06-17 08:45:00.474524] TCP_KEEPIDLE = 120
  5313. [2022-06-17 08:45:00.476148] TCP_KEEPINTVL = 75
  5314. [2022-06-17 08:45:00.477779] IPTOS_LOWDELAY = 16
  5315. [2022-06-17 08:45:00.479414] IPTOS_THROUGHPUT = 16
  5316. [2022-06-17 08:45:00.481031] SO_REUSEPORT = 1
  5317. [2022-06-17 08:45:00.482640] SO_SNDBUF = 16384
  5318. [2022-06-17 08:45:00.484332] SO_RCVBUF = 131072
  5319. [2022-06-17 08:45:00.485954] SO_SNDLOWAT = 1
  5320. [2022-06-17 08:45:00.487566] SO_RCVLOWAT = 1
  5321. [2022-06-17 08:45:00.489197] SO_SNDTIMEO = 0
  5322. [2022-06-17 08:45:00.490822] SO_RCVTIMEO = 0
  5323. [2022-06-17 08:45:00.492461] TCP_QUICKACK = 1
  5324. [2022-06-17 08:45:00.494176] TCP_DEFER_ACCEPT = 0
  5325. [2022-06-17 08:45:00.495803] TCP_USER_TIMEOUT = 0
  5326. [2022-06-17 08:45:00.497432] bind succeeded on port 445
  5327. [2022-06-17 08:45:00.499052] Socket options:
  5328. [2022-06-17 08:45:00.500673] SO_KEEPALIVE = 1
  5329. [2022-06-17 08:45:00.502302] SO_REUSEADDR = 1
  5330. [2022-06-17 08:45:00.503999] SO_BROADCAST = 0
  5331. [2022-06-17 08:45:00.505630] TCP_NODELAY = 0
  5332. [2022-06-17 08:45:00.507351] TCP_KEEPCNT = 9
  5333. [2022-06-17 08:45:00.508980] TCP_KEEPIDLE = 120
  5334. [2022-06-17 08:45:00.510602] TCP_KEEPINTVL = 75
  5335. [2022-06-17 08:45:00.512232] IPTOS_LOWDELAY = 0
  5336. [2022-06-17 08:45:00.513884] IPTOS_THROUGHPUT = 0
  5337. [2022-06-17 08:45:00.515506] SO_REUSEPORT = 1
  5338. [2022-06-17 08:45:00.517135] SO_SNDBUF = 16384
  5339. [2022-06-17 08:45:00.518764] SO_RCVBUF = 131072
  5340. [2022-06-17 08:45:00.520380] SO_SNDLOWAT = 1
  5341. [2022-06-17 08:45:00.521994] SO_RCVLOWAT = 1
  5342. [2022-06-17 08:45:00.523659] SO_SNDTIMEO = 0
  5343. [2022-06-17 08:45:00.525297] SO_RCVTIMEO = 0
  5344. [2022-06-17 08:45:00.526926] TCP_QUICKACK = 1
  5345. [2022-06-17 08:45:00.533004] TCP_DEFER_ACCEPT = 0
  5346. [2022-06-17 08:45:00.534860] TCP_USER_TIMEOUT = 0
  5347. [2022-06-17 08:45:00.543528] Socket options:
  5348. [2022-06-17 08:45:00.545337] SO_KEEPALIVE = 1
  5349. [2022-06-17 08:45:00.547022] SO_REUSEADDR = 1
  5350. [2022-06-17 08:45:00.548659] SO_BROADCAST = 0
  5351. [2022-06-17 08:45:00.550286] TCP_NODELAY = 1
  5352. [2022-06-17 08:45:00.551911] TCP_KEEPCNT = 9
  5353. [2022-06-17 08:45:00.553590] TCP_KEEPIDLE = 120
  5354. [2022-06-17 08:45:00.557225] TCP_KEEPINTVL = 75
  5355. [2022-06-17 08:45:00.558988] IPTOS_LOWDELAY = 16
  5356. [2022-06-17 08:45:00.560651] IPTOS_THROUGHPUT = 16
  5357. [2022-06-17 08:45:00.562545] SO_REUSEPORT = 1
  5358. [2022-06-17 08:45:00.564170] SO_SNDBUF = 16384
  5359. [2022-06-17 08:45:00.565941] SO_RCVBUF = 131072
  5360. [2022-06-17 08:45:00.567578] SO_SNDLOWAT = 1
  5361. [2022-06-17 08:45:00.569169] SO_RCVLOWAT = 1
  5362. [2022-06-17 08:45:00.570778] SO_SNDTIMEO = 0
  5363. [2022-06-17 08:45:00.572270] SO_RCVTIMEO = 0
  5364. [2022-06-17 08:45:00.573794] TCP_QUICKACK = 1
  5365. [2022-06-17 08:45:00.575298] TCP_DEFER_ACCEPT = 0
  5366. [2022-06-17 08:45:00.576920] TCP_USER_TIMEOUT = 0
  5367. [2022-06-17 08:45:00.578564] bind succeeded on port 139
  5368. [2022-06-17 08:45:00.580184] Socket options:
  5369. [2022-06-17 08:45:00.581791] SO_KEEPALIVE = 1
  5370. [2022-06-17 08:45:00.583451] SO_REUSEADDR = 1
  5371. [2022-06-17 08:45:00.585080] SO_BROADCAST = 0
  5372. [2022-06-17 08:45:00.586690] TCP_NODELAY = 0
  5373. [2022-06-17 08:45:00.588310] TCP_KEEPCNT = 9
  5374. [2022-06-17 08:45:00.589922] TCP_KEEPIDLE = 120
  5375. [2022-06-17 08:45:00.591537] TCP_KEEPINTVL = 75
  5376. [2022-06-17 08:45:00.593198] IPTOS_LOWDELAY = 0
  5377. [2022-06-17 08:45:00.594835] IPTOS_THROUGHPUT = 0
  5378. [2022-06-17 08:45:00.596434] SO_REUSEPORT = 1
  5379. [2022-06-17 08:45:00.598045] SO_SNDBUF = 16384
  5380. [2022-06-17 08:45:00.599548] SO_RCVBUF = 131072
  5381. [2022-06-17 08:45:00.601028] SO_SNDLOWAT = 1
  5382. [2022-06-17 08:45:00.602492] SO_RCVLOWAT = 1
  5383. [2022-06-17 08:45:00.604032] SO_SNDTIMEO = 0
  5384. [2022-06-17 08:45:00.605497] SO_RCVTIMEO = 0
  5385. [2022-06-17 08:45:00.606961] TCP_QUICKACK = 1
  5386. [2022-06-17 08:45:00.608422] TCP_DEFER_ACCEPT = 0
  5387. [2022-06-17 08:45:00.610250] TCP_USER_TIMEOUT = 0
  5388. [2022-06-17 08:45:00.611889] Socket options:
  5389. [2022-06-17 08:45:00.613567] SO_KEEPALIVE = 1
  5390. [2022-06-17 08:45:00.615197] SO_REUSEADDR = 1
  5391. [2022-06-17 08:45:00.616824] SO_BROADCAST = 0
  5392. [2022-06-17 08:45:00.618430] TCP_NODELAY = 1
  5393. [2022-06-17 08:45:00.620049] TCP_KEEPCNT = 9
  5394. [2022-06-17 08:45:00.621653] TCP_KEEPIDLE = 120
  5395. [2022-06-17 08:45:00.623373] TCP_KEEPINTVL = 75
  5396. [2022-06-17 08:45:00.625017] IPTOS_LOWDELAY = 16
  5397. [2022-06-17 08:45:00.626637] IPTOS_THROUGHPUT = 16
  5398. [2022-06-17 08:45:00.628262] SO_REUSEPORT = 1
  5399. [2022-06-17 08:45:00.629863] SO_SNDBUF = 16384
  5400. [2022-06-17 08:45:00.631464] SO_RCVBUF = 131072
  5401. [2022-06-17 08:45:00.633120] SO_SNDLOWAT = 1
  5402. [2022-06-17 08:45:00.634751] SO_RCVLOWAT = 1
  5403. [2022-06-17 08:45:00.636384] SO_SNDTIMEO = 0
  5404. [2022-06-17 08:45:00.638006] SO_RCVTIMEO = 0
  5405. [2022-06-17 08:45:00.639607] TCP_QUICKACK = 1
  5406. [2022-06-17 08:45:00.641212] TCP_DEFER_ACCEPT = 0
  5407. [2022-06-17 08:45:00.642826] TCP_USER_TIMEOUT = 0
  5408. [2022-06-17 08:45:00.644494] Registering messaging pointer for type 13 - private_data=0
  5409. [2022-06-17 08:45:00.646145] Registering messaging pointer for type 33 - private_data=0xb5bd9ef0
  5410. [2022-06-17 08:45:00.647797] Registering messaging pointer for type 783 - private_data=0
  5411. [2022-06-17 08:45:00.649443] Registering messaging pointer for type 1 - private_data=0
  5412. [2022-06-17 08:45:00.651070] Overriding messaging pointer for type 1 - private_data=0
  5413. [2022-06-17 08:45:00.652708] Registering messaging pointer for type 770 - private_data=0
  5414. [2022-06-17 08:45:00.654417] Registering messaging pointer for type 801 - private_data=0
  5415. [2022-06-17 08:45:00.656076] Registering messaging pointer for type 790 - private_data=0
  5416. [2022-06-17 08:45:00.657709] Registering messaging pointer for type 791 - private_data=0
  5417. [2022-06-17 08:45:00.659356] Registering messaging pointer for type 15 - private_data=0
  5418. [2022-06-17 08:45:00.660997] Registering messaging pointer for type 16 - private_data=0
  5419. [2022-06-17 08:45:00.662640] Registering messaging pointer for type 799 - private_data=0
  5420. [2022-06-17 08:45:00.664360] avahi_client_callback: AVAHI_CLIENT_S_RUNNING
  5421. [2022-06-17 08:45:00.665998] avahi_entry_group_callback: AVAHI_ENTRY_GROUP_UNCOMMITED
  5422. [2022-06-17 08:45:00.667628] waiting for connections
  5423. [2022-06-17 08:45:00.669242] avahi_entry_group_callback: AVAHI_ENTRY_GROUP_REGISTERING
  5424. [2022-06-17 08:45:00.670892] messaging_recv_cb: Received message 0x31f len 0 (num_fds:0) from 9560
  5425. [2022-06-17 08:45:00.672543] messaging_dgm_send: Sending message to 9561
  5426. [2022-06-17 08:45:00.674256] messaging_recv_cb: Received message 0x31f len 0 (num_fds:0) from 9557
  5427. [2022-06-17 08:45:00.675902] messaging_dgm_send: Sending message to 9560
  5428. [2022-06-17 08:45:00.677401] messaging_recv_cb: Received message 0x31f len 0 (num_fds:0) from 9557
  5429. [2022-06-17 08:45:00.679027] avahi_entry_group_callback: AVAHI_ENTRY_GROUP_ESTABLISHED
  5430. [2022-06-17 08:45:05.038048] msg_dgm_ref_destructor: refs=0
  5431. [2022-06-17 08:45:05.041005] messaging_dgm_ref: messaging_dgm_init returned No error information
  5432. [2022-06-17 08:45:05.042806] messaging_dgm_ref: unique = 2241766024559059093
  5433. [2022-06-17 08:45:05.044913] Registered MSG_REQ_POOL_USAGE
  5434. [2022-06-17 08:45:05.047066] Attempting to find a passdb backend to match smbpasswd (smbpasswd)
  5435. [2022-06-17 08:45:05.053008] Found pdb backend smbpasswd
  5436. [2022-06-17 08:45:05.054843] pdb backend smbpasswd has a valid init
  5437. [2022-06-17 08:45:05.056433] smbXsrv_client_create: client_guid[00000000-0000-0000-0000-000000000000] created
  5438. [2022-06-17 08:45:05.058127] &client_blob: struct smbXsrv_clientB
  5439. [2022-06-17 08:45:05.059795] version : SMBXSRV_VERSION_0 (0)
  5440. [2022-06-17 08:45:05.073807] reserved : 0x00000000 (0)
  5441. [2022-06-17 08:45:05.075572] info : union smbXsrv_clientU(case 0)
  5442. [2022-06-17 08:45:05.077281] info0 : *
  5443. [2022-06-17 08:45:05.078938] info0: struct smbXsrv_client
  5444. [2022-06-17 08:45:05.080683] table : *
  5445. [2022-06-17 08:45:05.082215] raw_ev_ctx : *
  5446. [2022-06-17 08:45:05.083973] msg_ctx : *
  5447. [2022-06-17 08:45:05.085634] global : *
  5448. [2022-06-17 08:45:05.087383] global: struct smbXsrv_client_global0
  5449. [2022-06-17 08:45:05.089013] db_rec : NULL
  5450. [2022-06-17 08:45:05.090534] server_id: struct server_id
  5451. [2022-06-17 08:45:05.092171] pid : 0x0000000000002574 (9588)
  5452. [2022-06-17 08:45:05.095824] task_id : 0x00000000 (0)
  5453. [2022-06-17 08:45:05.097763] vnn : 0xffffffff (4294967295)
  5454. [2022-06-17 08:45:05.103704] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  5455. [2022-06-17 08:45:05.105396] local_address : NULL
  5456. [2022-06-17 08:45:05.107083] remote_address : NULL
  5457. [2022-06-17 08:45:05.108742] remote_name : NULL
  5458. [2022-06-17 08:45:05.123703] initial_connect_time : Fri Jun 17 08:45:05 2022 UTC
  5459. [2022-06-17 08:45:05.125401] client_guid : 00000000-0000-0000-0000-000000000000
  5460. [2022-06-17 08:45:05.126956] stored : 0x00 (0)
  5461. [2022-06-17 08:45:05.128474] sconn : NULL
  5462. [2022-06-17 08:45:05.129988] session_table : NULL
  5463. [2022-06-17 08:45:05.131492] tcon_table : NULL
  5464. [2022-06-17 08:45:05.132784] open_table : NULL
  5465. [2022-06-17 08:45:05.134098] connections : NULL
  5466. [2022-06-17 08:45:05.135342] server_multi_channel_enabled: 0x00 (0)
  5467. [2022-06-17 08:45:05.136574] next_channel_id : 0x0000000000000000 (0)
  5468. [2022-06-17 08:45:05.137821] connection_pass_subreq : NULL
  5469. [2022-06-17 08:45:05.139056] pending_breaks : NULL
  5470. [2022-06-17 08:45:05.140277] Socket options:
  5471. [2022-06-17 08:45:05.142033] SO_KEEPALIVE = 1
  5472. [2022-06-17 08:45:05.143697] SO_REUSEADDR = 1
  5473. [2022-06-17 08:45:05.153508] SO_BROADCAST = 0
  5474. [2022-06-17 08:45:05.155271] TCP_NODELAY = 1
  5475. [2022-06-17 08:45:05.157120] TCP_KEEPCNT = 9
  5476. [2022-06-17 08:45:05.158802] TCP_KEEPIDLE = 120
  5477. [2022-06-17 08:45:05.160451] TCP_KEEPINTVL = 75
  5478. [2022-06-17 08:45:05.162083] IPTOS_LOWDELAY = 16
  5479. [2022-06-17 08:45:05.163866] IPTOS_THROUGHPUT = 16
  5480. [2022-06-17 08:45:05.165544] SO_REUSEPORT = 1
  5481. [2022-06-17 08:45:05.173516] SO_SNDBUF = 44800
  5482. [2022-06-17 08:45:05.175216] SO_RCVBUF = 131072
  5483. [2022-06-17 08:45:05.176897] SO_SNDLOWAT = 1
  5484. [2022-06-17 08:45:05.178530] SO_RCVLOWAT = 1
  5485. [2022-06-17 08:45:05.180161] SO_SNDTIMEO = 0
  5486. [2022-06-17 08:45:05.181786] SO_RCVTIMEO = 0
  5487. [2022-06-17 08:45:05.183453] TCP_QUICKACK = 1
  5488. [2022-06-17 08:45:05.187361] TCP_DEFER_ACCEPT = 0
  5489. [2022-06-17 08:45:05.189302] TCP_USER_TIMEOUT = 0
  5490. [2022-06-17 08:45:05.203530] Socket options:
  5491. [2022-06-17 08:45:05.205284] SO_KEEPALIVE = 1
  5492. [2022-06-17 08:45:05.206960] SO_REUSEADDR = 1
  5493. [2022-06-17 08:45:05.208595] SO_BROADCAST = 0
  5494. [2022-06-17 08:45:05.210200] TCP_NODELAY = 1
  5495. [2022-06-17 08:45:05.211835] TCP_KEEPCNT = 9
  5496. [2022-06-17 08:45:05.213508] TCP_KEEPIDLE = 120
  5497. [2022-06-17 08:45:05.215152] TCP_KEEPINTVL = 75
  5498. [2022-06-17 08:45:05.216788] IPTOS_LOWDELAY = 16
  5499. [2022-06-17 08:45:05.218414] IPTOS_THROUGHPUT = 16
  5500. [2022-06-17 08:45:05.220040] SO_REUSEPORT = 1
  5501. [2022-06-17 08:45:05.221651] SO_SNDBUF = 44800
  5502. [2022-06-17 08:45:05.223328] SO_RCVBUF = 131072
  5503. [2022-06-17 08:45:05.224962] SO_SNDLOWAT = 1
  5504. [2022-06-17 08:45:05.233469] SO_RCVLOWAT = 1
  5505. [2022-06-17 08:45:05.235028] SO_SNDTIMEO = 0
  5506. [2022-06-17 08:45:05.236530] SO_RCVTIMEO = 0
  5507. [2022-06-17 08:45:05.238026] TCP_QUICKACK = 1
  5508. [2022-06-17 08:45:05.239498] TCP_DEFER_ACCEPT = 0
  5509. [2022-06-17 08:45:05.240969] TCP_USER_TIMEOUT = 0
  5510. [2022-06-17 08:45:05.242444] Allowed connection from 192.168.1.10 (192.168.1.10)
  5511. [2022-06-17 08:45:05.244035] Connection allowed from ipv4:192.168.1.10:33730 to ipv4:192.168.1.250:445
  5512. [2022-06-17 08:45:05.253566] INFO: Current debug levels:
  5513. [2022-06-17 08:45:05.255176] all: 10
  5514. [2022-06-17 08:45:05.256688] tdb: 10
  5515. [2022-06-17 08:45:05.258163] printdrivers: 10
  5516. [2022-06-17 08:45:05.259629] lanman: 10
  5517. [2022-06-17 08:45:05.261094] smb: 10
  5518. [2022-06-17 08:45:05.262726] rpc_parse: 10
  5519. [2022-06-17 08:45:05.264452] rpc_srv: 10
  5520. [2022-06-17 08:45:05.265955] rpc_cli: 10
  5521. [2022-06-17 08:45:05.273708] passdb: 10
  5522. [2022-06-17 08:45:05.275423] sam: 10
  5523. [2022-06-17 08:45:05.277052] auth: 10
  5524. [2022-06-17 08:45:05.278672] winbind: 10
  5525. [2022-06-17 08:45:05.280296] vfs: 10
  5526. [2022-06-17 08:45:05.281915] idmap: 10
  5527. [2022-06-17 08:45:05.283604] quota: 10
  5528. [2022-06-17 08:45:05.293566] acls: 10
  5529. [2022-06-17 08:45:05.295352] locking: 10
  5530. [2022-06-17 08:45:05.297012] msdfs: 10
  5531. [2022-06-17 08:45:05.298645] dmapi: 10
  5532. [2022-06-17 08:45:05.300267] registry: 10
  5533. [2022-06-17 08:45:05.301888] scavenger: 10
  5534. [2022-06-17 08:45:05.303580] dns: 10
  5535. [2022-06-17 08:45:05.305204] ldb: 10
  5536. [2022-06-17 08:45:05.306832] tevent: 10
  5537. [2022-06-17 08:45:05.313617] auth_audit: 10
  5538. [2022-06-17 08:45:05.315411] auth_json_audit: 10
  5539. [2022-06-17 08:45:05.317079] kerberos: 10
  5540. [2022-06-17 08:45:05.318696] drs_repl: 10
  5541. [2022-06-17 08:45:05.320326] smb2: 10
  5542. [2022-06-17 08:45:05.333622] smb2_credits: 10
  5543. [2022-06-17 08:45:05.335473] dsdb_audit: 10
  5544. [2022-06-17 08:45:05.337162] dsdb_json_audit: 10
  5545. [2022-06-17 08:45:05.338806] dsdb_password_audit: 10
  5546. [2022-06-17 08:45:05.340433] dsdb_password_json_audit: 10
  5547. [2022-06-17 08:45:05.342071] dsdb_transaction_audit: 10
  5548. [2022-06-17 08:45:05.343777] dsdb_transaction_json_audit: 10
  5549. [2022-06-17 08:45:05.345321] dsdb_group_audit: 10
  5550. [2022-06-17 08:45:05.346805] dsdb_group_json_audit: 10
  5551. [2022-06-17 08:45:05.348285] lp_file_list_changed()
  5552. [2022-06-17 08:45:05.350051] file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Fri Jun 17 08:38:04 2022
  5553. [2022-06-17 08:45:05.351721]
  5554. [2022-06-17 08:45:05.357297] init_oplocks: initializing messages.
  5555. [2022-06-17 08:45:05.359145] Registering messaging pointer for type 774 - private_data=0xb5829e80
  5556. [2022-06-17 08:45:05.360866] Registering messaging pointer for type 778 - private_data=0xb5829e80
  5557. [2022-06-17 08:45:05.362544] Registering messaging pointer for type 770 - private_data=0xb5829e80
  5558. [2022-06-17 08:45:05.364288] Registering messaging pointer for type 801 - private_data=0xb5829e80
  5559. [2022-06-17 08:45:05.365952] Registering messaging pointer for type 787 - private_data=0xb5829e80
  5560. [2022-06-17 08:45:05.367595] Registering messaging pointer for type 779 - private_data=0xb5829e80
  5561. [2022-06-17 08:45:05.369240] Registering messaging pointer for type 15 - private_data=0
  5562. [2022-06-17 08:45:05.370888] Overriding messaging pointer for type 15 - private_data=0
  5563. [2022-06-17 08:45:05.372530] Deregistering messaging pointer for type 16 - private_data=0
  5564. [2022-06-17 08:45:05.374273] Registering messaging pointer for type 16 - private_data=0xb5829e80
  5565. [2022-06-17 08:45:05.375924] Deregistering messaging pointer for type 33 - private_data=0xb5bd9ef0
  5566. [2022-06-17 08:45:05.377447] Registering messaging pointer for type 33 - private_data=0xb5829e80
  5567. [2022-06-17 08:45:05.379181] Deregistering messaging pointer for type 790 - private_data=0
  5568. [2022-06-17 08:45:05.380844] Registering messaging pointer for type 790 - private_data=0xb5829e80
  5569. [2022-06-17 08:45:05.382497] Deregistering messaging pointer for type 791 - private_data=0
  5570. [2022-06-17 08:45:05.384230] Deregistering messaging pointer for type 1 - private_data=0
  5571. [2022-06-17 08:45:05.385894] Registering messaging pointer for type 1 - private_data=0
  5572. [2022-06-17 08:45:05.387533] event_add_idle: idle_evt(keepalive) 0xb62c0c70
  5573. [2022-06-17 08:45:05.389183] event_add_idle: idle_evt(deadtime) 0xb62c0ce0
  5574. [2022-06-17 08:45:05.390818] event_add_idle: idle_evt(housekeeping) 0xb62c0d50
  5575. [2022-06-17 08:45:05.392449] got smb length of 166
  5576. [2022-06-17 08:45:05.394027] got message type 0x0 of len 0xa6
  5577. [2022-06-17 08:45:05.395792] Transaction 0 of length 170 (0 toread)
  5578. [2022-06-17 08:45:05.397437] smbd_smb2_first_negprot: packet length 166
  5579. [2022-06-17 08:45:05.399101] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 0 (position 0) from bitmap
  5580. [2022-06-17 08:45:05.400772] smbd_smb2_request_dispatch: opcode[SMB2_OP_NEGPROT] mid = 0
  5581. [2022-06-17 08:45:05.402412] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  5582. [2022-06-17 08:45:05.404136] Security token: (NULL)
  5583. [2022-06-17 08:45:05.405758] UNIX token of user 0
  5584. [2022-06-17 08:45:05.407374] Primary group is 0 and contains 0 supplementary groups
  5585. [2022-06-17 08:45:05.409007] change_to_root_user: now uid=(0,0) gid=(0,0)
  5586. [2022-06-17 08:45:05.410650] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  5587. [2022-06-17 08:45:05.412295] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  5588. [2022-06-17 08:45:05.414027] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  5589. [2022-06-17 08:45:05.415680] Security token: (NULL)
  5590. [2022-06-17 08:45:05.417301] UNIX token of user 0
  5591. [2022-06-17 08:45:05.418911] Primary group is 0 and contains 0 supplementary groups
  5592. [2022-06-17 08:45:05.420551] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  5593. [2022-06-17 08:45:05.422187] set_remote_arch: Client arch is 'Vista'
  5594. [2022-06-17 08:45:05.423860] INFO: Current debug levels:
  5595. [2022-06-17 08:45:05.425492] all: 10
  5596. [2022-06-17 08:45:05.426973] tdb: 10
  5597. [2022-06-17 08:45:05.428579] printdrivers: 10
  5598. [2022-06-17 08:45:05.430193] lanman: 10
  5599. [2022-06-17 08:45:05.431815] smb: 10
  5600. [2022-06-17 08:45:05.433484] rpc_parse: 10
  5601. [2022-06-17 08:45:05.435117] rpc_srv: 10
  5602. [2022-06-17 08:45:05.436726] rpc_cli: 10
  5603. [2022-06-17 08:45:05.438329] passdb: 10
  5604. [2022-06-17 08:45:05.439944] sam: 10
  5605. [2022-06-17 08:45:05.441544] auth: 10
  5606. [2022-06-17 08:45:05.443195] winbind: 10
  5607. [2022-06-17 08:45:05.444824] vfs: 10
  5608. [2022-06-17 08:45:05.446318] idmap: 10
  5609. [2022-06-17 08:45:05.447796] quota: 10
  5610. [2022-06-17 08:45:05.449268] acls: 10
  5611. [2022-06-17 08:45:05.450729] locking: 10
  5612. [2022-06-17 08:45:05.452197] msdfs: 10
  5613. [2022-06-17 08:45:05.453700] dmapi: 10
  5614. [2022-06-17 08:45:05.455176] registry: 10
  5615. [2022-06-17 08:45:05.456665] scavenger: 10
  5616. [2022-06-17 08:45:05.458138] dns: 10
  5617. [2022-06-17 08:45:05.459599] ldb: 10
  5618. [2022-06-17 08:45:05.462056] tevent: 10
  5619. [2022-06-17 08:45:05.463768] auth_audit: 10
  5620. [2022-06-17 08:45:05.465401] auth_json_audit: 10
  5621. [2022-06-17 08:45:05.467022] kerberos: 10
  5622. [2022-06-17 08:45:05.468647] drs_repl: 10
  5623. [2022-06-17 08:45:05.470275] smb2: 10
  5624. [2022-06-17 08:45:05.471884] smb2_credits: 10
  5625. [2022-06-17 08:45:05.473551] dsdb_audit: 10
  5626. [2022-06-17 08:45:05.475185] dsdb_json_audit: 10
  5627. [2022-06-17 08:45:05.476805] dsdb_password_audit: 10
  5628. [2022-06-17 08:45:05.478422] dsdb_password_json_audit: 10
  5629. [2022-06-17 08:45:05.480056] dsdb_transaction_audit: 10
  5630. [2022-06-17 08:45:05.481692] dsdb_transaction_json_audit: 10
  5631. [2022-06-17 08:45:05.483375] dsdb_group_audit: 10
  5632. [2022-06-17 08:45:05.485006] dsdb_group_json_audit: 10
  5633. [2022-06-17 08:45:05.486623] lp_file_list_changed()
  5634. [2022-06-17 08:45:05.488233] file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Fri Jun 17 08:38:04 2022
  5635. [2022-06-17 08:45:05.489898]
  5636. [2022-06-17 08:45:05.491508] Selected protocol SMB3_11
  5637. [2022-06-17 08:45:05.493183] make_auth3_context_for_ntlm: Making default auth method list for server role = 'standalone server', encrypt passwords = yes
  5638. [2022-06-17 08:45:05.494885] Attempting to register auth backend anonymous
  5639. [2022-06-17 08:45:05.496533] Successfully added auth method 'anonymous'
  5640. [2022-06-17 08:45:05.498159] Attempting to register auth backend sam
  5641. [2022-06-17 08:45:05.499781] Successfully added auth method 'sam'
  5642. [2022-06-17 08:45:05.501405] Attempting to register auth backend sam_ignoredomain
  5643. [2022-06-17 08:45:05.503114] Successfully added auth method 'sam_ignoredomain'
  5644. [2022-06-17 08:45:05.504787] Attempting to register auth backend sam_netlogon3
  5645. [2022-06-17 08:45:05.506447] Successfully added auth method 'sam_netlogon3'
  5646. [2022-06-17 08:45:05.508090] Attempting to register auth backend unix
  5647. [2022-06-17 08:45:05.509726] Successfully added auth method 'unix'
  5648. [2022-06-17 08:45:05.511364] load_auth_module: Attempting to find an auth method to match anonymous
  5649. [2022-06-17 08:45:05.513055] load_auth_module: auth method anonymous has a valid init
  5650. [2022-06-17 08:45:05.514711] load_auth_module: Attempting to find an auth method to match sam_ignoredomain
  5651. [2022-06-17 08:45:05.516372] load_auth_module: auth method sam_ignoredomain has a valid init
  5652. [2022-06-17 08:45:05.518048] GENSEC backend 'gssapi_spnego' registered
  5653. [2022-06-17 08:45:05.519692] GENSEC backend 'gssapi_krb5' registered
  5654. [2022-06-17 08:45:05.521336] GENSEC backend 'gssapi_krb5_sasl' registered
  5655. [2022-06-17 08:45:05.523025] GENSEC backend 'spnego' registered
  5656. [2022-06-17 08:45:05.524676] GENSEC backend 'schannel' registered
  5657. [2022-06-17 08:45:05.526313] GENSEC backend 'naclrpc_as_system' registered
  5658. [2022-06-17 08:45:05.527950] GENSEC backend 'sasl-EXTERNAL' registered
  5659. [2022-06-17 08:45:05.529601] GENSEC backend 'ntlmssp' registered
  5660. [2022-06-17 08:45:05.531238] GENSEC backend 'ntlmssp_resume_ccache' registered
  5661. [2022-06-17 08:45:05.532911] GENSEC backend 'http_basic' registered
  5662. [2022-06-17 08:45:05.534546] GENSEC backend 'http_ntlm' registered
  5663. [2022-06-17 08:45:05.536177] GENSEC backend 'http_negotiate' registered
  5664. [2022-06-17 08:45:05.537688] Starting GENSEC mechanism spnego
  5665. [2022-06-17 08:45:05.539403] Starting GENSEC submechanism ntlmssp
  5666. [2022-06-17 08:45:05.541043] gensec_update_send: spnego[0xb5161e70]: subreq: 0xb68523a0
  5667. [2022-06-17 08:45:05.542680] gensec_update_done: spnego[0xb5161e70]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0xb68523a0/../../auth/gensec/spnego.c:1632]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0xb6852480)] timer[0] finish[../../auth/gensec/spnego.c:2116]
  5668. [2022-06-17 08:45:05.544502] smbd_smb2_request_done_ex: mid [0] idx[1] status[NT_STATUS_OK] body[64] dyn[yes:140] at ../../source3/smbd/smb2_negprot.c:667
  5669. [2022-06-17 08:45:05.546202] smb2_set_operation_credit: smb2_set_operation_credit: requested 31, charge 1, granted 1, current possible/max 8192/8192, total granted/max/low/range 1/8192/1/1
  5670. [2022-06-17 08:45:05.547917] smbd_smb2_request idx[1] of 5 vectors
  5671. [2022-06-17 08:45:05.549555] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 1 (position 1) from bitmap
  5672. [2022-06-17 08:45:05.551225] smbd_smb2_request_dispatch: opcode[SMB2_OP_SESSSETUP] mid = 1
  5673. [2022-06-17 08:45:05.552911] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  5674. [2022-06-17 08:45:05.554577] Security token: (NULL)
  5675. [2022-06-17 08:45:05.556201] UNIX token of user 0
  5676. [2022-06-17 08:45:05.557819] Primary group is 0 and contains 0 supplementary groups
  5677. [2022-06-17 08:45:05.559463] change_to_root_user: now uid=(0,0) gid=(0,0)
  5678. [2022-06-17 08:45:05.561095] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  5679. [2022-06-17 08:45:05.562847] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  5680. [2022-06-17 08:45:05.564571] db_tdb_log_key: Locking key 6F1A4B46
  5681. [2022-06-17 08:45:05.566235] db_tdb_fetch_locked_internal: Allocated locked data 0xb5bd9e70
  5682. [2022-06-17 08:45:05.567883] dbwrap_watched_subrec_wakeup_fn: No watchers
  5683. [2022-06-17 08:45:05.569521] smbXsrv_session_global_store: key '6F1A4B46' stored
  5684. [2022-06-17 08:45:05.571158] &global_blob: struct smbXsrv_session_globalB
  5685. [2022-06-17 08:45:05.572798] version : SMBXSRV_VERSION_0 (0)
  5686. [2022-06-17 08:45:05.574506] seqnum : 0x00000001 (1)
  5687. [2022-06-17 08:45:05.576161] info : union smbXsrv_session_globalU(case 0)
  5688. [2022-06-17 08:45:05.577693] info0 : *
  5689. [2022-06-17 08:45:05.579380] info0: struct smbXsrv_session_global0
  5690. [2022-06-17 08:45:05.581028] db_rec : *
  5691. [2022-06-17 08:45:05.582662] session_global_id : 0x6f1a4b46 (1863994182)
  5692. [2022-06-17 08:45:05.584389] session_wire_id : 0x000000006f1a4b46 (1863994182)
  5693. [2022-06-17 08:45:05.586049] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5694. [2022-06-17 08:45:05.587709] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  5695. [2022-06-17 08:45:05.589374] auth_time : NTTIME(0)
  5696. [2022-06-17 08:45:05.591019] auth_session_info_seqnum : 0x00000000 (0)
  5697. [2022-06-17 08:45:05.592678] auth_session_info : NULL
  5698. [2022-06-17 08:45:05.594247] connection_dialect : 0x0311 (785)
  5699. [2022-06-17 08:45:05.595758] signing_flags : 0x00 (0)
  5700. [2022-06-17 08:45:05.597516] 0: SMBXSRV_SIGNING_REQUIRED
  5701. [2022-06-17 08:45:05.599172] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  5702. [2022-06-17 08:45:05.600808] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  5703. [2022-06-17 08:45:05.612806] encryption_flags : 0x00 (0)
  5704. [2022-06-17 08:45:05.614822] 0: SMBXSRV_ENCRYPTION_REQUIRED
  5705. [2022-06-17 08:45:05.616422] 0: SMBXSRV_ENCRYPTION_DESIRED
  5706. [2022-06-17 08:45:05.617951] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  5707. [2022-06-17 08:45:05.619467] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  5708. [2022-06-17 08:45:05.620970] signing_key : NULL
  5709. [2022-06-17 08:45:05.622460] encryption_key : NULL
  5710. [2022-06-17 08:45:05.624057] decryption_key : NULL
  5711. [2022-06-17 08:45:05.625570] num_channels : 0x00000001 (1)
  5712. [2022-06-17 08:45:05.627374] channels: ARRAY(1)
  5713. [2022-06-17 08:45:05.629018] channels: struct smbXsrv_channel_global0
  5714. [2022-06-17 08:45:05.630683] server_id: struct server_id
  5715. [2022-06-17 08:45:05.632326] pid : 0x0000000000002574 (9588)
  5716. [2022-06-17 08:45:05.634053] task_id : 0x00000000 (0)
  5717. [2022-06-17 08:45:05.635727] vnn : 0xffffffff (4294967295)
  5718. [2022-06-17 08:45:05.637402] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  5719. [2022-06-17 08:45:05.639079] channel_id : 0x0000000000000000 (0)
  5720. [2022-06-17 08:45:05.640720] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5721. [2022-06-17 08:45:05.642369] local_address : 'ipv4:192.168.1.250:445'
  5722. [2022-06-17 08:45:05.644106] remote_address : 'ipv4:192.168.1.10:33730'
  5723. [2022-06-17 08:45:05.645773] remote_name : '192.168.1.10'
  5724. [2022-06-17 08:45:05.647308] signing_key : NULL
  5725. [2022-06-17 08:45:05.649070] auth_session_info_seqnum : 0x00000000 (0)
  5726. [2022-06-17 08:45:05.650719] connection : *
  5727. [2022-06-17 08:45:05.652238] encryption_cipher : 0x0000 (0)
  5728. [2022-06-17 08:45:05.654091] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  5729. [2022-06-17 08:45:05.655735] db_tdb_log_key: Unlocking key 6F1A4B46
  5730. [2022-06-17 08:45:05.657369] smbXsrv_session_create: global_id (0x6f1a4b46) stored
  5731. [2022-06-17 08:45:05.659001] &session_blob: struct smbXsrv_sessionB
  5732. [2022-06-17 08:45:05.660616] version : SMBXSRV_VERSION_0 (0)
  5733. [2022-06-17 08:45:05.662157] reserved : 0x00000000 (0)
  5734. [2022-06-17 08:45:05.663720] info : union smbXsrv_sessionU(case 0)
  5735. [2022-06-17 08:45:05.665242] info0 : *
  5736. [2022-06-17 08:45:05.666725] info0: struct smbXsrv_session
  5737. [2022-06-17 08:45:05.668202] table : *
  5738. [2022-06-17 08:45:05.669690] db_rec : NULL
  5739. [2022-06-17 08:45:05.671194] client : *
  5740. [2022-06-17 08:45:05.672685] local_id : 0x6f1a4b46 (1863994182)
  5741. [2022-06-17 08:45:05.674245] global : *
  5742. [2022-06-17 08:45:05.675755] global: struct smbXsrv_session_global0
  5743. [2022-06-17 08:45:05.677475] db_rec : NULL
  5744. [2022-06-17 08:45:05.678994] session_global_id : 0x6f1a4b46 (1863994182)
  5745. [2022-06-17 08:45:05.680513] session_wire_id : 0x000000006f1a4b46 (1863994182)
  5746. [2022-06-17 08:45:05.682028] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5747. [2022-06-17 08:45:05.683603] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  5748. [2022-06-17 08:45:05.685120] auth_time : NTTIME(0)
  5749. [2022-06-17 08:45:05.686631] auth_session_info_seqnum : 0x00000000 (0)
  5750. [2022-06-17 08:45:05.688221] auth_session_info : NULL
  5751. [2022-06-17 08:45:05.689746] connection_dialect : 0x0311 (785)
  5752. [2022-06-17 08:45:05.691402] signing_flags : 0x00 (0)
  5753. [2022-06-17 08:45:05.692986] 0: SMBXSRV_SIGNING_REQUIRED
  5754. [2022-06-17 08:45:05.694522] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  5755. [2022-06-17 08:45:05.696044] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  5756. [2022-06-17 08:45:05.697543] encryption_flags : 0x00 (0)
  5757. [2022-06-17 08:45:05.699040] 0: SMBXSRV_ENCRYPTION_REQUIRED
  5758. [2022-06-17 08:45:05.700538] 0: SMBXSRV_ENCRYPTION_DESIRED
  5759. [2022-06-17 08:45:05.702665] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  5760. [2022-06-17 08:45:05.704389] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  5761. [2022-06-17 08:45:05.706062] signing_key : NULL
  5762. [2022-06-17 08:45:05.707721] encryption_key : NULL
  5763. [2022-06-17 08:45:05.709369] decryption_key : NULL
  5764. [2022-06-17 08:45:05.711005] num_channels : 0x00000001 (1)
  5765. [2022-06-17 08:45:05.712651] channels: ARRAY(1)
  5766. [2022-06-17 08:45:05.714360] channels: struct smbXsrv_channel_global0
  5767. [2022-06-17 08:45:05.716014] server_id: struct server_id
  5768. [2022-06-17 08:45:05.717646] pid : 0x0000000000002574 (9588)
  5769. [2022-06-17 08:45:05.719311] task_id : 0x00000000 (0)
  5770. [2022-06-17 08:45:05.720970] vnn : 0xffffffff (4294967295)
  5771. [2022-06-17 08:45:05.722631] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  5772. [2022-06-17 08:45:05.724381] channel_id : 0x0000000000000000 (0)
  5773. [2022-06-17 08:45:05.726041] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5774. [2022-06-17 08:45:05.727691] local_address : 'ipv4:192.168.1.250:445'
  5775. [2022-06-17 08:45:05.729343] remote_address : 'ipv4:192.168.1.10:33730'
  5776. [2022-06-17 08:45:05.731005] remote_name : '192.168.1.10'
  5777. [2022-06-17 08:45:05.732668] signing_key : NULL
  5778. [2022-06-17 08:45:05.734378] auth_session_info_seqnum : 0x00000000 (0)
  5779. [2022-06-17 08:45:05.736044] connection : *
  5780. [2022-06-17 08:45:05.737692] encryption_cipher : 0x0000 (0)
  5781. [2022-06-17 08:45:05.739355] status : NT_STATUS_MORE_PROCESSING_REQUIRED
  5782. [2022-06-17 08:45:05.741008] idle_time : Fri Jun 17 08:45:05 2022 UTC
  5783. [2022-06-17 08:45:05.742653] nonce_high_random : 0x0000000000000000 (0)
  5784. [2022-06-17 08:45:05.744376] nonce_high_max : 0x0000000000000000 (0)
  5785. [2022-06-17 08:45:05.746042] nonce_high : 0x0000000000000000 (0)
  5786. [2022-06-17 08:45:05.747688] nonce_low : 0x0000000000000000 (0)
  5787. [2022-06-17 08:45:05.749347] tcon_table : *
  5788. [2022-06-17 08:45:05.750972] homes_snum : 0xffffffff (4294967295)
  5789. [2022-06-17 08:45:05.752622] pending_auth : NULL
  5790. [2022-06-17 08:45:05.754333] make_auth3_context_for_ntlm: Making default auth method list for server role = 'standalone server', encrypt passwords = yes
  5791. [2022-06-17 08:45:05.756019] load_auth_module: Attempting to find an auth method to match anonymous
  5792. [2022-06-17 08:45:05.757660] load_auth_module: auth method anonymous has a valid init
  5793. [2022-06-17 08:45:05.759310] load_auth_module: Attempting to find an auth method to match sam_ignoredomain
  5794. [2022-06-17 08:45:05.760957] load_auth_module: auth method sam_ignoredomain has a valid init
  5795. [2022-06-17 08:45:05.762600] Starting GENSEC mechanism spnego
  5796. [2022-06-17 08:45:05.764319] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  5797. [2022-06-17 08:45:05.765981] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  5798. [2022-06-17 08:45:05.767641] db_tdb_log_key: Locking key 6F1A4B46
  5799. [2022-06-17 08:45:05.769279] db_tdb_fetch_locked_internal: Allocated locked data 0xb5896c70
  5800. [2022-06-17 08:45:05.770926] dbwrap_watched_subrec_wakeup_fn: No watchers
  5801. [2022-06-17 08:45:05.772567] smbXsrv_session_global_store: key '6F1A4B46' stored
  5802. [2022-06-17 08:45:05.774267] &global_blob: struct smbXsrv_session_globalB
  5803. [2022-06-17 08:45:05.775910] version : SMBXSRV_VERSION_0 (0)
  5804. [2022-06-17 08:45:05.777557] seqnum : 0x00000002 (2)
  5805. [2022-06-17 08:45:05.779203] info : union smbXsrv_session_globalU(case 0)
  5806. [2022-06-17 08:45:05.780858] info0 : *
  5807. [2022-06-17 08:45:05.782493] info0: struct smbXsrv_session_global0
  5808. [2022-06-17 08:45:05.784244] db_rec : *
  5809. [2022-06-17 08:45:05.785884] session_global_id : 0x6f1a4b46 (1863994182)
  5810. [2022-06-17 08:45:05.787531] session_wire_id : 0x000000006f1a4b46 (1863994182)
  5811. [2022-06-17 08:45:05.789180] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5812. [2022-06-17 08:45:05.790817] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  5813. [2022-06-17 08:45:05.792488] auth_time : NTTIME(0)
  5814. [2022-06-17 08:45:05.794081] auth_session_info_seqnum : 0x00000000 (0)
  5815. [2022-06-17 08:45:05.795581] auth_session_info : NULL
  5816. [2022-06-17 08:45:05.797358] connection_dialect : 0x0311 (785)
  5817. [2022-06-17 08:45:05.799013] signing_flags : 0x00 (0)
  5818. [2022-06-17 08:45:05.800647] 0: SMBXSRV_SIGNING_REQUIRED
  5819. [2022-06-17 08:45:05.802287] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  5820. [2022-06-17 08:45:05.803998] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  5821. [2022-06-17 08:45:05.805648] encryption_flags : 0x00 (0)
  5822. [2022-06-17 08:45:05.807307] 0: SMBXSRV_ENCRYPTION_REQUIRED
  5823. [2022-06-17 08:45:05.808951] 0: SMBXSRV_ENCRYPTION_DESIRED
  5824. [2022-06-17 08:45:05.810462] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  5825. [2022-06-17 08:45:05.812202] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  5826. [2022-06-17 08:45:05.813886] signing_key : NULL
  5827. [2022-06-17 08:45:05.815542] encryption_key : NULL
  5828. [2022-06-17 08:45:05.817195] decryption_key : NULL
  5829. [2022-06-17 08:45:05.818834] num_channels : 0x00000001 (1)
  5830. [2022-06-17 08:45:05.820462] channels: ARRAY(1)
  5831. [2022-06-17 08:45:05.822110] channels: struct smbXsrv_channel_global0
  5832. [2022-06-17 08:45:05.823842] server_id: struct server_id
  5833. [2022-06-17 08:45:05.825496] pid : 0x0000000000002574 (9588)
  5834. [2022-06-17 08:45:05.833028] task_id : 0x00000000 (0)
  5835. [2022-06-17 08:45:05.834896] vnn : 0xffffffff (4294967295)
  5836. [2022-06-17 08:45:05.836639] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  5837. [2022-06-17 08:45:05.843622] channel_id : 0x0000000000000000 (0)
  5838. [2022-06-17 08:45:05.845430] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5839. [2022-06-17 08:45:05.847141] local_address : 'ipv4:192.168.1.250:445'
  5840. [2022-06-17 08:45:05.848819] remote_address : 'ipv4:192.168.1.10:33730'
  5841. [2022-06-17 08:45:05.850493] remote_name : '192.168.1.10'
  5842. [2022-06-17 08:45:05.852149] signing_key : NULL
  5843. [2022-06-17 08:45:05.855278] auth_session_info_seqnum : 0x00000000 (0)
  5844. [2022-06-17 08:45:05.857031] connection : *
  5845. [2022-06-17 08:45:05.858701] encryption_cipher : 0x0000 (0)
  5846. [2022-06-17 08:45:05.860366] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  5847. [2022-06-17 08:45:05.862034] db_tdb_log_key: Unlocking key 6F1A4B46
  5848. [2022-06-17 08:45:05.863755] smbXsrv_session_update: global_id (0x6f1a4b46) stored
  5849. [2022-06-17 08:45:05.865420] &session_blob: struct smbXsrv_sessionB
  5850. [2022-06-17 08:45:05.867086] version : SMBXSRV_VERSION_0 (0)
  5851. [2022-06-17 08:45:05.868737] reserved : 0x00000000 (0)
  5852. [2022-06-17 08:45:05.870365] info : union smbXsrv_sessionU(case 0)
  5853. [2022-06-17 08:45:05.872007] info0 : *
  5854. [2022-06-17 08:45:05.873708] info0: struct smbXsrv_session
  5855. [2022-06-17 08:45:05.875357] table : *
  5856. [2022-06-17 08:45:05.877008] db_rec : NULL
  5857. [2022-06-17 08:45:05.878660] client : *
  5858. [2022-06-17 08:45:05.880301] local_id : 0x6f1a4b46 (1863994182)
  5859. [2022-06-17 08:45:05.881955] global : *
  5860. [2022-06-17 08:45:05.883643] global: struct smbXsrv_session_global0
  5861. [2022-06-17 08:45:05.885296] db_rec : NULL
  5862. [2022-06-17 08:45:05.886952] session_global_id : 0x6f1a4b46 (1863994182)
  5863. [2022-06-17 08:45:05.888602] session_wire_id : 0x000000006f1a4b46 (1863994182)
  5864. [2022-06-17 08:45:05.890264] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5865. [2022-06-17 08:45:05.891932] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  5866. [2022-06-17 08:45:05.893648] auth_time : NTTIME(0)
  5867. [2022-06-17 08:45:05.895308] auth_session_info_seqnum : 0x00000000 (0)
  5868. [2022-06-17 08:45:05.896954] auth_session_info : NULL
  5869. [2022-06-17 08:45:05.898590] connection_dialect : 0x0311 (785)
  5870. [2022-06-17 08:45:05.900229] signing_flags : 0x00 (0)
  5871. [2022-06-17 08:45:05.901886] 0: SMBXSRV_SIGNING_REQUIRED
  5872. [2022-06-17 08:45:05.903581] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  5873. [2022-06-17 08:45:05.905249] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  5874. [2022-06-17 08:45:05.906899] encryption_flags : 0x00 (0)
  5875. [2022-06-17 08:45:05.908530] 0: SMBXSRV_ENCRYPTION_REQUIRED
  5876. [2022-06-17 08:45:05.910169] 0: SMBXSRV_ENCRYPTION_DESIRED
  5877. [2022-06-17 08:45:05.911812] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  5878. [2022-06-17 08:45:05.913503] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  5879. [2022-06-17 08:45:05.915169] signing_key : NULL
  5880. [2022-06-17 08:45:05.916814] encryption_key : NULL
  5881. [2022-06-17 08:45:05.918452] decryption_key : NULL
  5882. [2022-06-17 08:45:05.920100] num_channels : 0x00000001 (1)
  5883. [2022-06-17 08:45:05.921753] channels: ARRAY(1)
  5884. [2022-06-17 08:45:05.923424] channels: struct smbXsrv_channel_global0
  5885. [2022-06-17 08:45:05.925083] server_id: struct server_id
  5886. [2022-06-17 08:45:05.926723] pid : 0x0000000000002574 (9588)
  5887. [2022-06-17 08:45:05.928385] task_id : 0x00000000 (0)
  5888. [2022-06-17 08:45:05.930043] vnn : 0xffffffff (4294967295)
  5889. [2022-06-17 08:45:05.931691] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  5890. [2022-06-17 08:45:05.933409] channel_id : 0x0000000000000000 (0)
  5891. [2022-06-17 08:45:05.935075] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5892. [2022-06-17 08:45:05.936737] local_address : 'ipv4:192.168.1.250:445'
  5893. [2022-06-17 08:45:05.938406] remote_address : 'ipv4:192.168.1.10:33730'
  5894. [2022-06-17 08:45:05.940075] remote_name : '192.168.1.10'
  5895. [2022-06-17 08:45:05.941720] signing_key : NULL
  5896. [2022-06-17 08:45:05.943427] auth_session_info_seqnum : 0x00000000 (0)
  5897. [2022-06-17 08:45:05.945088] connection : *
  5898. [2022-06-17 08:45:05.946725] encryption_cipher : 0x0000 (0)
  5899. [2022-06-17 08:45:05.948389] status : NT_STATUS_MORE_PROCESSING_REQUIRED
  5900. [2022-06-17 08:45:05.950044] idle_time : Fri Jun 17 08:45:05 2022 UTC
  5901. [2022-06-17 08:45:05.951693] nonce_high_random : 0x0000000000000000 (0)
  5902. [2022-06-17 08:45:05.953384] nonce_high_max : 0x0000000000000000 (0)
  5903. [2022-06-17 08:45:05.955045] nonce_high : 0x0000000000000000 (0)
  5904. [2022-06-17 08:45:05.956698] nonce_low : 0x0000000000000000 (0)
  5905. [2022-06-17 08:45:05.958343] tcon_table : *
  5906. [2022-06-17 08:45:05.959856] homes_snum : 0xffffffff (4294967295)
  5907. [2022-06-17 08:45:05.961357] pending_auth : *
  5908. [2022-06-17 08:45:05.962899] pending_auth: struct smbXsrv_session_auth0
  5909. [2022-06-17 08:45:05.964432] prev : *
  5910. [2022-06-17 08:45:05.965945] next : NULL
  5911. [2022-06-17 08:45:05.967433] session : *
  5912. [2022-06-17 08:45:05.968914] connection : *
  5913. [2022-06-17 08:45:05.970403] gensec : *
  5914. [2022-06-17 08:45:05.972066] preauth : *
  5915. [2022-06-17 08:45:05.973665] in_flags : 0x00 (0)
  5916. [2022-06-17 08:45:05.975196] in_security_mode : 0x01 (1)
  5917. [2022-06-17 08:45:05.976698] creation_time : Fri Jun 17 08:45:05 2022 UTC
  5918. [2022-06-17 08:45:05.978213] idle_time : Fri Jun 17 08:45:05 2022 UTC
  5919. [2022-06-17 08:45:05.979718] channel_id : 0x0000000000000000 (0)
  5920. [2022-06-17 08:45:05.981230] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  5921. [2022-06-17 08:45:05.982716] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  5922. [2022-06-17 08:45:05.984259] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  5923. [2022-06-17 08:45:05.985771] Security token: (NULL)
  5924. [2022-06-17 08:45:05.987470] UNIX token of user 0
  5925. [2022-06-17 08:45:05.988979] Primary group is 0 and contains 0 supplementary groups
  5926. [2022-06-17 08:45:05.990480] Starting GENSEC submechanism ntlmssp
  5927. [2022-06-17 08:45:05.991969] Got NTLMSSP neg_flags=0x62088215
  5928. [2022-06-17 08:45:05.993500] NTLMSSP_NEGOTIATE_UNICODE
  5929. [2022-06-17 08:45:05.994992] NTLMSSP_REQUEST_TARGET
  5930. [2022-06-17 08:45:05.996480] NTLMSSP_NEGOTIATE_SIGN
  5931. [2022-06-17 08:45:05.997959] NTLMSSP_NEGOTIATE_NTLM
  5932. [2022-06-17 08:45:05.999433] NTLMSSP_NEGOTIATE_ALWAYS_SIGN
  5933. [2022-06-17 08:45:06.000919] NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
  5934. [2022-06-17 08:45:06.002609] NTLMSSP_NEGOTIATE_VERSION
  5935. [2022-06-17 08:45:06.004190] NTLMSSP_NEGOTIATE_128
  5936. [2022-06-17 08:45:06.005676] NTLMSSP_NEGOTIATE_KEY_EXCH
  5937. [2022-06-17 08:45:06.007607] negotiate: struct NEGOTIATE_MESSAGE
  5938. [2022-06-17 08:45:06.009280] Signature : 'NTLMSSP'
  5939. [2022-06-17 08:45:06.010938] MessageType : NtLmNegotiate (1)
  5940. [2022-06-17 08:45:06.012568] NegotiateFlags : 0x62088215 (1644724757)
  5941. [2022-06-17 08:45:06.014304] 1: NTLMSSP_NEGOTIATE_UNICODE
  5942. [2022-06-17 08:45:06.015952] 0: NTLMSSP_NEGOTIATE_OEM
  5943. [2022-06-17 08:45:06.017583] 1: NTLMSSP_REQUEST_TARGET
  5944. [2022-06-17 08:45:06.019213] 1: NTLMSSP_NEGOTIATE_SIGN
  5945. [2022-06-17 08:45:06.020860] 0: NTLMSSP_NEGOTIATE_SEAL
  5946. [2022-06-17 08:45:06.022492] 0: NTLMSSP_NEGOTIATE_DATAGRAM
  5947. [2022-06-17 08:45:06.024224] 0: NTLMSSP_NEGOTIATE_LM_KEY
  5948. [2022-06-17 08:45:06.025870] 0: NTLMSSP_NEGOTIATE_NETWARE
  5949. [2022-06-17 08:45:06.027373] 1: NTLMSSP_NEGOTIATE_NTLM
  5950. [2022-06-17 08:45:06.029130] 0: NTLMSSP_NEGOTIATE_NT_ONLY
  5951. [2022-06-17 08:45:06.030772] 0: NTLMSSP_ANONYMOUS
  5952. [2022-06-17 08:45:06.032410] 0: NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED
  5953. [2022-06-17 08:45:06.034152] 0: NTLMSSP_NEGOTIATE_OEM_WORKSTATION_SUPPLIED
  5954. [2022-06-17 08:45:06.035814] 0: NTLMSSP_NEGOTIATE_THIS_IS_LOCAL_CALL
  5955. [2022-06-17 08:45:06.037452] 1: NTLMSSP_NEGOTIATE_ALWAYS_SIGN
  5956. [2022-06-17 08:45:06.039083] 0: NTLMSSP_TARGET_TYPE_DOMAIN
  5957. [2022-06-17 08:45:06.040719] 0: NTLMSSP_TARGET_TYPE_SERVER
  5958. [2022-06-17 08:45:06.042361] 0: NTLMSSP_TARGET_TYPE_SHARE
  5959. [2022-06-17 08:45:06.044097] 1: NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
  5960. [2022-06-17 08:45:06.045761] 0: NTLMSSP_NEGOTIATE_IDENTIFY
  5961. [2022-06-17 08:45:06.047390] 0: NTLMSSP_REQUEST_NON_NT_SESSION_KEY
  5962. [2022-06-17 08:45:06.049027] 0: NTLMSSP_NEGOTIATE_TARGET_INFO
  5963. [2022-06-17 08:45:06.050661] 1: NTLMSSP_NEGOTIATE_VERSION
  5964. [2022-06-17 08:45:06.052280] 1: NTLMSSP_NEGOTIATE_128
  5965. [2022-06-17 08:45:06.053971] 1: NTLMSSP_NEGOTIATE_KEY_EXCH
  5966. [2022-06-17 08:45:06.055624] 0: NTLMSSP_NEGOTIATE_56
  5967. [2022-06-17 08:45:06.057273] DomainNameLen : 0x0000 (0)
  5968. [2022-06-17 08:45:06.058911] DomainNameMaxLen : 0x0000 (0)
  5969. [2022-06-17 08:45:06.060551] DomainName : *
  5970. [2022-06-17 08:45:06.062316] DomainName : ''
  5971. [2022-06-17 08:45:06.064052] WorkstationLen : 0x0000 (0)
  5972. [2022-06-17 08:45:06.065704] WorkstationMaxLen : 0x0000 (0)
  5973. [2022-06-17 08:45:06.067370] Workstation : *
  5974. [2022-06-17 08:45:06.069017] Workstation : ''
  5975. [2022-06-17 08:45:06.070660] Version: struct ntlmssp_VERSION
  5976. [2022-06-17 08:45:06.072289] ProductMajorVersion : NTLMSSP_WINDOWS_MAJOR_VERSION_6 (6)
  5977. [2022-06-17 08:45:06.074008] ProductMinorVersion : NTLMSSP_WINDOWS_MINOR_VERSION_1 (1)
  5978. [2022-06-17 08:45:06.075668] ProductBuild : 0x0000 (0)
  5979. [2022-06-17 08:45:06.077297] Reserved: ARRAY(3)
  5980. [2022-06-17 08:45:06.078805] [0] : 0x00 (0)
  5981. [2022-06-17 08:45:06.091316] [1] : 0x00 (0)
  5982. [2022-06-17 08:45:06.093149] [2] : 0x00 (0)
  5983. [2022-06-17 08:45:06.094871] NTLMRevisionCurrent : NTLMSSP_REVISION_W2K3 (15)
  5984. [2022-06-17 08:45:06.096541] short string '', sent with NULL termination despite NOTERM flag in IDL
  5985. [2022-06-17 08:45:06.098190] challenge: struct CHALLENGE_MESSAGE
  5986. [2022-06-17 08:45:06.099819] Signature : 'NTLMSSP'
  5987. [2022-06-17 08:45:06.101451] MessageType : NtLmChallenge (0x2)
  5988. [2022-06-17 08:45:06.103141] TargetNameLen : 0x000c (12)
  5989. [2022-06-17 08:45:06.104808] TargetNameMaxLen : 0x000c (12)
  5990. [2022-06-17 08:45:06.106469] TargetName : *
  5991. [2022-06-17 08:45:06.108127] TargetName : 'ZALUPA'
  5992. [2022-06-17 08:45:06.109768] NegotiateFlags : 0x628a8215 (1653244437)
  5993. [2022-06-17 08:45:06.111407] 1: NTLMSSP_NEGOTIATE_UNICODE
  5994. [2022-06-17 08:45:06.113078] 0: NTLMSSP_NEGOTIATE_OEM
  5995. [2022-06-17 08:45:06.114730] 1: NTLMSSP_REQUEST_TARGET
  5996. [2022-06-17 08:45:06.116376] 1: NTLMSSP_NEGOTIATE_SIGN
  5997. [2022-06-17 08:45:06.118008] 0: NTLMSSP_NEGOTIATE_SEAL
  5998. [2022-06-17 08:45:06.119637] 0: NTLMSSP_NEGOTIATE_DATAGRAM
  5999. [2022-06-17 08:45:06.121278] 0: NTLMSSP_NEGOTIATE_LM_KEY
  6000. [2022-06-17 08:45:06.122947] 0: NTLMSSP_NEGOTIATE_NETWARE
  6001. [2022-06-17 08:45:06.124582] 1: NTLMSSP_NEGOTIATE_NTLM
  6002. [2022-06-17 08:45:06.126205] 0: NTLMSSP_NEGOTIATE_NT_ONLY
  6003. [2022-06-17 08:45:06.127845] 0: NTLMSSP_ANONYMOUS
  6004. [2022-06-17 08:45:06.129489] 0: NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED
  6005. [2022-06-17 08:45:06.131131] 0: NTLMSSP_NEGOTIATE_OEM_WORKSTATION_SUPPLIED
  6006. [2022-06-17 08:45:06.132772] 0: NTLMSSP_NEGOTIATE_THIS_IS_LOCAL_CALL
  6007. [2022-06-17 08:45:06.134478] 1: NTLMSSP_NEGOTIATE_ALWAYS_SIGN
  6008. [2022-06-17 08:45:06.136135] 0: NTLMSSP_TARGET_TYPE_DOMAIN
  6009. [2022-06-17 08:45:06.137773] 1: NTLMSSP_TARGET_TYPE_SERVER
  6010. [2022-06-17 08:45:06.139404] 0: NTLMSSP_TARGET_TYPE_SHARE
  6011. [2022-06-17 08:45:06.141050] 1: NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
  6012. [2022-06-17 08:45:06.142693] 0: NTLMSSP_NEGOTIATE_IDENTIFY
  6013. [2022-06-17 08:45:06.144394] 0: NTLMSSP_REQUEST_NON_NT_SESSION_KEY
  6014. [2022-06-17 08:45:06.146027] 1: NTLMSSP_NEGOTIATE_TARGET_INFO
  6015. [2022-06-17 08:45:06.147672] 1: NTLMSSP_NEGOTIATE_VERSION
  6016. [2022-06-17 08:45:06.149316] 1: NTLMSSP_NEGOTIATE_128
  6017. [2022-06-17 08:45:06.150949] 1: NTLMSSP_NEGOTIATE_KEY_EXCH
  6018. [2022-06-17 08:45:06.152587] 0: NTLMSSP_NEGOTIATE_56
  6019. [2022-06-17 08:45:06.154304] ServerChallenge : 35249412ce6fc318
  6020. [2022-06-17 08:45:06.155951] Reserved : 0000000000000000
  6021. [2022-06-17 08:45:06.157583] TargetInfoLen : 0x004c (76)
  6022. [2022-06-17 08:45:06.159225] TargetInfoMaxLen : 0x004c (76)
  6023. [2022-06-17 08:45:06.160867] TargetInfo : *
  6024. [2022-06-17 08:45:06.162491] TargetInfo: struct AV_PAIR_LIST
  6025. [2022-06-17 08:45:06.164204] count : 0x00000006 (6)
  6026. [2022-06-17 08:45:06.165870] pair: ARRAY(6)
  6027. [2022-06-17 08:45:06.167504] pair: struct AV_PAIR
  6028. [2022-06-17 08:45:06.169366] AvId : MsvAvNbDomainName (0x2)
  6029. [2022-06-17 08:45:06.171020] AvLen : 0x000c (12)
  6030. [2022-06-17 08:45:06.172658] Value : union ntlmssp_AvValue(case 0x2)
  6031. [2022-06-17 08:45:06.174385] AvNbDomainName : 'ZALUPA'
  6032. [2022-06-17 08:45:06.176036] pair: struct AV_PAIR
  6033. [2022-06-17 08:45:06.177689] AvId : MsvAvNbComputerName (0x1)
  6034. [2022-06-17 08:45:06.179339] AvLen : 0x000c (12)
  6035. [2022-06-17 08:45:06.180987] Value : union ntlmssp_AvValue(case 0x1)
  6036. [2022-06-17 08:45:06.182632] AvNbComputerName : 'ZALUPA'
  6037. [2022-06-17 08:45:06.184361] pair: struct AV_PAIR
  6038. [2022-06-17 08:45:06.186002] AvId : MsvAvDnsDomainName (0x4)
  6039. [2022-06-17 08:45:06.187658] AvLen : 0x0002 (2)
  6040. [2022-06-17 08:45:06.189304] Value : union ntlmssp_AvValue(case 0x4)
  6041. [2022-06-17 08:45:06.190974] AvDnsDomainName : ''
  6042. [2022-06-17 08:45:06.192617] pair: struct AV_PAIR
  6043. [2022-06-17 08:45:06.194330] AvId : MsvAvDnsComputerName (0x3)
  6044. [2022-06-17 08:45:06.195992] AvLen : 0x0012 (18)
  6045. [2022-06-17 08:45:06.197632] Value : union ntlmssp_AvValue(case 0x3)
  6046. [2022-06-17 08:45:06.199273] AvDnsComputerName : 'localhost'
  6047. [2022-06-17 08:45:06.200916] pair: struct AV_PAIR
  6048. [2022-06-17 08:45:06.202550] AvId : MsvAvTimestamp (0x7)
  6049. [2022-06-17 08:45:06.204289] AvLen : 0x0008 (8)
  6050. [2022-06-17 08:45:06.205947] Value : union ntlmssp_AvValue(case 0x7)
  6051. [2022-06-17 08:45:06.207607] AvTimestamp : Fri Jun 17 08:45:05 2022 UTC
  6052. [2022-06-17 08:45:06.209250] pair: struct AV_PAIR
  6053. [2022-06-17 08:45:06.210889] AvId : MsvAvEOL (0x0)
  6054. [2022-06-17 08:45:06.212539] AvLen : 0x0000 (0)
  6055. [2022-06-17 08:45:06.214271] Value : union ntlmssp_AvValue(case 0x0)
  6056. [2022-06-17 08:45:06.215936] Version: struct ntlmssp_VERSION
  6057. [2022-06-17 08:45:06.217568] ProductMajorVersion : NTLMSSP_WINDOWS_MAJOR_VERSION_6 (0x6)
  6058. [2022-06-17 08:45:06.219226] ProductMinorVersion : NTLMSSP_WINDOWS_MINOR_VERSION_1 (0x1)
  6059. [2022-06-17 08:45:06.220879] ProductBuild : 0x0000 (0)
  6060. [2022-06-17 08:45:06.222515] Reserved : 000000
  6061. [2022-06-17 08:45:06.224247] NTLMRevisionCurrent : NTLMSSP_REVISION_W2K3 (0xF)
  6062. [2022-06-17 08:45:06.225911] gensec_update_send: ntlmssp[0xb516aac0]: subreq: 0xb649fc70
  6063. [2022-06-17 08:45:06.227433] gensec_update_send: spnego[0xb516a940]: subreq: 0xb5c2b380
  6064. [2022-06-17 08:45:06.229110] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6065. [2022-06-17 08:45:06.230753] gensec_update_done: ntlmssp[0xb516aac0]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0xb649fc70/../../auth/ntlmssp/ntlmssp.c:181]: state[2] error[0 (0x0)] state[struct gensec_ntlmssp_update_state (0xb649fd50)] timer[0] finish[../../auth/ntlmssp/ntlmssp.c:215]
  6066. [2022-06-17 08:45:06.232504] gensec_update_done: spnego[0xb516a940]: NT_STATUS_MORE_PROCESSING_REQUIRED tevent_req[0xb5c2b380/../../auth/gensec/spnego.c:1632]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0xb5c2b460)] timer[0] finish[../../auth/gensec/spnego.c:2116]
  6067. [2022-06-17 08:45:06.234336] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6068. [2022-06-17 08:45:06.235988] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6069. [2022-06-17 08:45:06.237633] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6070. [2022-06-17 08:45:06.239273] Security token: (NULL)
  6071. [2022-06-17 08:45:06.240884] UNIX token of user 0
  6072. [2022-06-17 08:45:06.242499] Primary group is 0 and contains 0 supplementary groups
  6073. [2022-06-17 08:45:06.244212] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6074. [2022-06-17 08:45:06.245856] smbd_smb2_request_done_ex: mid [1] idx[1] status[NT_STATUS_MORE_PROCESSING_REQUIRED] body[8] dyn[yes:175] at ../../source3/smbd/smb2_sesssetup.c:183
  6075. [2022-06-17 08:45:06.247559] smb2_set_operation_credit: smb2_set_operation_credit: requested 8192, charge 1, granted 1, current possible/max 8192/8192, total granted/max/low/range 1/8192/2/1
  6076. [2022-06-17 08:45:06.249276] smbd_smb2_request idx[1] of 5 vectors
  6077. [2022-06-17 08:45:06.250927] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 2 (position 2) from bitmap
  6078. [2022-06-17 08:45:06.252599] smbd_smb2_request_dispatch: opcode[SMB2_OP_SESSSETUP] mid = 2
  6079. [2022-06-17 08:45:06.254330] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  6080. [2022-06-17 08:45:06.255987] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  6081. [2022-06-17 08:45:06.257638] db_tdb_log_key: Locking key 6F1A4B46
  6082. [2022-06-17 08:45:06.259269] db_tdb_fetch_locked_internal: Allocated locked data 0xb59d0cb0
  6083. [2022-06-17 08:45:06.260891] dbwrap_watched_subrec_wakeup_fn: No watchers
  6084. [2022-06-17 08:45:06.262539] smbXsrv_session_global_store: key '6F1A4B46' stored
  6085. [2022-06-17 08:45:06.264283] &global_blob: struct smbXsrv_session_globalB
  6086. [2022-06-17 08:45:06.265938] version : SMBXSRV_VERSION_0 (0)
  6087. [2022-06-17 08:45:06.267583] seqnum : 0x00000003 (3)
  6088. [2022-06-17 08:45:06.269207] info : union smbXsrv_session_globalU(case 0)
  6089. [2022-06-17 08:45:06.270851] info0 : *
  6090. [2022-06-17 08:45:06.272475] info0: struct smbXsrv_session_global0
  6091. [2022-06-17 08:45:06.274191] db_rec : *
  6092. [2022-06-17 08:45:06.275865] session_global_id : 0x6f1a4b46 (1863994182)
  6093. [2022-06-17 08:45:06.277515] session_wire_id : 0x000000006f1a4b46 (1863994182)
  6094. [2022-06-17 08:45:06.279155] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6095. [2022-06-17 08:45:06.280807] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  6096. [2022-06-17 08:45:06.282446] auth_time : NTTIME(0)
  6097. [2022-06-17 08:45:06.284179] auth_session_info_seqnum : 0x00000000 (0)
  6098. [2022-06-17 08:45:06.285821] auth_session_info : NULL
  6099. [2022-06-17 08:45:06.287472] connection_dialect : 0x0311 (785)
  6100. [2022-06-17 08:45:06.289107] signing_flags : 0x04 (4)
  6101. [2022-06-17 08:45:06.290750] 0: SMBXSRV_SIGNING_REQUIRED
  6102. [2022-06-17 08:45:06.292271] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  6103. [2022-06-17 08:45:06.293810] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  6104. [2022-06-17 08:45:06.295319] encryption_flags : 0x08 (8)
  6105. [2022-06-17 08:45:06.296806] 0: SMBXSRV_ENCRYPTION_REQUIRED
  6106. [2022-06-17 08:45:06.298307] 0: SMBXSRV_ENCRYPTION_DESIRED
  6107. [2022-06-17 08:45:06.299814] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  6108. [2022-06-17 08:45:06.301314] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  6109. [2022-06-17 08:45:06.302803] signing_key : NULL
  6110. [2022-06-17 08:45:06.304481] encryption_key : NULL
  6111. [2022-06-17 08:45:06.306123] decryption_key : NULL
  6112. [2022-06-17 08:45:06.307662] num_channels : 0x00000001 (1)
  6113. [2022-06-17 08:45:06.309178] channels: ARRAY(1)
  6114. [2022-06-17 08:45:06.310685] channels: struct smbXsrv_channel_global0
  6115. [2022-06-17 08:45:06.312184] server_id: struct server_id
  6116. [2022-06-17 08:45:06.313735] pid : 0x0000000000002574 (9588)
  6117. [2022-06-17 08:45:06.315257] task_id : 0x00000000 (0)
  6118. [2022-06-17 08:45:06.322970] vnn : 0xffffffff (4294967295)
  6119. [2022-06-17 08:45:06.324621] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  6120. [2022-06-17 08:45:06.326196] channel_id : 0x0000000000000000 (0)
  6121. [2022-06-17 08:45:06.327721] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6122. [2022-06-17 08:45:06.333009] local_address : 'ipv4:192.168.1.250:445'
  6123. [2022-06-17 08:45:06.334575] remote_address : 'ipv4:192.168.1.10:33730'
  6124. [2022-06-17 08:45:06.336095] remote_name : '192.168.1.10'
  6125. [2022-06-17 08:45:06.337828] signing_key : NULL
  6126. [2022-06-17 08:45:06.339347] auth_session_info_seqnum : 0x00000000 (0)
  6127. [2022-06-17 08:45:06.340851] connection : *
  6128. [2022-06-17 08:45:06.342356] encryption_cipher : 0x0000 (0)
  6129. [2022-06-17 08:45:06.343945] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  6130. [2022-06-17 08:45:06.345467] db_tdb_log_key: Unlocking key 6F1A4B46
  6131. [2022-06-17 08:45:06.346957] smbXsrv_session_update: global_id (0x6f1a4b46) stored
  6132. [2022-06-17 08:45:06.348439] &session_blob: struct smbXsrv_sessionB
  6133. [2022-06-17 08:45:06.349926] version : SMBXSRV_VERSION_0 (0)
  6134. [2022-06-17 08:45:06.351572] reserved : 0x00000000 (0)
  6135. [2022-06-17 08:45:06.353187] info : union smbXsrv_sessionU(case 0)
  6136. [2022-06-17 08:45:06.354734] info0 : *
  6137. [2022-06-17 08:45:06.356236] info0: struct smbXsrv_session
  6138. [2022-06-17 08:45:06.357722] table : *
  6139. [2022-06-17 08:45:06.359223] db_rec : NULL
  6140. [2022-06-17 08:45:06.360715] client : *
  6141. [2022-06-17 08:45:06.362204] local_id : 0x6f1a4b46 (1863994182)
  6142. [2022-06-17 08:45:06.363758] global : *
  6143. [2022-06-17 08:45:06.365272] global: struct smbXsrv_session_global0
  6144. [2022-06-17 08:45:06.367492] db_rec : NULL
  6145. [2022-06-17 08:45:06.369071] session_global_id : 0x6f1a4b46 (1863994182)
  6146. [2022-06-17 08:45:06.370828] session_wire_id : 0x000000006f1a4b46 (1863994182)
  6147. [2022-06-17 08:45:06.372485] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6148. [2022-06-17 08:45:06.374101] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  6149. [2022-06-17 08:45:06.375777] auth_time : NTTIME(0)
  6150. [2022-06-17 08:45:06.377437] auth_session_info_seqnum : 0x00000000 (0)
  6151. [2022-06-17 08:45:06.379086] auth_session_info : NULL
  6152. [2022-06-17 08:45:06.380734] connection_dialect : 0x0311 (785)
  6153. [2022-06-17 08:45:06.382378] signing_flags : 0x04 (4)
  6154. [2022-06-17 08:45:06.384080] 0: SMBXSRV_SIGNING_REQUIRED
  6155. [2022-06-17 08:45:06.385827] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  6156. [2022-06-17 08:45:06.387464] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  6157. [2022-06-17 08:45:06.388993] encryption_flags : 0x08 (8)
  6158. [2022-06-17 08:45:06.390648] 0: SMBXSRV_ENCRYPTION_REQUIRED
  6159. [2022-06-17 08:45:06.392396] 0: SMBXSRV_ENCRYPTION_DESIRED
  6160. [2022-06-17 08:45:06.394010] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  6161. [2022-06-17 08:45:06.395665] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  6162. [2022-06-17 08:45:06.397313] signing_key : NULL
  6163. [2022-06-17 08:45:06.398954] encryption_key : NULL
  6164. [2022-06-17 08:45:06.400695] decryption_key : NULL
  6165. [2022-06-17 08:45:06.402230] num_channels : 0x00000001 (1)
  6166. [2022-06-17 08:45:06.403975] channels: ARRAY(1)
  6167. [2022-06-17 08:45:06.405623] channels: struct smbXsrv_channel_global0
  6168. [2022-06-17 08:45:06.407375] server_id: struct server_id
  6169. [2022-06-17 08:45:06.409004] pid : 0x0000000000002574 (9588)
  6170. [2022-06-17 08:45:06.410548] task_id : 0x00000000 (0)
  6171. [2022-06-17 08:45:06.412204] vnn : 0xffffffff (4294967295)
  6172. [2022-06-17 08:45:06.414799] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  6173. [2022-06-17 08:45:06.416505] channel_id : 0x0000000000000000 (0)
  6174. [2022-06-17 08:45:06.418167] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6175. [2022-06-17 08:45:06.419831] local_address : 'ipv4:192.168.1.250:445'
  6176. [2022-06-17 08:45:06.421482] remote_address : 'ipv4:192.168.1.10:33730'
  6177. [2022-06-17 08:45:06.423195] remote_name : '192.168.1.10'
  6178. [2022-06-17 08:45:06.424853] signing_key : NULL
  6179. [2022-06-17 08:45:06.426517] auth_session_info_seqnum : 0x00000000 (0)
  6180. [2022-06-17 08:45:06.428049] connection : *
  6181. [2022-06-17 08:45:06.429839] encryption_cipher : 0x0000 (0)
  6182. [2022-06-17 08:45:06.431491] status : NT_STATUS_MORE_PROCESSING_REQUIRED
  6183. [2022-06-17 08:45:06.433200] idle_time : Fri Jun 17 08:45:05 2022 UTC
  6184. [2022-06-17 08:45:06.434855] nonce_high_random : 0x0000000000000000 (0)
  6185. [2022-06-17 08:45:06.436508] nonce_high_max : 0x0000000000000000 (0)
  6186. [2022-06-17 08:45:06.438148] nonce_high : 0x0000000000000000 (0)
  6187. [2022-06-17 08:45:06.439800] nonce_low : 0x0000000000000000 (0)
  6188. [2022-06-17 08:45:06.441453] tcon_table : *
  6189. [2022-06-17 08:45:06.443157] homes_snum : 0xffffffff (4294967295)
  6190. [2022-06-17 08:45:06.444810] pending_auth : *
  6191. [2022-06-17 08:45:06.446458] pending_auth: struct smbXsrv_session_auth0
  6192. [2022-06-17 08:45:06.448113] prev : *
  6193. [2022-06-17 08:45:06.449757] next : NULL
  6194. [2022-06-17 08:45:06.451411] session : *
  6195. [2022-06-17 08:45:06.453111] connection : *
  6196. [2022-06-17 08:45:06.454765] gensec : *
  6197. [2022-06-17 08:45:06.456414] preauth : *
  6198. [2022-06-17 08:45:06.458054] in_flags : 0x00 (0)
  6199. [2022-06-17 08:45:06.459683] in_security_mode : 0x01 (1)
  6200. [2022-06-17 08:45:06.461311] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6201. [2022-06-17 08:45:06.463011] idle_time : Fri Jun 17 08:45:05 2022 UTC
  6202. [2022-06-17 08:45:06.464697] channel_id : 0x0000000000000000 (0)
  6203. [2022-06-17 08:45:06.466367] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  6204. [2022-06-17 08:45:06.468005] Security token: (NULL)
  6205. [2022-06-17 08:45:06.469619] UNIX token of user 0
  6206. [2022-06-17 08:45:06.471239] Primary group is 0 and contains 0 supplementary groups
  6207. [2022-06-17 08:45:06.472920] change_to_root_user: now uid=(0,0) gid=(0,0)
  6208. [2022-06-17 08:45:06.474579] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  6209. [2022-06-17 08:45:06.476250] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  6210. [2022-06-17 08:45:06.477899] db_tdb_log_key: Locking key 6F1A4B46
  6211. [2022-06-17 08:45:06.479531] db_tdb_fetch_locked_internal: Allocated locked data 0xb62aecf0
  6212. [2022-06-17 08:45:06.481169] dbwrap_watched_subrec_wakeup_fn: No watchers
  6213. [2022-06-17 08:45:06.482807] smbXsrv_session_global_store: key '6F1A4B46' stored
  6214. [2022-06-17 08:45:06.484503] &global_blob: struct smbXsrv_session_globalB
  6215. [2022-06-17 08:45:06.486145] version : SMBXSRV_VERSION_0 (0)
  6216. [2022-06-17 08:45:06.487792] seqnum : 0x00000004 (4)
  6217. [2022-06-17 08:45:06.489438] info : union smbXsrv_session_globalU(case 0)
  6218. [2022-06-17 08:45:06.491082] info0 : *
  6219. [2022-06-17 08:45:06.492704] info0: struct smbXsrv_session_global0
  6220. [2022-06-17 08:45:06.494390] db_rec : *
  6221. [2022-06-17 08:45:06.496031] session_global_id : 0x6f1a4b46 (1863994182)
  6222. [2022-06-17 08:45:06.497673] session_wire_id : 0x000000006f1a4b46 (1863994182)
  6223. [2022-06-17 08:45:06.499352] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6224. [2022-06-17 08:45:06.501017] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  6225. [2022-06-17 08:45:06.502673] auth_time : NTTIME(0)
  6226. [2022-06-17 08:45:06.504370] auth_session_info_seqnum : 0x00000000 (0)
  6227. [2022-06-17 08:45:06.506023] auth_session_info : NULL
  6228. [2022-06-17 08:45:06.507659] connection_dialect : 0x0311 (785)
  6229. [2022-06-17 08:45:06.509305] signing_flags : 0x04 (4)
  6230. [2022-06-17 08:45:06.510955] 0: SMBXSRV_SIGNING_REQUIRED
  6231. [2022-06-17 08:45:06.512615] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  6232. [2022-06-17 08:45:06.514346] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  6233. [2022-06-17 08:45:06.516004] encryption_flags : 0x08 (8)
  6234. [2022-06-17 08:45:06.517647] 0: SMBXSRV_ENCRYPTION_REQUIRED
  6235. [2022-06-17 08:45:06.519286] 0: SMBXSRV_ENCRYPTION_DESIRED
  6236. [2022-06-17 08:45:06.520921] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  6237. [2022-06-17 08:45:06.522557] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  6238. [2022-06-17 08:45:06.524293] signing_key : NULL
  6239. [2022-06-17 08:45:06.525944] encryption_key : NULL
  6240. [2022-06-17 08:45:06.527606] decryption_key : NULL
  6241. [2022-06-17 08:45:06.529256] num_channels : 0x00000001 (1)
  6242. [2022-06-17 08:45:06.530897] channels: ARRAY(1)
  6243. [2022-06-17 08:45:06.532523] channels: struct smbXsrv_channel_global0
  6244. [2022-06-17 08:45:06.534245] server_id: struct server_id
  6245. [2022-06-17 08:45:06.535896] pid : 0x0000000000002574 (9588)
  6246. [2022-06-17 08:45:06.537564] task_id : 0x00000000 (0)
  6247. [2022-06-17 08:45:06.539213] vnn : 0xffffffff (4294967295)
  6248. [2022-06-17 08:45:06.540874] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  6249. [2022-06-17 08:45:06.542543] channel_id : 0x0000000000000000 (0)
  6250. [2022-06-17 08:45:06.552245] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6251. [2022-06-17 08:45:06.554013] local_address : 'ipv4:192.168.1.250:445'
  6252. [2022-06-17 08:45:06.556080] remote_address : 'ipv4:192.168.1.10:33730'
  6253. [2022-06-17 08:45:06.557769] remote_name : '192.168.1.10'
  6254. [2022-06-17 08:45:06.559430] signing_key : NULL
  6255. [2022-06-17 08:45:06.563581] auth_session_info_seqnum : 0x00000000 (0)
  6256. [2022-06-17 08:45:06.565365] connection : *
  6257. [2022-06-17 08:45:06.567049] encryption_cipher : 0x0000 (0)
  6258. [2022-06-17 08:45:06.570085] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  6259. [2022-06-17 08:45:06.571776] db_tdb_log_key: Unlocking key 6F1A4B46
  6260. [2022-06-17 08:45:06.573485] smbXsrv_session_update: global_id (0x6f1a4b46) stored
  6261. [2022-06-17 08:45:06.575156] &session_blob: struct smbXsrv_sessionB
  6262. [2022-06-17 08:45:06.576809] version : SMBXSRV_VERSION_0 (0)
  6263. [2022-06-17 08:45:06.578453] reserved : 0x00000000 (0)
  6264. [2022-06-17 08:45:06.580092] info : union smbXsrv_sessionU(case 0)
  6265. [2022-06-17 08:45:06.581739] info0 : *
  6266. [2022-06-17 08:45:06.583430] info0: struct smbXsrv_session
  6267. [2022-06-17 08:45:06.585099] table : *
  6268. [2022-06-17 08:45:06.586747] db_rec : NULL
  6269. [2022-06-17 08:45:06.588396] client : *
  6270. [2022-06-17 08:45:06.590029] local_id : 0x6f1a4b46 (1863994182)
  6271. [2022-06-17 08:45:06.591672] global : *
  6272. [2022-06-17 08:45:06.593350] global: struct smbXsrv_session_global0
  6273. [2022-06-17 08:45:06.595019] db_rec : NULL
  6274. [2022-06-17 08:45:06.596658] session_global_id : 0x6f1a4b46 (1863994182)
  6275. [2022-06-17 08:45:06.598314] session_wire_id : 0x000000006f1a4b46 (1863994182)
  6276. [2022-06-17 08:45:06.599974] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6277. [2022-06-17 08:45:06.601635] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  6278. [2022-06-17 08:45:06.603330] auth_time : NTTIME(0)
  6279. [2022-06-17 08:45:06.604985] auth_session_info_seqnum : 0x00000000 (0)
  6280. [2022-06-17 08:45:06.606630] auth_session_info : NULL
  6281. [2022-06-17 08:45:06.608279] connection_dialect : 0x0311 (785)
  6282. [2022-06-17 08:45:06.609935] signing_flags : 0x04 (4)
  6283. [2022-06-17 08:45:06.611463] 0: SMBXSRV_SIGNING_REQUIRED
  6284. [2022-06-17 08:45:06.613020] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  6285. [2022-06-17 08:45:06.614534] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  6286. [2022-06-17 08:45:06.616044] encryption_flags : 0x08 (8)
  6287. [2022-06-17 08:45:06.617534] 0: SMBXSRV_ENCRYPTION_REQUIRED
  6288. [2022-06-17 08:45:06.619026] 0: SMBXSRV_ENCRYPTION_DESIRED
  6289. [2022-06-17 08:45:06.620527] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  6290. [2022-06-17 08:45:06.622029] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  6291. [2022-06-17 08:45:06.623644] signing_key : NULL
  6292. [2022-06-17 08:45:06.625160] encryption_key : NULL
  6293. [2022-06-17 08:45:06.626842] decryption_key : NULL
  6294. [2022-06-17 08:45:06.628364] num_channels : 0x00000001 (1)
  6295. [2022-06-17 08:45:06.630161] channels: ARRAY(1)
  6296. [2022-06-17 08:45:06.631812] channels: struct smbXsrv_channel_global0
  6297. [2022-06-17 08:45:06.633518] server_id: struct server_id
  6298. [2022-06-17 08:45:06.635172] pid : 0x0000000000002574 (9588)
  6299. [2022-06-17 08:45:06.636840] task_id : 0x00000000 (0)
  6300. [2022-06-17 08:45:06.638491] vnn : 0xffffffff (4294967295)
  6301. [2022-06-17 08:45:06.640141] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  6302. [2022-06-17 08:45:06.641806] channel_id : 0x0000000000000000 (0)
  6303. [2022-06-17 08:45:06.643505] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6304. [2022-06-17 08:45:06.645192] local_address : 'ipv4:192.168.1.250:445'
  6305. [2022-06-17 08:45:06.646843] remote_address : 'ipv4:192.168.1.10:33730'
  6306. [2022-06-17 08:45:06.648499] remote_name : '192.168.1.10'
  6307. [2022-06-17 08:45:06.650145] signing_key : NULL
  6308. [2022-06-17 08:45:06.651776] auth_session_info_seqnum : 0x00000000 (0)
  6309. [2022-06-17 08:45:06.653473] connection : *
  6310. [2022-06-17 08:45:06.655128] encryption_cipher : 0x0000 (0)
  6311. [2022-06-17 08:45:06.656776] status : NT_STATUS_MORE_PROCESSING_REQUIRED
  6312. [2022-06-17 08:45:06.658428] idle_time : Fri Jun 17 08:45:05 2022 UTC
  6313. [2022-06-17 08:45:06.660066] nonce_high_random : 0x0000000000000000 (0)
  6314. [2022-06-17 08:45:06.661709] nonce_high_max : 0x0000000000000000 (0)
  6315. [2022-06-17 08:45:06.663398] nonce_high : 0x0000000000000000 (0)
  6316. [2022-06-17 08:45:06.665060] nonce_low : 0x0000000000000000 (0)
  6317. [2022-06-17 08:45:06.666701] tcon_table : *
  6318. [2022-06-17 08:45:06.668338] homes_snum : 0xffffffff (4294967295)
  6319. [2022-06-17 08:45:06.669983] pending_auth : *
  6320. [2022-06-17 08:45:06.671624] pending_auth: struct smbXsrv_session_auth0
  6321. [2022-06-17 08:45:06.673297] prev : *
  6322. [2022-06-17 08:45:06.674948] next : NULL
  6323. [2022-06-17 08:45:06.676472] session : *
  6324. [2022-06-17 08:45:06.677974] connection : *
  6325. [2022-06-17 08:45:06.679468] gensec : *
  6326. [2022-06-17 08:45:06.680965] preauth : *
  6327. [2022-06-17 08:45:06.682456] in_flags : 0x00 (0)
  6328. [2022-06-17 08:45:06.684040] in_security_mode : 0x01 (1)
  6329. [2022-06-17 08:45:06.685968] creation_time : Fri Jun 17 08:45:05 2022 UTC
  6330. [2022-06-17 08:45:06.687629] idle_time : Fri Jun 17 08:45:05 2022 UTC
  6331. [2022-06-17 08:45:06.689370] channel_id : 0x0000000000000000 (0)
  6332. [2022-06-17 08:45:06.690917] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6333. [2022-06-17 08:45:06.692412] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6334. [2022-06-17 08:45:06.694107] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6335. [2022-06-17 08:45:06.695645] Security token: (NULL)
  6336. [2022-06-17 08:45:06.697232] UNIX token of user 0
  6337. [2022-06-17 08:45:06.698856] Primary group is 0 and contains 0 supplementary groups
  6338. [2022-06-17 08:45:06.700492] short string '', sent with NULL termination despite NOTERM flag in IDL
  6339. [2022-06-17 08:45:06.702131] authenticate: struct AUTHENTICATE_MESSAGE
  6340. [2022-06-17 08:45:06.703854] Signature : 'NTLMSSP'
  6341. [2022-06-17 08:45:06.705519] MessageType : NtLmAuthenticate (3)
  6342. [2022-06-17 08:45:06.707171] LmChallengeResponseLen : 0x0018 (24)
  6343. [2022-06-17 08:45:06.708814] LmChallengeResponseMaxLen: 0x0018 (24)
  6344. [2022-06-17 08:45:06.710509] LmChallengeResponse : *
  6345. [2022-06-17 08:45:06.712168] LmChallengeResponse : union ntlmssp_LM_RESPONSE_with_len(case 24)
  6346. [2022-06-17 08:45:06.713875] v1: struct LM_RESPONSE
  6347. [2022-06-17 08:45:06.715529] Response : 000000000000000000000000000000000000000000000000
  6348. [2022-06-17 08:45:06.717189] NtChallengeResponseLen : 0x00f0 (240)
  6349. [2022-06-17 08:45:06.718830] NtChallengeResponseMaxLen: 0x00f0 (240)
  6350. [2022-06-17 08:45:06.720475] NtChallengeResponse : *
  6351. [2022-06-17 08:45:06.722109] NtChallengeResponse : union ntlmssp_NTLM_RESPONSE_with_len(case 240)
  6352. [2022-06-17 08:45:06.723817] v2: struct NTLMv2_RESPONSE
  6353. [2022-06-17 08:45:06.725473] Response : 0305ee37d2c7dc4bf00f4b46a92ed7e5
  6354. [2022-06-17 08:45:06.727117] Challenge: struct NTLMv2_CLIENT_CHALLENGE
  6355. [2022-06-17 08:45:06.728767] RespType : 0x01 (1)
  6356. [2022-06-17 08:45:06.730432] HiRespType : 0x01 (1)
  6357. [2022-06-17 08:45:06.732079] Reserved1 : 0x0000 (0)
  6358. [2022-06-17 08:45:06.733775] Reserved2 : 0x00000000 (0)
  6359. [2022-06-17 08:45:06.735446] TimeStamp : Fri Jun 17 08:45:05 2022 UTC
  6360. [2022-06-17 08:45:06.737085] ChallengeFromClient : 019d29316206947a
  6361. [2022-06-17 08:45:06.738732] Reserved3 : 0x00000000 (0)
  6362. [2022-06-17 08:45:06.740385] AvPairs: struct AV_PAIR_LIST
  6363. [2022-06-17 08:45:06.741901] count : 0x0000000a (10)
  6364. [2022-06-17 08:45:06.743598] pair: ARRAY(10)
  6365. [2022-06-17 08:45:06.745241] pair: struct AV_PAIR
  6366. [2022-06-17 08:45:06.746758] AvId : MsvAvNbDomainName (0x2)
  6367. [2022-06-17 08:45:06.748498] AvLen : 0x000c (12)
  6368. [2022-06-17 08:45:06.750156] Value : union ntlmssp_AvValue(case 0x2)
  6369. [2022-06-17 08:45:06.751686] AvNbDomainName : 'ZALUPA'
  6370. [2022-06-17 08:45:06.753497] pair: struct AV_PAIR
  6371. [2022-06-17 08:45:06.755039] AvId : MsvAvNbComputerName (0x1)
  6372. [2022-06-17 08:45:06.756828] AvLen : 0x000c (12)
  6373. [2022-06-17 08:45:06.758485] Value : union ntlmssp_AvValue(case 0x1)
  6374. [2022-06-17 08:45:06.760155] AvNbComputerName : 'ZALUPA'
  6375. [2022-06-17 08:45:06.761795] pair: struct AV_PAIR
  6376. [2022-06-17 08:45:06.763367] AvId : MsvAvDnsDomainName (0x4)
  6377. [2022-06-17 08:45:06.765144] AvLen : 0x0002 (2)
  6378. [2022-06-17 08:45:06.766811] Value : union ntlmssp_AvValue(case 0x4)
  6379. [2022-06-17 08:45:06.768477] AvDnsDomainName : ''
  6380. [2022-06-17 08:45:06.770120] pair: struct AV_PAIR
  6381. [2022-06-17 08:45:06.781706] AvId : MsvAvDnsComputerName (0x3)
  6382. [2022-06-17 08:45:06.783516] AvLen : 0x0012 (18)
  6383. [2022-06-17 08:45:06.785233] Value : union ntlmssp_AvValue(case 0x3)
  6384. [2022-06-17 08:45:06.786794] AvDnsComputerName : 'localhost'
  6385. [2022-06-17 08:45:06.788589] pair: struct AV_PAIR
  6386. [2022-06-17 08:45:06.790234] AvId : MsvAvTimestamp (0x7)
  6387. [2022-06-17 08:45:06.791895] AvLen : 0x0008 (8)
  6388. [2022-06-17 08:45:06.793466] Value : union ntlmssp_AvValue(case 0x7)
  6389. [2022-06-17 08:45:06.795220] AvTimestamp : Fri Jun 17 08:45:05 2022 UTC
  6390. [2022-06-17 08:45:06.796888] pair: struct AV_PAIR
  6391. [2022-06-17 08:45:06.798548] AvId : MsvAvFlags (0x6)
  6392. [2022-06-17 08:45:06.800210] AvLen : 0x0004 (4)
  6393. [2022-06-17 08:45:06.801864] Value : union ntlmssp_AvValue(case 0x6)
  6394. [2022-06-17 08:45:06.803570] AvFlags : 0x00000002 (2)
  6395. [2022-06-17 08:45:06.805230] 0: NTLMSSP_AVFLAG_CONSTRAINTED_ACCOUNT
  6396. [2022-06-17 08:45:06.806884] 1: NTLMSSP_AVFLAG_MIC_IN_AUTHENTICATE_MESSAGE
  6397. [2022-06-17 08:45:06.808531] 0: NTLMSSP_AVFLAG_TARGET_SPN_FROM_UNTRUSTED_SOURCE
  6398. [2022-06-17 08:45:06.810183] pair: struct AV_PAIR
  6399. [2022-06-17 08:45:06.811838] AvId : MsvAvSingleHost (0x8)
  6400. [2022-06-17 08:45:06.813424] AvLen : 0x0030 (48)
  6401. [2022-06-17 08:45:06.814954] Value : union ntlmssp_AvValue(case 0x8)
  6402. [2022-06-17 08:45:06.816460] AvSingleHost: struct ntlmssp_SingleHostData
  6403. [2022-06-17 08:45:06.818220] Size : 0x00000030 (48)
  6404. [2022-06-17 08:45:06.819875] Z4 : 0x00000000 (0)
  6405. [2022-06-17 08:45:06.821535] token_info: struct LSAP_TOKEN_INFO_INTEGRITY
  6406. [2022-06-17 08:45:06.823242] Flags : 0x00000000 (0)
  6407. [2022-06-17 08:45:06.824928] TokenIL : 0x00000000 (0)
  6408. [2022-06-17 08:45:06.826583] MachineId : 0c18bd46c901a766bdee49fb89a32fb6e464fb01c742a218764a8d4d50d4f398
  6409. [2022-06-17 08:45:06.828264] remaining : DATA_BLOB length=0
  6410. [2022-06-17 08:45:06.829942] pair: struct AV_PAIR
  6411. [2022-06-17 08:45:06.831590] AvId : MsvChannelBindings (0xA)
  6412. [2022-06-17 08:45:06.833301] AvLen : 0x0010 (16)
  6413. [2022-06-17 08:45:06.834957] Value : union ntlmssp_AvValue(case 0xA)
  6414. [2022-06-17 08:45:06.836617] ChannelBindings : 00000000000000000000000000000000
  6415. [2022-06-17 08:45:06.838278] pair: struct AV_PAIR
  6416. [2022-06-17 08:45:06.839922] AvId : MsvAvTargetName (0x9)
  6417. [2022-06-17 08:45:06.841573] AvLen : 0x0024 (36)
  6418. [2022-06-17 08:45:06.843296] Value : union ntlmssp_AvValue(case 0x9)
  6419. [2022-06-17 08:45:06.844982] AvTargetName : 'cifs/192.168.1.250'
  6420. [2022-06-17 08:45:06.846631] pair: struct AV_PAIR
  6421. [2022-06-17 08:45:06.848276] AvId : MsvAvEOL (0x0)
  6422. [2022-06-17 08:45:06.849929] AvLen : 0x0000 (0)
  6423. [2022-06-17 08:45:06.851587] Value : union ntlmssp_AvValue(case 0x0)
  6424. [2022-06-17 08:45:06.853279] DomainNameLen : 0x0012 (18)
  6425. [2022-06-17 08:45:06.854925] DomainNameMaxLen : 0x0012 (18)
  6426. [2022-06-17 08:45:06.856561] DomainName : *
  6427. [2022-06-17 08:45:06.858216] DomainName : 'WORKGROUP'
  6428. [2022-06-17 08:45:06.859864] UserNameLen : 0x0010 (16)
  6429. [2022-06-17 08:45:06.861505] UserNameMaxLen : 0x0010 (16)
  6430. [2022-06-17 08:45:06.863200] UserName : *
  6431. [2022-06-17 08:45:06.864845] UserName : 'useruser'
  6432. [2022-06-17 08:45:06.866495] WorkstationLen : 0x000c (12)
  6433. [2022-06-17 08:45:06.868139] WorkstationMaxLen : 0x000c (12)
  6434. [2022-06-17 08:45:06.869783] Workstation : *
  6435. [2022-06-17 08:45:06.871412] Workstation : 'LINUPS'
  6436. [2022-06-17 08:45:06.873094] EncryptedRandomSessionKeyLen: 0x0010 (16)
  6437. [2022-06-17 08:45:06.874776] EncryptedRandomSessionKeyMaxLen: 0x0010 (16)
  6438. [2022-06-17 08:45:06.876430] EncryptedRandomSessionKey: *
  6439. [2022-06-17 08:45:06.878064] EncryptedRandomSessionKey: DATA_BLOB length=16
  6440. [2022-06-17 08:45:06.879690] [0000] 83 1C E2 0E E1 3A DB C1 DB D0 CE A2 F9 70 23 09 .....:.. .....p#.
  6441. [2022-06-17 08:45:06.881339] NegotiateFlags : 0x62088215 (1644724757)
  6442. [2022-06-17 08:45:06.883009] 1: NTLMSSP_NEGOTIATE_UNICODE
  6443. [2022-06-17 08:45:06.884658] 0: NTLMSSP_NEGOTIATE_OEM
  6444. [2022-06-17 08:45:06.886320] 1: NTLMSSP_REQUEST_TARGET
  6445. [2022-06-17 08:45:06.887973] 1: NTLMSSP_NEGOTIATE_SIGN
  6446. [2022-06-17 08:45:06.889607] 0: NTLMSSP_NEGOTIATE_SEAL
  6447. [2022-06-17 08:45:06.891239] 0: NTLMSSP_NEGOTIATE_DATAGRAM
  6448. [2022-06-17 08:45:06.892910] 0: NTLMSSP_NEGOTIATE_LM_KEY
  6449. [2022-06-17 08:45:06.894570] 0: NTLMSSP_NEGOTIATE_NETWARE
  6450. [2022-06-17 08:45:06.896205] 1: NTLMSSP_NEGOTIATE_NTLM
  6451. [2022-06-17 08:45:06.897853] 0: NTLMSSP_NEGOTIATE_NT_ONLY
  6452. [2022-06-17 08:45:06.899493] 0: NTLMSSP_ANONYMOUS
  6453. [2022-06-17 08:45:06.901136] 0: NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED
  6454. [2022-06-17 08:45:06.902785] 0: NTLMSSP_NEGOTIATE_OEM_WORKSTATION_SUPPLIED
  6455. [2022-06-17 08:45:06.904512] 0: NTLMSSP_NEGOTIATE_THIS_IS_LOCAL_CALL
  6456. [2022-06-17 08:45:06.906160] 1: NTLMSSP_NEGOTIATE_ALWAYS_SIGN
  6457. [2022-06-17 08:45:06.907798] 0: NTLMSSP_TARGET_TYPE_DOMAIN
  6458. [2022-06-17 08:45:06.909444] 0: NTLMSSP_TARGET_TYPE_SERVER
  6459. [2022-06-17 08:45:06.911094] 0: NTLMSSP_TARGET_TYPE_SHARE
  6460. [2022-06-17 08:45:06.912733] 1: NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
  6461. [2022-06-17 08:45:06.914446] 0: NTLMSSP_NEGOTIATE_IDENTIFY
  6462. [2022-06-17 08:45:06.916080] 0: NTLMSSP_REQUEST_NON_NT_SESSION_KEY
  6463. [2022-06-17 08:45:06.917717] 0: NTLMSSP_NEGOTIATE_TARGET_INFO
  6464. [2022-06-17 08:45:06.919359] 1: NTLMSSP_NEGOTIATE_VERSION
  6465. [2022-06-17 08:45:06.921000] 1: NTLMSSP_NEGOTIATE_128
  6466. [2022-06-17 08:45:06.922642] 1: NTLMSSP_NEGOTIATE_KEY_EXCH
  6467. [2022-06-17 08:45:06.924368] 0: NTLMSSP_NEGOTIATE_56
  6468. [2022-06-17 08:45:06.925997] Version: struct ntlmssp_VERSION
  6469. [2022-06-17 08:45:06.927642] ProductMajorVersion : NTLMSSP_WINDOWS_MAJOR_VERSION_6 (6)
  6470. [2022-06-17 08:45:06.929291] ProductMinorVersion : NTLMSSP_WINDOWS_MINOR_VERSION_1 (1)
  6471. [2022-06-17 08:45:06.930948] ProductBuild : 0x0000 (0)
  6472. [2022-06-17 08:45:06.932588] Reserved: ARRAY(3)
  6473. [2022-06-17 08:45:06.934314] [0] : 0x00 (0)
  6474. [2022-06-17 08:45:06.935955] [1] : 0x00 (0)
  6475. [2022-06-17 08:45:06.937595] [2] : 0x00 (0)
  6476. [2022-06-17 08:45:06.939229] NTLMRevisionCurrent : NTLMSSP_REVISION_W2K3 (15)
  6477. [2022-06-17 08:45:06.940858] Got user=[useruser] domain=[WORKGROUP] workstation=[LINUPS] len1=24 len2=240
  6478. [2022-06-17 08:45:06.942519] short string '', sent with NULL termination despite NOTERM flag in IDL
  6479. [2022-06-17 08:45:06.944260] &v2_resp: struct NTLMv2_RESPONSE
  6480. [2022-06-17 08:45:06.945915] Response : 0305ee37d2c7dc4bf00f4b46a92ed7e5
  6481. [2022-06-17 08:45:06.947568] Challenge: struct NTLMv2_CLIENT_CHALLENGE
  6482. [2022-06-17 08:45:06.949206] RespType : 0x01 (1)
  6483. [2022-06-17 08:45:06.950832] HiRespType : 0x01 (1)
  6484. [2022-06-17 08:45:06.952471] Reserved1 : 0x0000 (0)
  6485. [2022-06-17 08:45:06.954188] Reserved2 : 0x00000000 (0)
  6486. [2022-06-17 08:45:06.955840] TimeStamp : Fri Jun 17 08:45:05 2022 UTC
  6487. [2022-06-17 08:45:06.957498] ChallengeFromClient : 019d29316206947a
  6488. [2022-06-17 08:45:06.959137] Reserved3 : 0x00000000 (0)
  6489. [2022-06-17 08:45:06.960772] AvPairs: struct AV_PAIR_LIST
  6490. [2022-06-17 08:45:06.962398] count : 0x0000000a (10)
  6491. [2022-06-17 08:45:06.964121] pair: ARRAY(10)
  6492. [2022-06-17 08:45:06.965756] pair: struct AV_PAIR
  6493. [2022-06-17 08:45:06.967384] AvId : MsvAvNbDomainName (0x2)
  6494. [2022-06-17 08:45:06.969026] AvLen : 0x000c (12)
  6495. [2022-06-17 08:45:06.970703] Value : union ntlmssp_AvValue(case 0x2)
  6496. [2022-06-17 08:45:06.972361] AvNbDomainName : 'ZALUPA'
  6497. [2022-06-17 08:45:06.974089] pair: struct AV_PAIR
  6498. [2022-06-17 08:45:06.975718] AvId : MsvAvNbComputerName (0x1)
  6499. [2022-06-17 08:45:06.977373] AvLen : 0x000c (12)
  6500. [2022-06-17 08:45:06.979008] Value : union ntlmssp_AvValue(case 0x1)
  6501. [2022-06-17 08:45:06.980659] AvNbComputerName : 'ZALUPA'
  6502. [2022-06-17 08:45:06.982306] pair: struct AV_PAIR
  6503. [2022-06-17 08:45:06.984057] AvId : MsvAvDnsDomainName (0x4)
  6504. [2022-06-17 08:45:06.985722] AvLen : 0x0002 (2)
  6505. [2022-06-17 08:45:06.987365] Value : union ntlmssp_AvValue(case 0x4)
  6506. [2022-06-17 08:45:06.989019] AvDnsDomainName : ''
  6507. [2022-06-17 08:45:06.990650] pair: struct AV_PAIR
  6508. [2022-06-17 08:45:06.992281] AvId : MsvAvDnsComputerName (0x3)
  6509. [2022-06-17 08:45:06.994002] AvLen : 0x0012 (18)
  6510. [2022-06-17 08:45:06.995668] Value : union ntlmssp_AvValue(case 0x3)
  6511. [2022-06-17 08:45:06.997332] AvDnsComputerName : 'localhost'
  6512. [2022-06-17 08:45:06.998990] pair: struct AV_PAIR
  6513. [2022-06-17 08:45:07.000622] AvId : MsvAvTimestamp (0x7)
  6514. [2022-06-17 08:45:07.002259] AvLen : 0x0008 (8)
  6515. [2022-06-17 08:45:07.012980] Value : union ntlmssp_AvValue(case 0x7)
  6516. [2022-06-17 08:45:07.014722] AvTimestamp : Fri Jun 17 08:45:05 2022 UTC
  6517. [2022-06-17 08:45:07.016423] pair: struct AV_PAIR
  6518. [2022-06-17 08:45:07.018076] AvId : MsvAvFlags (0x6)
  6519. [2022-06-17 08:45:07.019732] AvLen : 0x0004 (4)
  6520. [2022-06-17 08:45:07.021386] Value : union ntlmssp_AvValue(case 0x6)
  6521. [2022-06-17 08:45:07.023095] AvFlags : 0x00000002 (2)
  6522. [2022-06-17 08:45:07.026320] 0: NTLMSSP_AVFLAG_CONSTRAINTED_ACCOUNT
  6523. [2022-06-17 08:45:07.028002] 1: NTLMSSP_AVFLAG_MIC_IN_AUTHENTICATE_MESSAGE
  6524. [2022-06-17 08:45:07.029669] 0: NTLMSSP_AVFLAG_TARGET_SPN_FROM_UNTRUSTED_SOURCE
  6525. [2022-06-17 08:45:07.031333] pair: struct AV_PAIR
  6526. [2022-06-17 08:45:07.033017] AvId : MsvAvSingleHost (0x8)
  6527. [2022-06-17 08:45:07.034694] AvLen : 0x0030 (48)
  6528. [2022-06-17 08:45:07.036351] Value : union ntlmssp_AvValue(case 0x8)
  6529. [2022-06-17 08:45:07.038020] AvSingleHost: struct ntlmssp_SingleHostData
  6530. [2022-06-17 08:45:07.039653] Size : 0x00000030 (48)
  6531. [2022-06-17 08:45:07.041304] Z4 : 0x00000000 (0)
  6532. [2022-06-17 08:45:07.042992] token_info: struct LSAP_TOKEN_INFO_INTEGRITY
  6533. [2022-06-17 08:45:07.044657] Flags : 0x00000000 (0)
  6534. [2022-06-17 08:45:07.046314] TokenIL : 0x00000000 (0)
  6535. [2022-06-17 08:45:07.047951] MachineId : 0c18bd46c901a766bdee49fb89a32fb6e464fb01c742a218764a8d4d50d4f398
  6536. [2022-06-17 08:45:07.049617] remaining : DATA_BLOB length=0
  6537. [2022-06-17 08:45:07.051277] pair: struct AV_PAIR
  6538. [2022-06-17 08:45:07.052949] AvId : MsvChannelBindings (0xA)
  6539. [2022-06-17 08:45:07.054635] AvLen : 0x0010 (16)
  6540. [2022-06-17 08:45:07.062990] Value : union ntlmssp_AvValue(case 0xA)
  6541. [2022-06-17 08:45:07.064870] ChannelBindings : 00000000000000000000000000000000
  6542. [2022-06-17 08:45:07.066587] pair: struct AV_PAIR
  6543. [2022-06-17 08:45:07.068244] AvId : MsvAvTargetName (0x9)
  6544. [2022-06-17 08:45:07.073497] AvLen : 0x0024 (36)
  6545. [2022-06-17 08:45:07.075333] Value : union ntlmssp_AvValue(case 0x9)
  6546. [2022-06-17 08:45:07.077120] AvTargetName : 'cifs/192.168.1.250'
  6547. [2022-06-17 08:45:07.078810] pair: struct AV_PAIR
  6548. [2022-06-17 08:45:07.083444] AvId : MsvAvEOL (0x0)
  6549. [2022-06-17 08:45:07.085178] AvLen : 0x0000 (0)
  6550. [2022-06-17 08:45:07.086880] Value : union ntlmssp_AvValue(case 0x0)
  6551. [2022-06-17 08:45:07.089335] Mapping user [WORKGROUP]\[useruser] from workstation [LINUPS]
  6552. [2022-06-17 08:45:07.091042] attempting to make a user_info for useruser (useruser)
  6553. [2022-06-17 08:45:07.092718] making strings for useruser's user_info struct
  6554. [2022-06-17 08:45:07.094326] making blobs for useruser's user_info struct
  6555. [2022-06-17 08:45:07.096066] made a user_info for useruser (useruser)
  6556. [2022-06-17 08:45:07.097706] check_ntlm_password: Checking password for unmapped user [WORKGROUP]\[useruser]@[LINUPS] with the new password interface
  6557. [2022-06-17 08:45:07.099379] check_ntlm_password: mapped user is: [WORKGROUP]\[useruser]@[LINUPS]
  6558. [2022-06-17 08:45:07.101020] check_ntlm_password: auth_context challenge created by random
  6559. [2022-06-17 08:45:07.102681] challenge is:
  6560. [2022-06-17 08:45:07.104379] [0000] 35 24 94 12 CE 6F C3 18 5$...o..
  6561. [2022-06-17 08:45:07.106044] Check auth for: [useruser]
  6562. [2022-06-17 08:45:07.107675] auth_check_ntlm_password: anonymous had nothing to say
  6563. [2022-06-17 08:45:07.109305] auth_sam_ignoredomain_auth: Check auth for: [WORKGROUP]\[useruser]
  6564. [2022-06-17 08:45:07.110822] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  6565. [2022-06-17 08:45:07.112313] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  6566. [2022-06-17 08:45:07.113876] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  6567. [2022-06-17 08:45:07.115375] Security token: (NULL)
  6568. [2022-06-17 08:45:07.116848] UNIX token of user 0
  6569. [2022-06-17 08:45:07.118823] Primary group is 0 and contains 0 supplementary groups
  6570. [2022-06-17 08:45:07.120587] getsampwnam (smbpasswd): search by name: useruser
  6571. [2022-06-17 08:45:07.122247] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  6572. [2022-06-17 08:45:07.123937] getsmbfilepwent: skipping comment or blank line
  6573. [2022-06-17 08:45:07.125583] getsmbfilepwent: LM password for user nobody invalidated
  6574. [2022-06-17 08:45:07.127228] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  6575. [2022-06-17 08:45:07.128878] getsmbfilepwent: LM password for user useruser invalidated
  6576. [2022-06-17 08:45:07.130531] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  6577. [2022-06-17 08:45:07.132192] endsmbfilepwent_internal: closed password file.
  6578. [2022-06-17 08:45:07.133880] getsampwnam (smbpasswd): found by name: useruser
  6579. [2022-06-17 08:45:07.135533] Finding user useruser
  6580. [2022-06-17 08:45:07.137145] Trying _Get_Pwnam(), username as lowercase is useruser
  6581. [2022-06-17 08:45:07.138790] Get_Pwnam_internals did find user [useruser]!
  6582. [2022-06-17 08:45:07.140423] pdb_set_username: setting username useruser, was
  6583. [2022-06-17 08:45:07.142068] pdb_set_full_name: setting full name nobody, was
  6584. [2022-06-17 08:45:07.143770] pdb_set_domain: setting domain ZALUPA, was
  6585. [2022-06-17 08:45:07.145428] Home server: ZALUPA
  6586. [2022-06-17 08:45:07.147043] pdb_set_profile_path: setting profile path \\ZALUPA\useruser\profile, was
  6587. [2022-06-17 08:45:07.148684] Home server: ZALUPA
  6588. [2022-06-17 08:45:07.150293] pdb_set_homedir: setting home dir \\ZALUPA\useruser, was
  6589. [2022-06-17 08:45:07.151926] pdb_set_dir_drive: setting dir drive , was NULL
  6590. [2022-06-17 08:45:07.153621] pdb_set_logon_script: setting logon script , was
  6591. [2022-06-17 08:45:07.155277] pdb_set_user_sid: setting user sid S-1-5-21-3939785350-4027435424-1589595352-132066
  6592. [2022-06-17 08:45:07.156936] pdb_set_user_sid_from_rid:
  6593. [2022-06-17 08:45:07.158551] setting user sid S-1-5-21-3939785350-4027435424-1589595352-132066 from rid 132066
  6594. [2022-06-17 08:45:07.160210] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6595. [2022-06-17 08:45:07.161844] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6596. [2022-06-17 08:45:07.163516] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6597. [2022-06-17 08:45:07.165173] Security token: (NULL)
  6598. [2022-06-17 08:45:07.166802] UNIX token of user 0
  6599. [2022-06-17 08:45:07.168420] Primary group is 0 and contains 0 supplementary groups
  6600. [2022-06-17 08:45:07.170059] account_policy_get: name: maximum password age, val: -1
  6601. [2022-06-17 08:45:07.171704] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6602. [2022-06-17 08:45:07.173402] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6603. [2022-06-17 08:45:07.175061] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6604. [2022-06-17 08:45:07.176714] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6605. [2022-06-17 08:45:07.178241] Security token: (NULL)
  6606. [2022-06-17 08:45:07.180160] UNIX token of user 0
  6607. [2022-06-17 08:45:07.181809] Primary group is 0 and contains 0 supplementary groups
  6608. [2022-06-17 08:45:07.183509] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6609. [2022-06-17 08:45:07.185152] xid_to_sid: GID 65534 -> S-1-22-2-65534 fallback
  6610. [2022-06-17 08:45:07.186808] Forcing Primary Group to 'Domain Users' for useruser
  6611. [2022-06-17 08:45:07.188452] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6612. [2022-06-17 08:45:07.190081] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6613. [2022-06-17 08:45:07.191716] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6614. [2022-06-17 08:45:07.193406] Security token: (NULL)
  6615. [2022-06-17 08:45:07.195021] UNIX token of user 0
  6616. [2022-06-17 08:45:07.196634] Primary group is 0 and contains 0 supplementary groups
  6617. [2022-06-17 08:45:07.198261] account_policy_get: name: password history, val: 0
  6618. [2022-06-17 08:45:07.199895] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6619. [2022-06-17 08:45:07.201537] pdb_set_username: setting username useruser, was
  6620. [2022-06-17 08:45:07.203230] pdb_set_domain: setting domain ZALUPA, was
  6621. [2022-06-17 08:45:07.204871] pdb_set_nt_username: setting nt username , was
  6622. [2022-06-17 08:45:07.206514] pdb_set_full_name: setting full name nobody, was
  6623. [2022-06-17 08:45:07.208154] Home server: ZALUPA
  6624. [2022-06-17 08:45:07.209763] pdb_set_homedir: setting home dir \\ZALUPA\useruser, was
  6625. [2022-06-17 08:45:07.211384] pdb_set_dir_drive: setting dir drive , was NULL
  6626. [2022-06-17 08:45:07.213063] pdb_set_logon_script: setting logon script , was
  6627. [2022-06-17 08:45:07.214739] Home server: ZALUPA
  6628. [2022-06-17 08:45:07.216359] pdb_set_profile_path: setting profile path \\ZALUPA\useruser\profile, was
  6629. [2022-06-17 08:45:07.218009] pdb_set_workstations: setting workstations , was
  6630. [2022-06-17 08:45:07.219659] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6631. [2022-06-17 08:45:07.221292] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6632. [2022-06-17 08:45:07.222953] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6633. [2022-06-17 08:45:07.224587] Security token: (NULL)
  6634. [2022-06-17 08:45:07.226210] UNIX token of user 0
  6635. [2022-06-17 08:45:07.227839] Primary group is 0 and contains 0 supplementary groups
  6636. [2022-06-17 08:45:07.229474] account_policy_get: name: password history, val: 0
  6637. [2022-06-17 08:45:07.231104] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6638. [2022-06-17 08:45:07.232717] pdb_set_user_sid: setting user sid S-1-5-21-3939785350-4027435424-1589595352-132066
  6639. [2022-06-17 08:45:07.234432] pdb_set_user_sid_from_rid:
  6640. [2022-06-17 08:45:07.236056] setting user sid S-1-5-21-3939785350-4027435424-1589595352-132066 from rid 132066
  6641. [2022-06-17 08:45:07.237718] pdb_set_group_sid: setting group sid S-1-5-21-3939785350-4027435424-1589595352-513
  6642. [2022-06-17 08:45:07.239375] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  6643. [2022-06-17 08:45:07.241016] ntlm_password_check: Checking NTLMv2 password with domain [WORKGROUP]
  6644. [2022-06-17 08:45:07.242662] sam_account_ok: Checking SMB password for user useruser
  6645. [2022-06-17 08:45:07.244362] logon_hours_ok: user useruser allowed to logon at this time (Fri Jun 17 08:45:05 2022
  6646. [2022-06-17 08:45:07.246022] )
  6647. [2022-06-17 08:45:07.247638] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  6648. [2022-06-17 08:45:07.249279] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  6649. [2022-06-17 08:45:07.250914] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  6650. [2022-06-17 08:45:07.252553] Security token: (NULL)
  6651. [2022-06-17 08:45:07.254266] UNIX token of user 0
  6652. [2022-06-17 08:45:07.255894] Primary group is 0 and contains 0 supplementary groups
  6653. [2022-06-17 08:45:07.257532] account_policy_get: name: maximum password age, val: -1
  6654. [2022-06-17 08:45:07.259172] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  6655. [2022-06-17 08:45:07.260686] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  6656. [2022-06-17 08:45:07.262412] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  6657. [2022-06-17 08:45:07.264152] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  6658. [2022-06-17 08:45:07.265808] Security token: (NULL)
  6659. [2022-06-17 08:45:07.267419] UNIX token of user 0
  6660. [2022-06-17 08:45:07.269040] Primary group is 0 and contains 0 supplementary groups
  6661. [2022-06-17 08:45:07.270692] Finding user useruser
  6662. [2022-06-17 08:45:07.272312] Trying _Get_Pwnam(), username as lowercase is useruser
  6663. [2022-06-17 08:45:07.274045] Get_Pwnam_internals did find user [useruser]!
  6664. [2022-06-17 08:45:07.275695] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6665. [2022-06-17 08:45:07.277332] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6666. [2022-06-17 08:45:07.278969] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6667. [2022-06-17 08:45:07.280615] Security token: (NULL)
  6668. [2022-06-17 08:45:07.282223] UNIX token of user 0
  6669. [2022-06-17 08:45:07.283892] Primary group is 0 and contains 0 supplementary groups
  6670. [2022-06-17 08:45:07.285541] account_policy_get: name: minimum password age, val: 0
  6671. [2022-06-17 08:45:07.287178] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6672. [2022-06-17 08:45:07.288823] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6673. [2022-06-17 08:45:07.300917] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6674. [2022-06-17 08:45:07.302779] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6675. [2022-06-17 08:45:07.304567] Security token: (NULL)
  6676. [2022-06-17 08:45:07.306213] UNIX token of user 0
  6677. [2022-06-17 08:45:07.307840] Primary group is 0 and contains 0 supplementary groups
  6678. [2022-06-17 08:45:07.309512] account_policy_get: name: maximum password age, val: -1
  6679. [2022-06-17 08:45:07.311046] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6680. [2022-06-17 08:45:07.312548] Finding user useruser
  6681. [2022-06-17 08:45:07.314356] Trying _Get_Pwnam(), username as lowercase is useruser
  6682. [2022-06-17 08:45:07.316006] Get_Pwnam_internals did find user [useruser]!
  6683. [2022-06-17 08:45:07.317653] sys_getgrouplist: user [useruser]
  6684. [2022-06-17 08:45:07.319270] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 3
  6685. [2022-06-17 08:45:07.320892] push_conn_ctx(0) : conn_ctx_stack_ndx = 2
  6686. [2022-06-17 08:45:07.322529] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 3
  6687. [2022-06-17 08:45:07.324281] Security token: (NULL)
  6688. [2022-06-17 08:45:07.325921] UNIX token of user 0
  6689. [2022-06-17 08:45:07.327420] Primary group is 0 and contains 0 supplementary groups
  6690. [2022-06-17 08:45:07.329174] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 2
  6691. [2022-06-17 08:45:07.330806] xid_to_sid: GID 65534 -> S-1-22-2-65534 fallback
  6692. [2022-06-17 08:45:07.332449] make_server_info_sam: made server info for user useruser -> useruser
  6693. [2022-06-17 08:45:07.334172] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  6694. [2022-06-17 08:45:07.335824] auth_check_ntlm_password: sam_ignoredomain authentication for user [useruser] succeeded
  6695. [2022-06-17 08:45:07.337486] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  6696. [2022-06-17 08:45:07.339128] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  6697. [2022-06-17 08:45:07.340750] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  6698. [2022-06-17 08:45:07.342379] Security token: (NULL)
  6699. [2022-06-17 08:45:07.344199] UNIX token of user 0
  6700. [2022-06-17 08:45:07.345839] Primary group is 0 and contains 0 supplementary groups
  6701. [2022-06-17 08:45:07.347485] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  6702. [2022-06-17 08:45:07.349121] check_ntlm_password: PAM Account for user [useruser] succeeded
  6703. [2022-06-17 08:45:07.350765] Auth: [SMB2,(null)] user [WORKGROUP]\[useruser] at [Fri, 17 Jun 2022 08:45:05.322039 UTC] with [NTLMv2] status [NT_STATUS_OK] workstation [LINUPS] remote host [ipv4:192.168.1.10:33730] became [ZALUPA]\[useruser] [S-1-5-21-3939785350-4027435424-1589595352-132066]. local host [ipv4:192.168.1.250:445]
  6704. [2022-06-17 08:45:07.352541] log_no_json: JSON auth logs not available unless compiled with jansson
  6705. [2022-06-17 08:45:07.354327] check_ntlm_password: authentication for user [useruser] -> [useruser] -> [useruser] succeeded
  6706. [2022-06-17 08:45:07.356007] lp_load_ex: refreshing parameters
  6707. [2022-06-17 08:45:07.357650] Freeing parametrics:
  6708. [2022-06-17 08:45:07.359275] Initialising global parameters
  6709. [2022-06-17 08:45:07.360918] INFO: Current debug levels:
  6710. [2022-06-17 08:45:07.362535] all: 10
  6711. [2022-06-17 08:45:07.364246] tdb: 10
  6712. [2022-06-17 08:45:07.365862] printdrivers: 10
  6713. [2022-06-17 08:45:07.367490] lanman: 10
  6714. [2022-06-17 08:45:07.369105] smb: 10
  6715. [2022-06-17 08:45:07.370716] rpc_parse: 10
  6716. [2022-06-17 08:45:07.372329] rpc_srv: 10
  6717. [2022-06-17 08:45:07.374026] rpc_cli: 10
  6718. [2022-06-17 08:45:07.375637] passdb: 10
  6719. [2022-06-17 08:45:07.377240] sam: 10
  6720. [2022-06-17 08:45:07.378850] auth: 10
  6721. [2022-06-17 08:45:07.380459] winbind: 10
  6722. [2022-06-17 08:45:07.382071] vfs: 10
  6723. [2022-06-17 08:45:07.383744] idmap: 10
  6724. [2022-06-17 08:45:07.385354] quota: 10
  6725. [2022-06-17 08:45:07.386967] acls: 10
  6726. [2022-06-17 08:45:07.388568] locking: 10
  6727. [2022-06-17 08:45:07.390181] msdfs: 10
  6728. [2022-06-17 08:45:07.391777] dmapi: 10
  6729. [2022-06-17 08:45:07.393452] registry: 10
  6730. [2022-06-17 08:45:07.395093] scavenger: 10
  6731. [2022-06-17 08:45:07.396732] dns: 10
  6732. [2022-06-17 08:45:07.398348] ldb: 10
  6733. [2022-06-17 08:45:07.399950] tevent: 10
  6734. [2022-06-17 08:45:07.401545] auth_audit: 10
  6735. [2022-06-17 08:45:07.403208] auth_json_audit: 10
  6736. [2022-06-17 08:45:07.404839] kerberos: 10
  6737. [2022-06-17 08:45:07.406468] drs_repl: 10
  6738. [2022-06-17 08:45:07.408090] smb2: 10
  6739. [2022-06-17 08:45:07.409697] smb2_credits: 10
  6740. [2022-06-17 08:45:07.411292] dsdb_audit: 10
  6741. [2022-06-17 08:45:07.412934] dsdb_json_audit: 10
  6742. [2022-06-17 08:45:07.414575] dsdb_password_audit: 10
  6743. [2022-06-17 08:45:07.416190] dsdb_password_json_audit: 10
  6744. [2022-06-17 08:45:07.417821] dsdb_transaction_audit: 10
  6745. [2022-06-17 08:45:07.419459] dsdb_transaction_json_audit: 10
  6746. [2022-06-17 08:45:07.421093] dsdb_group_audit: 10
  6747. [2022-06-17 08:45:07.423450] dsdb_group_json_audit: 10
  6748. [2022-06-17 08:45:07.425090] Processing section "[global]"
  6749. [2022-06-17 08:45:07.426610] doing parameter netbios name = zalupa
  6750. [2022-06-17 08:45:07.428244] doing parameter interfaces = br-lan
  6751. [2022-06-17 08:45:07.429885] doing parameter server string = SASAm
  6752. [2022-06-17 08:45:07.431522] doing parameter unix charset = UTF-8
  6753. [2022-06-17 08:45:07.433216] doing parameter workgroup = WORKGROUP
  6754. [2022-06-17 08:45:07.434973] doing parameter log level = 2
  6755. [2022-06-17 08:45:07.436492] doing parameter bind interfaces only = yes
  6756. [2022-06-17 08:45:07.438121] doing parameter deadtime = 15
  6757. [2022-06-17 08:45:07.439850] doing parameter enable core files = no
  6758. [2022-06-17 08:45:07.441375] doing parameter security = user
  6759. [2022-06-17 08:45:07.443158] doing parameter debug timestamp = yes
  6760. [2022-06-17 08:45:07.444693] doing parameter invalid users = root
  6761. [2022-06-17 08:45:07.446322] doing parameter map to guest = Bad User
  6762. [2022-06-17 08:45:07.448056] doing parameter null passwords = yes
  6763. [2022-06-17 08:45:07.449577] lpcfg_do_global_parameter: WARNING: The "null passwords" option is deprecated
  6764. [2022-06-17 08:45:07.451227] doing parameter passdb backend = smbpasswd
  6765. [2022-06-17 08:45:07.452985] doing parameter socket options = IPTOS_LOWDELAY TCP_NODELAY
  6766. [2022-06-17 08:45:07.454534] doing parameter load printers = No
  6767. [2022-06-17 08:45:07.456287] doing parameter printcap name = /dev/null
  6768. [2022-06-17 08:45:07.457818] doing parameter disable spoolss = yes
  6769. [2022-06-17 08:45:07.459448] doing parameter printing = bsd
  6770. [2022-06-17 08:45:07.461068] doing parameter mdns name = mdns
  6771. [2022-06-17 08:45:07.462693] doing parameter veto files = /Thumbs.db/.DS_Store/._.DS_Store/.apdisk/
  6772. [2022-06-17 08:45:07.464496] doing parameter delete veto files = yes
  6773. [2022-06-17 08:45:07.466142] Processing section "[shr]"
  6774. [2022-06-17 08:45:07.467654] doing parameter path = /mnt/share/
  6775. [2022-06-17 08:45:07.469286] doing parameter create mask = 0666
  6776. [2022-06-17 08:45:07.470912] doing parameter directory mask = 0777
  6777. [2022-06-17 08:45:07.472632] doing parameter read only = no
  6778. [2022-06-17 08:45:07.474227] doing parameter guest ok = yes
  6779. [2022-06-17 08:45:07.475989] doing parameter vfs objects = io_uring
  6780. [2022-06-17 08:45:07.477624] pm_process() returned Yes
  6781. [2022-06-17 08:45:07.479250] lp_servicenumber: couldn't find homes
  6782. [2022-06-17 08:45:07.480773] adding IPC service
  6783. [2022-06-17 08:45:07.482406] auth3_check_password_send: Got NT session key of length 16
  6784. [2022-06-17 08:45:07.484124] auth3_check_password_send: Got LM session key of length 8
  6785. [2022-06-17 08:45:07.485768] gensec_update_send: ntlmssp[0xb516aac0]: subreq: 0xb5c2bc80
  6786. [2022-06-17 08:45:07.487415] gensec_update_send: spnego[0xb516a940]: subreq: 0xb5bf11e0
  6787. [2022-06-17 08:45:07.489057] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6788. [2022-06-17 08:45:07.490715] Create local NT token for useruser
  6789. [2022-06-17 08:45:07.492355] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: value=[65533:U]
  6790. [2022-06-17 08:45:07.494097] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: id=[65533], endptr=[:U]
  6791. [2022-06-17 08:45:07.495775] sid S-1-5-21-3939785350-4027435424-1589595352-132066 -> uid 65533
  6792. [2022-06-17 08:45:07.497520] sys_getgrouplist: user [useruser]
  6793. [2022-06-17 08:45:07.499149] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6794. [2022-06-17 08:45:07.500667] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6795. [2022-06-17 08:45:07.502311] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6796. [2022-06-17 08:45:07.504163] Security token: (NULL)
  6797. [2022-06-17 08:45:07.505788] UNIX token of user 0
  6798. [2022-06-17 08:45:07.507397] Primary group is 0 and contains 0 supplementary groups
  6799. [2022-06-17 08:45:07.508930] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6800. [2022-06-17 08:45:07.510561] xid_to_sid: GID 65534 -> S-1-22-2-65534 fallback
  6801. [2022-06-17 08:45:07.512196] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6802. [2022-06-17 08:45:07.514020] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6803. [2022-06-17 08:45:07.515554] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6804. [2022-06-17 08:45:07.517205] Security token: (NULL)
  6805. [2022-06-17 08:45:07.518922] UNIX token of user 0
  6806. [2022-06-17 08:45:07.520433] Primary group is 0 and contains 0 supplementary groups
  6807. [2022-06-17 08:45:07.522077] Failed to fetch domain sid for WORKGROUP
  6808. [2022-06-17 08:45:07.523747] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6809. [2022-06-17 08:45:07.525393] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6810. [2022-06-17 08:45:07.527145] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6811. [2022-06-17 08:45:07.528677] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6812. [2022-06-17 08:45:07.530323] Security token: (NULL)
  6813. [2022-06-17 08:45:07.531948] UNIX token of user 0
  6814. [2022-06-17 08:45:07.533621] Primary group is 0 and contains 0 supplementary groups
  6815. [2022-06-17 08:45:07.535282] Could not find map for sid S-1-5-32-544
  6816. [2022-06-17 08:45:07.536919] create_builtin_administrators: Failed to create Administrators
  6817. [2022-06-17 08:45:07.538598] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6818. [2022-06-17 08:45:07.540333] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6819. [2022-06-17 08:45:07.541858] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6820. [2022-06-17 08:45:07.543655] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6821. [2022-06-17 08:45:07.545309] Security token: (NULL)
  6822. [2022-06-17 08:45:07.546925] UNIX token of user 0
  6823. [2022-06-17 08:45:07.548430] Primary group is 0 and contains 0 supplementary groups
  6824. [2022-06-17 08:45:07.550064] Could not find map for sid S-1-5-32-545
  6825. [2022-06-17 08:45:07.551799] create_builtin_users: Failed to create Users
  6826. [2022-06-17 08:45:07.553379] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6827. [2022-06-17 08:45:07.555030] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6828. [2022-06-17 08:45:07.556671] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6829. [2022-06-17 08:45:07.559021] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6830. [2022-06-17 08:45:07.561127] Security token: (NULL)
  6831. [2022-06-17 08:45:07.563665] UNIX token of user 0
  6832. [2022-06-17 08:45:07.565254] Primary group is 0 and contains 0 supplementary groups
  6833. [2022-06-17 08:45:07.566941] Could not find map for sid S-1-5-32-546
  6834. [2022-06-17 08:45:07.568588] create_builtin_guests: Failed to create Guests
  6835. [2022-06-17 08:45:07.570222] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6836. [2022-06-17 08:45:07.572948] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6837. [2022-06-17 08:45:07.574532] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6838. [2022-06-17 08:45:07.576194] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6839. [2022-06-17 08:45:07.577857] Security token: (NULL)
  6840. [2022-06-17 08:45:07.579598] UNIX token of user 0
  6841. [2022-06-17 08:45:07.581699] Primary group is 0 and contains 0 supplementary groups
  6842. [2022-06-17 08:45:07.583775] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6843. [2022-06-17 08:45:07.585357] get_privileges: No privileges assigned to SID [S-1-5-21-3939785350-4027435424-1589595352-132066]
  6844. [2022-06-17 08:45:07.587035] get_privileges: No privileges assigned to SID [S-1-5-21-3939785350-4027435424-1589595352-513]
  6845. [2022-06-17 08:45:07.588712] get_privileges: No privileges assigned to SID [S-1-22-2-65534]
  6846. [2022-06-17 08:45:07.590679] get_privileges_for_sids: sid = S-1-1-0
  6847. [2022-06-17 08:45:07.592467] Privilege set: 0x0
  6848. [2022-06-17 08:45:07.594060] get_privileges: No privileges assigned to SID [S-1-5-2]
  6849. [2022-06-17 08:45:07.595578] get_privileges: No privileges assigned to SID [S-1-5-11]
  6850. [2022-06-17 08:45:07.597074] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: value=[65533:U]
  6851. [2022-06-17 08:45:07.598722] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: id=[65533], endptr=[:U]
  6852. [2022-06-17 08:45:07.600510] wbcSidsToUnixIds returned WBC_ERR_WINBIND_NOT_AVAILABLE
  6853. [2022-06-17 08:45:07.602151] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6854. [2022-06-17 08:45:07.603744] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6855. [2022-06-17 08:45:07.605496] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6856. [2022-06-17 08:45:07.607139] Security token: (NULL)
  6857. [2022-06-17 08:45:07.608746] UNIX token of user 0
  6858. [2022-06-17 08:45:07.610259] Primary group is 0 and contains 0 supplementary groups
  6859. [2022-06-17 08:45:07.612011] lookup_global_sam_rid: looking up RID 513.
  6860. [2022-06-17 08:45:07.613596] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  6861. [2022-06-17 08:45:07.615253] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  6862. [2022-06-17 08:45:07.616995] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  6863. [2022-06-17 08:45:07.618533] Security token: (NULL)
  6864. [2022-06-17 08:45:07.620152] UNIX token of user 0
  6865. [2022-06-17 08:45:07.621781] Primary group is 0 and contains 0 supplementary groups
  6866. [2022-06-17 08:45:07.623580] smbpasswd_getsampwrid: search by sid: S-1-5-21-3939785350-4027435424-1589595352-513
  6867. [2022-06-17 08:45:07.625138] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  6868. [2022-06-17 08:45:07.626866] getsmbfilepwent: skipping comment or blank line
  6869. [2022-06-17 08:45:07.628414] getsmbfilepwent: LM password for user nobody invalidated
  6870. [2022-06-17 08:45:07.630060] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  6871. [2022-06-17 08:45:07.631813] getsmbfilepwent: LM password for user useruser invalidated
  6872. [2022-06-17 08:45:07.633386] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  6873. [2022-06-17 08:45:07.635033] getsmbfilepwent: end of file reached.
  6874. [2022-06-17 08:45:07.636668] endsmbfilepwent_internal: closed password file.
  6875. [2022-06-17 08:45:07.643050] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  6876. [2022-06-17 08:45:07.644827] Can't find a unix id for an unmapped group
  6877. [2022-06-17 08:45:07.653473] SID S-1-5-21-3939785350-4027435424-1589595352-513 belongs to our domain, but there is no corresponding object in the database.
  6878. [2022-06-17 08:45:07.655311] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6879. [2022-06-17 08:45:07.657000] LEGACY: mapping failed for sid S-1-5-21-3939785350-4027435424-1589595352-513
  6880. [2022-06-17 08:45:07.658559] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6881. [2022-06-17 08:45:07.660203] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6882. [2022-06-17 08:45:07.661980] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6883. [2022-06-17 08:45:07.663585] Security token: (NULL)
  6884. [2022-06-17 08:45:07.665231] UNIX token of user 0
  6885. [2022-06-17 08:45:07.666967] Primary group is 0 and contains 0 supplementary groups
  6886. [2022-06-17 08:45:07.668503] lookup_global_sam_rid: looking up RID 513.
  6887. [2022-06-17 08:45:07.670236] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  6888. [2022-06-17 08:45:07.671842] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  6889. [2022-06-17 08:45:07.673530] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  6890. [2022-06-17 08:45:07.675082] Security token: (NULL)
  6891. [2022-06-17 08:45:07.676829] UNIX token of user 0
  6892. [2022-06-17 08:45:07.678336] Primary group is 0 and contains 0 supplementary groups
  6893. [2022-06-17 08:45:07.680086] smbpasswd_getsampwrid: search by sid: S-1-5-21-3939785350-4027435424-1589595352-513
  6894. [2022-06-17 08:45:07.681731] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  6895. [2022-06-17 08:45:07.683314] getsmbfilepwent: skipping comment or blank line
  6896. [2022-06-17 08:45:07.684954] getsmbfilepwent: LM password for user nobody invalidated
  6897. [2022-06-17 08:45:07.686627] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  6898. [2022-06-17 08:45:07.688278] getsmbfilepwent: LM password for user useruser invalidated
  6899. [2022-06-17 08:45:07.690030] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  6900. [2022-06-17 08:45:07.691714] getsmbfilepwent: end of file reached.
  6901. [2022-06-17 08:45:07.693407] endsmbfilepwent_internal: closed password file.
  6902. [2022-06-17 08:45:07.695070] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  6903. [2022-06-17 08:45:07.696725] Can't find a unix id for an unmapped group
  6904. [2022-06-17 08:45:07.698352] SID S-1-5-21-3939785350-4027435424-1589595352-513 belongs to our domain, but there is no corresponding object in the database.
  6905. [2022-06-17 08:45:07.700039] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6906. [2022-06-17 08:45:07.701685] LEGACY: mapping failed for sid S-1-5-21-3939785350-4027435424-1589595352-513
  6907. [2022-06-17 08:45:07.703509] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6908. [2022-06-17 08:45:07.705045] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6909. [2022-06-17 08:45:07.706684] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6910. [2022-06-17 08:45:07.708439] Security token: (NULL)
  6911. [2022-06-17 08:45:07.709943] UNIX token of user 0
  6912. [2022-06-17 08:45:07.711425] Primary group is 0 and contains 0 supplementary groups
  6913. [2022-06-17 08:45:07.713203] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6914. [2022-06-17 08:45:07.714747] LEGACY: mapping failed for sid S-1-1-0
  6915. [2022-06-17 08:45:07.716386] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6916. [2022-06-17 08:45:07.718008] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6917. [2022-06-17 08:45:07.719638] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6918. [2022-06-17 08:45:07.721293] Security token: (NULL)
  6919. [2022-06-17 08:45:07.723064] UNIX token of user 0
  6920. [2022-06-17 08:45:07.724598] Primary group is 0 and contains 0 supplementary groups
  6921. [2022-06-17 08:45:07.726340] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6922. [2022-06-17 08:45:07.727968] LEGACY: mapping failed for sid S-1-1-0
  6923. [2022-06-17 08:45:07.729491] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6924. [2022-06-17 08:45:07.731113] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6925. [2022-06-17 08:45:07.732736] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6926. [2022-06-17 08:45:07.734425] Security token: (NULL)
  6927. [2022-06-17 08:45:07.736051] UNIX token of user 0
  6928. [2022-06-17 08:45:07.737789] Primary group is 0 and contains 0 supplementary groups
  6929. [2022-06-17 08:45:07.739419] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6930. [2022-06-17 08:45:07.740937] LEGACY: mapping failed for sid S-1-5-2
  6931. [2022-06-17 08:45:07.742584] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6932. [2022-06-17 08:45:07.744283] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6933. [2022-06-17 08:45:07.745920] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6934. [2022-06-17 08:45:07.747577] Security token: (NULL)
  6935. [2022-06-17 08:45:07.749222] UNIX token of user 0
  6936. [2022-06-17 08:45:07.750838] Primary group is 0 and contains 0 supplementary groups
  6937. [2022-06-17 08:45:07.752574] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6938. [2022-06-17 08:45:07.754168] LEGACY: mapping failed for sid S-1-5-2
  6939. [2022-06-17 08:45:07.755802] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6940. [2022-06-17 08:45:07.757434] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6941. [2022-06-17 08:45:07.759162] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6942. [2022-06-17 08:45:07.760682] Security token: (NULL)
  6943. [2022-06-17 08:45:07.762310] UNIX token of user 0
  6944. [2022-06-17 08:45:07.764020] Primary group is 0 and contains 0 supplementary groups
  6945. [2022-06-17 08:45:07.765661] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6946. [2022-06-17 08:45:07.767301] LEGACY: mapping failed for sid S-1-5-11
  6947. [2022-06-17 08:45:07.768927] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  6948. [2022-06-17 08:45:07.770548] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  6949. [2022-06-17 08:45:07.772187] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  6950. [2022-06-17 08:45:07.774018] Security token: (NULL)
  6951. [2022-06-17 08:45:07.775650] UNIX token of user 0
  6952. [2022-06-17 08:45:07.777166] Primary group is 0 and contains 0 supplementary groups
  6953. [2022-06-17 08:45:07.778665] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  6954. [2022-06-17 08:45:07.780414] LEGACY: mapping failed for sid S-1-5-11
  6955. [2022-06-17 08:45:07.781938] Could not convert SID S-1-5-21-3939785350-4027435424-1589595352-513 to gid, ignoring it
  6956. [2022-06-17 08:45:07.783756] Could not convert SID S-1-1-0 to gid, ignoring it
  6957. [2022-06-17 08:45:07.785303] Could not convert SID S-1-5-2 to gid, ignoring it
  6958. [2022-06-17 08:45:07.786951] Could not convert SID S-1-5-11 to gid, ignoring it
  6959. [2022-06-17 08:45:07.788596] Security token SIDs (7):
  6960. [2022-06-17 08:45:07.790212] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-132066
  6961. [2022-06-17 08:45:07.791965] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-513
  6962. [2022-06-17 08:45:07.793650] SID[ 2]: S-1-22-2-65534
  6963. [2022-06-17 08:45:07.795167] SID[ 3]: S-1-1-0
  6964. [2022-06-17 08:45:07.796783] SID[ 4]: S-1-5-2
  6965. [2022-06-17 08:45:07.798409] SID[ 5]: S-1-5-11
  6966. [2022-06-17 08:45:07.800131] SID[ 6]: S-1-22-1-65533
  6967. [2022-06-17 08:45:07.801627] Privileges (0x 0):
  6968. [2022-06-17 08:45:07.803298] Rights (0x 0):
  6969. [2022-06-17 08:45:07.805052] UNIX token of user 65533
  6970. [2022-06-17 08:45:07.806569] Primary group is 65534 and contains 1 supplementary groups
  6971. [2022-06-17 08:45:07.808219] Group[ 0]: 65534
  6972. [2022-06-17 08:45:07.809701] ntlmssp_server_auth: Using unmodified nt session key.
  6973. [2022-06-17 08:45:07.811452] NTLMSSP Sign/Seal - Initialising with flags:
  6974. [2022-06-17 08:45:07.813022] Got NTLMSSP neg_flags=0x62088215
  6975. [2022-06-17 08:45:07.814675] NTLMSSP_NEGOTIATE_UNICODE
  6976. [2022-06-17 08:45:07.816294] NTLMSSP_REQUEST_TARGET
  6977. [2022-06-17 08:45:07.817902] NTLMSSP_NEGOTIATE_SIGN
  6978. [2022-06-17 08:45:07.819633] NTLMSSP_NEGOTIATE_NTLM
  6979. [2022-06-17 08:45:07.821147] NTLMSSP_NEGOTIATE_ALWAYS_SIGN
  6980. [2022-06-17 08:45:07.822774] NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
  6981. [2022-06-17 08:45:07.824499] NTLMSSP_NEGOTIATE_VERSION
  6982. [2022-06-17 08:45:07.826126] NTLMSSP_NEGOTIATE_128
  6983. [2022-06-17 08:45:07.827760] NTLMSSP_NEGOTIATE_KEY_EXCH
  6984. [2022-06-17 08:45:07.829370] dump_arc4_state: NTLMSSP send seal arc4 state:
  6985. [2022-06-17 08:45:07.830988]
  6986. [2022-06-17 08:45:07.832611] dump_arc4_state: NTLMSSP recv seal arc4 state:
  6987. [2022-06-17 08:45:07.834355]
  6988. [2022-06-17 08:45:07.836087] gensec_update_done: ntlmssp[0xb516aac0]: NT_STATUS_OK tevent_req[0xb5c2bc80/../../auth/ntlmssp/ntlmssp.c:181]: state[2] error[0 (0x0)] state[struct gensec_ntlmssp_update_state (0xb5c2bd60)] timer[0] finish[../../auth/ntlmssp/ntlmssp.c:244]
  6989. [2022-06-17 08:45:07.837722] ntlmssp_check_packet: NTLMSSP signature OK !
  6990. [2022-06-17 08:45:07.839457] NTLMSSP Sign/Seal - Initialising with flags:
  6991. [2022-06-17 08:45:07.840985] Got NTLMSSP neg_flags=0x62088215
  6992. [2022-06-17 08:45:07.842634] NTLMSSP_NEGOTIATE_UNICODE
  6993. [2022-06-17 08:45:07.844325] NTLMSSP_REQUEST_TARGET
  6994. [2022-06-17 08:45:07.845975] NTLMSSP_NEGOTIATE_SIGN
  6995. [2022-06-17 08:45:07.847588] NTLMSSP_NEGOTIATE_NTLM
  6996. [2022-06-17 08:45:07.849218] NTLMSSP_NEGOTIATE_ALWAYS_SIGN
  6997. [2022-06-17 08:45:07.850958] NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
  6998. [2022-06-17 08:45:07.852488] NTLMSSP_NEGOTIATE_VERSION
  6999. [2022-06-17 08:45:07.854177] NTLMSSP_NEGOTIATE_128
  7000. [2022-06-17 08:45:07.855784] NTLMSSP_NEGOTIATE_KEY_EXCH
  7001. [2022-06-17 08:45:07.857551] dump_arc4_state: NTLMSSP send seal arc4 state:
  7002. [2022-06-17 08:45:07.859088]
  7003. [2022-06-17 08:45:07.860701] dump_arc4_state: NTLMSSP recv seal arc4 state:
  7004. [2022-06-17 08:45:07.862333]
  7005. [2022-06-17 08:45:07.864171] gensec_update_done: spnego[0xb516a940]: NT_STATUS_OK tevent_req[0xb5bf11e0/../../auth/gensec/spnego.c:1632]: state[2] error[0 (0x0)] state[struct gensec_spnego_update_state (0xb5bf12c0)] timer[0] finish[../../auth/gensec/spnego.c:2116]
  7006. [2022-06-17 08:45:07.865808] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7007. [2022-06-17 08:45:07.867451] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7008. [2022-06-17 08:45:07.869090] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7009. [2022-06-17 08:45:07.870748] Security token: (NULL)
  7010. [2022-06-17 08:45:07.872477] UNIX token of user 0
  7011. [2022-06-17 08:45:07.874141] Primary group is 0 and contains 0 supplementary groups
  7012. [2022-06-17 08:45:07.875671] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7013. [2022-06-17 08:45:07.877324] Create local NT token for useruser
  7014. [2022-06-17 08:45:07.878958] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: value=[65533:U]
  7015. [2022-06-17 08:45:07.880487] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: id=[65533], endptr=[:U]
  7016. [2022-06-17 08:45:07.882205] sid S-1-5-21-3939785350-4027435424-1589595352-132066 -> uid 65533
  7017. [2022-06-17 08:45:07.883789] sys_getgrouplist: user [useruser]
  7018. [2022-06-17 08:45:07.885431] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7019. [2022-06-17 08:45:07.887074] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7020. [2022-06-17 08:45:07.888702] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7021. [2022-06-17 08:45:07.890333] Security token: (NULL)
  7022. [2022-06-17 08:45:07.891943] UNIX token of user 0
  7023. [2022-06-17 08:45:07.893639] Primary group is 0 and contains 0 supplementary groups
  7024. [2022-06-17 08:45:07.895292] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7025. [2022-06-17 08:45:07.897030] xid_to_sid: GID 65534 -> S-1-22-2-65534 fallback
  7026. [2022-06-17 08:45:07.898549] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7027. [2022-06-17 08:45:07.900179] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7028. [2022-06-17 08:45:07.901808] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7029. [2022-06-17 08:45:07.903589] Security token: (NULL)
  7030. [2022-06-17 08:45:07.905105] UNIX token of user 0
  7031. [2022-06-17 08:45:07.906737] Primary group is 0 and contains 0 supplementary groups
  7032. [2022-06-17 08:45:07.908484] Failed to fetch domain sid for WORKGROUP
  7033. [2022-06-17 08:45:07.909998] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7034. [2022-06-17 08:45:07.911490] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7035. [2022-06-17 08:45:07.913165] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7036. [2022-06-17 08:45:07.914912] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7037. [2022-06-17 08:45:07.916455] Security token: (NULL)
  7038. [2022-06-17 08:45:07.918078] UNIX token of user 0
  7039. [2022-06-17 08:45:07.919703] Primary group is 0 and contains 0 supplementary groups
  7040. [2022-06-17 08:45:07.921339] Could not find map for sid S-1-5-32-544
  7041. [2022-06-17 08:45:07.923027] create_builtin_administrators: Failed to create Administrators
  7042. [2022-06-17 08:45:07.924693] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7043. [2022-06-17 08:45:07.926337] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7044. [2022-06-17 08:45:07.927949] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7045. [2022-06-17 08:45:07.929694] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7046. [2022-06-17 08:45:07.931224] Security token: (NULL)
  7047. [2022-06-17 08:45:07.932841] UNIX token of user 0
  7048. [2022-06-17 08:45:07.934504] Primary group is 0 and contains 0 supplementary groups
  7049. [2022-06-17 08:45:07.936145] Could not find map for sid S-1-5-32-545
  7050. [2022-06-17 08:45:07.937879] create_builtin_users: Failed to create Users
  7051. [2022-06-17 08:45:07.939513] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7052. [2022-06-17 08:45:07.941136] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7053. [2022-06-17 08:45:07.942666] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7054. [2022-06-17 08:45:07.944476] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7055. [2022-06-17 08:45:07.946009] Security token: (NULL)
  7056. [2022-06-17 08:45:07.947628] UNIX token of user 0
  7057. [2022-06-17 08:45:07.949255] Primary group is 0 and contains 0 supplementary groups
  7058. [2022-06-17 08:45:07.950904] Could not find map for sid S-1-5-32-546
  7059. [2022-06-17 08:45:07.952544] create_builtin_guests: Failed to create Guests
  7060. [2022-06-17 08:45:07.954241] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7061. [2022-06-17 08:45:07.955879] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7062. [2022-06-17 08:45:07.957513] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7063. [2022-06-17 08:45:07.959146] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7064. [2022-06-17 08:45:07.960776] Security token: (NULL)
  7065. [2022-06-17 08:45:07.965598] UNIX token of user 0
  7066. [2022-06-17 08:45:07.973541] Primary group is 0 and contains 0 supplementary groups
  7067. [2022-06-17 08:45:07.975367] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7068. [2022-06-17 08:45:07.977045] get_privileges: No privileges assigned to SID [S-1-5-21-3939785350-4027435424-1589595352-132066]
  7069. [2022-06-17 08:45:07.978731] get_privileges: No privileges assigned to SID [S-1-5-21-3939785350-4027435424-1589595352-513]
  7070. [2022-06-17 08:45:07.980500] get_privileges: No privileges assigned to SID [S-1-22-2-65534]
  7071. [2022-06-17 08:45:07.984305] get_privileges_for_sids: sid = S-1-1-0
  7072. [2022-06-17 08:45:07.986079] Privilege set: 0x0
  7073. [2022-06-17 08:45:07.987794] get_privileges: No privileges assigned to SID [S-1-5-2]
  7074. [2022-06-17 08:45:07.989590] get_privileges: No privileges assigned to SID [S-1-5-11]
  7075. [2022-06-17 08:45:07.991148] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: value=[65533:U]
  7076. [2022-06-17 08:45:07.992984] Parsing value for key [IDMAP/SID2XID/S-1-5-21-3939785350-4027435424-1589595352-132066]: id=[65533], endptr=[:U]
  7077. [2022-06-17 08:45:07.994575] wbcSidsToUnixIds returned WBC_ERR_WINBIND_NOT_AVAILABLE
  7078. [2022-06-17 08:45:07.996228] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7079. [2022-06-17 08:45:07.997866] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7080. [2022-06-17 08:45:07.999605] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7081. [2022-06-17 08:45:08.001133] Security token: (NULL)
  7082. [2022-06-17 08:45:08.002754] UNIX token of user 0
  7083. [2022-06-17 08:45:08.004442] Primary group is 0 and contains 0 supplementary groups
  7084. [2022-06-17 08:45:08.006089] lookup_global_sam_rid: looking up RID 513.
  7085. [2022-06-17 08:45:08.007814] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  7086. [2022-06-17 08:45:08.009327] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  7087. [2022-06-17 08:45:08.011069] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  7088. [2022-06-17 08:45:08.012597] Security token: (NULL)
  7089. [2022-06-17 08:45:08.014299] UNIX token of user 0
  7090. [2022-06-17 08:45:08.016063] Primary group is 0 and contains 0 supplementary groups
  7091. [2022-06-17 08:45:08.017609] smbpasswd_getsampwrid: search by sid: S-1-5-21-3939785350-4027435424-1589595352-513
  7092. [2022-06-17 08:45:08.019368] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  7093. [2022-06-17 08:45:08.021005] getsmbfilepwent: skipping comment or blank line
  7094. [2022-06-17 08:45:08.022525] getsmbfilepwent: LM password for user nobody invalidated
  7095. [2022-06-17 08:45:08.024340] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  7096. [2022-06-17 08:45:08.025884] getsmbfilepwent: LM password for user useruser invalidated
  7097. [2022-06-17 08:45:08.027526] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  7098. [2022-06-17 08:45:08.029184] getsmbfilepwent: end of file reached.
  7099. [2022-06-17 08:45:08.030924] endsmbfilepwent_internal: closed password file.
  7100. [2022-06-17 08:45:08.032455] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  7101. [2022-06-17 08:45:08.034269] Can't find a unix id for an unmapped group
  7102. [2022-06-17 08:45:08.035793] SID S-1-5-21-3939785350-4027435424-1589595352-513 belongs to our domain, but there is no corresponding object in the database.
  7103. [2022-06-17 08:45:08.037483] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7104. [2022-06-17 08:45:08.039225] LEGACY: mapping failed for sid S-1-5-21-3939785350-4027435424-1589595352-513
  7105. [2022-06-17 08:45:08.040771] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7106. [2022-06-17 08:45:08.042405] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7107. [2022-06-17 08:45:08.044137] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7108. [2022-06-17 08:45:08.045897] Security token: (NULL)
  7109. [2022-06-17 08:45:08.047501] UNIX token of user 0
  7110. [2022-06-17 08:45:08.049005] Primary group is 0 and contains 0 supplementary groups
  7111. [2022-06-17 08:45:08.050644] lookup_global_sam_rid: looking up RID 513.
  7112. [2022-06-17 08:45:08.052277] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  7113. [2022-06-17 08:45:08.053978] push_conn_ctx(0) : conn_ctx_stack_ndx = 1
  7114. [2022-06-17 08:45:08.055628] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  7115. [2022-06-17 08:45:08.057276] Security token: (NULL)
  7116. [2022-06-17 08:45:08.058888] UNIX token of user 0
  7117. [2022-06-17 08:45:08.060490] Primary group is 0 and contains 0 supplementary groups
  7118. [2022-06-17 08:45:08.062114] smbpasswd_getsampwrid: search by sid: S-1-5-21-3939785350-4027435424-1589595352-513
  7119. [2022-06-17 08:45:08.063809] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  7120. [2022-06-17 08:45:08.065581] getsmbfilepwent: skipping comment or blank line
  7121. [2022-06-17 08:45:08.067109] getsmbfilepwent: LM password for user nobody invalidated
  7122. [2022-06-17 08:45:08.068744] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  7123. [2022-06-17 08:45:08.070575] getsmbfilepwent: LM password for user useruser invalidated
  7124. [2022-06-17 08:45:08.072121] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  7125. [2022-06-17 08:45:08.073811] getsmbfilepwent: end of file reached.
  7126. [2022-06-17 08:45:08.075561] endsmbfilepwent_internal: closed password file.
  7127. [2022-06-17 08:45:08.077093] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  7128. [2022-06-17 08:45:08.078833] Can't find a unix id for an unmapped group
  7129. [2022-06-17 08:45:08.080449] SID S-1-5-21-3939785350-4027435424-1589595352-513 belongs to our domain, but there is no corresponding object in the database.
  7130. [2022-06-17 08:45:08.082115] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7131. [2022-06-17 08:45:08.083701] LEGACY: mapping failed for sid S-1-5-21-3939785350-4027435424-1589595352-513
  7132. [2022-06-17 08:45:08.085371] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7133. [2022-06-17 08:45:08.086887] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7134. [2022-06-17 08:45:08.088382] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7135. [2022-06-17 08:45:08.089883] Security token: (NULL)
  7136. [2022-06-17 08:45:08.091350] UNIX token of user 0
  7137. [2022-06-17 08:45:08.092819] Primary group is 0 and contains 0 supplementary groups
  7138. [2022-06-17 08:45:08.094388] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7139. [2022-06-17 08:45:08.095876] LEGACY: mapping failed for sid S-1-1-0
  7140. [2022-06-17 08:45:08.097716] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7141. [2022-06-17 08:45:08.099261] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7142. [2022-06-17 08:45:08.101017] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7143. [2022-06-17 08:45:08.102652] Security token: (NULL)
  7144. [2022-06-17 08:45:08.104228] UNIX token of user 0
  7145. [2022-06-17 08:45:08.105956] Primary group is 0 and contains 0 supplementary groups
  7146. [2022-06-17 08:45:08.107598] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7147. [2022-06-17 08:45:08.109130] LEGACY: mapping failed for sid S-1-1-0
  7148. [2022-06-17 08:45:08.110772] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7149. [2022-06-17 08:45:08.112411] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7150. [2022-06-17 08:45:08.114216] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7151. [2022-06-17 08:45:08.115757] Security token: (NULL)
  7152. [2022-06-17 08:45:08.117375] UNIX token of user 0
  7153. [2022-06-17 08:45:08.118993] Primary group is 0 and contains 0 supplementary groups
  7154. [2022-06-17 08:45:08.120638] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7155. [2022-06-17 08:45:08.122388] LEGACY: mapping failed for sid S-1-5-2
  7156. [2022-06-17 08:45:08.124004] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7157. [2022-06-17 08:45:08.125756] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7158. [2022-06-17 08:45:08.127287] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7159. [2022-06-17 08:45:08.128923] Security token: (NULL)
  7160. [2022-06-17 08:45:08.130541] UNIX token of user 0
  7161. [2022-06-17 08:45:08.132146] Primary group is 0 and contains 0 supplementary groups
  7162. [2022-06-17 08:45:08.133713] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7163. [2022-06-17 08:45:08.135494] LEGACY: mapping failed for sid S-1-5-2
  7164. [2022-06-17 08:45:08.137039] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7165. [2022-06-17 08:45:08.138676] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7166. [2022-06-17 08:45:08.140403] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7167. [2022-06-17 08:45:08.141934] Security token: (NULL)
  7168. [2022-06-17 08:45:08.143606] UNIX token of user 0
  7169. [2022-06-17 08:45:08.145355] Primary group is 0 and contains 0 supplementary groups
  7170. [2022-06-17 08:45:08.147007] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7171. [2022-06-17 08:45:08.148534] LEGACY: mapping failed for sid S-1-5-11
  7172. [2022-06-17 08:45:08.150170] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7173. [2022-06-17 08:45:08.151921] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7174. [2022-06-17 08:45:08.153613] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7175. [2022-06-17 08:45:08.155150] Security token: (NULL)
  7176. [2022-06-17 08:45:08.156774] UNIX token of user 0
  7177. [2022-06-17 08:45:08.158397] Primary group is 0 and contains 0 supplementary groups
  7178. [2022-06-17 08:45:08.160041] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7179. [2022-06-17 08:45:08.161545] LEGACY: mapping failed for sid S-1-5-11
  7180. [2022-06-17 08:45:08.163239] Could not convert SID S-1-5-21-3939785350-4027435424-1589595352-513 to gid, ignoring it
  7181. [2022-06-17 08:45:08.165019] Could not convert SID S-1-1-0 to gid, ignoring it
  7182. [2022-06-17 08:45:08.166560] Could not convert SID S-1-5-2 to gid, ignoring it
  7183. [2022-06-17 08:45:08.168204] Could not convert SID S-1-5-11 to gid, ignoring it
  7184. [2022-06-17 08:45:08.169861] Security token SIDs (7):
  7185. [2022-06-17 08:45:08.171497] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-132066
  7186. [2022-06-17 08:45:08.173188] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-513
  7187. [2022-06-17 08:45:08.174949] SID[ 2]: S-1-22-2-65534
  7188. [2022-06-17 08:45:08.176457] SID[ 3]: S-1-1-0
  7189. [2022-06-17 08:45:08.178059] SID[ 4]: S-1-5-2
  7190. [2022-06-17 08:45:08.179773] SID[ 5]: S-1-5-11
  7191. [2022-06-17 08:45:08.181280] SID[ 6]: S-1-22-1-65533
  7192. [2022-06-17 08:45:08.183039] Privileges (0x 0):
  7193. [2022-06-17 08:45:08.184573] Rights (0x 0):
  7194. [2022-06-17 08:45:08.186212] UNIX token of user 65533
  7195. [2022-06-17 08:45:08.187936] Primary group is 65534 and contains 1 supplementary groups
  7196. [2022-06-17 08:45:08.189450] Group[ 0]: 65534
  7197. [2022-06-17 08:45:08.191061] Successful AuthZ: [SMB2,NTLMSSP] user [ZALUPA]\[useruser] [S-1-5-21-3939785350-4027435424-1589595352-132066] at [Fri, 17 Jun 2022 08:45:05.840234 UTC] Remote host [ipv4:192.168.1.10:33730] local host [ipv4:192.168.1.250:445]
  7198. [2022-06-17 08:45:08.192803] lp_servicenumber: couldn't find useruser
  7199. [2022-06-17 08:45:08.194738] Finding user useruser
  7200. [2022-06-17 08:45:08.196264] Trying _Get_Pwnam(), username as lowercase is useruser
  7201. [2022-06-17 08:45:08.197782] Get_Pwnam_internals did find user [useruser]!
  7202. [2022-06-17 08:45:08.199273] Adding homes service for user 'useruser' using home directory: '/var'
  7203. [2022-06-17 08:45:08.200775] lp_servicenumber: couldn't find homes
  7204. [2022-06-17 08:45:08.202260] INFO: Current debug levels:
  7205. [2022-06-17 08:45:08.203775] all: 10
  7206. [2022-06-17 08:45:08.205258] tdb: 10
  7207. [2022-06-17 08:45:08.206730] printdrivers: 10
  7208. [2022-06-17 08:45:08.208204] lanman: 10
  7209. [2022-06-17 08:45:08.209878] smb: 10
  7210. [2022-06-17 08:45:08.211366] rpc_parse: 10
  7211. [2022-06-17 08:45:08.212840] rpc_srv: 10
  7212. [2022-06-17 08:45:08.214367] rpc_cli: 10
  7213. [2022-06-17 08:45:08.215851] passdb: 10
  7214. [2022-06-17 08:45:08.217345] sam: 10
  7215. [2022-06-17 08:45:08.218825] auth: 10
  7216. [2022-06-17 08:45:08.220295] winbind: 10
  7217. [2022-06-17 08:45:08.221768] vfs: 10
  7218. [2022-06-17 08:45:08.223278] idmap: 10
  7219. [2022-06-17 08:45:08.224981] quota: 10
  7220. [2022-06-17 08:45:08.226480] acls: 10
  7221. [2022-06-17 08:45:08.227960] locking: 10
  7222. [2022-06-17 08:45:08.229436] msdfs: 10
  7223. [2022-06-17 08:45:08.230893] dmapi: 10
  7224. [2022-06-17 08:45:08.232355] registry: 10
  7225. [2022-06-17 08:45:08.233907] scavenger: 10
  7226. [2022-06-17 08:45:08.235379] dns: 10
  7227. [2022-06-17 08:45:08.236851] ldb: 10
  7228. [2022-06-17 08:45:08.238324] tevent: 10
  7229. [2022-06-17 08:45:08.239979] auth_audit: 10
  7230. [2022-06-17 08:45:08.241473] auth_json_audit: 10
  7231. [2022-06-17 08:45:08.242983] kerberos: 10
  7232. [2022-06-17 08:45:08.244477] drs_repl: 10
  7233. [2022-06-17 08:45:08.245955] smb2: 10
  7234. [2022-06-17 08:45:08.247421] smb2_credits: 10
  7235. [2022-06-17 08:45:08.248893] dsdb_audit: 10
  7236. [2022-06-17 08:45:08.251056] dsdb_json_audit: 10
  7237. [2022-06-17 08:45:08.252606] dsdb_password_audit: 10
  7238. [2022-06-17 08:45:08.254310] dsdb_password_json_audit: 10
  7239. [2022-06-17 08:45:08.256053] dsdb_transaction_audit: 10
  7240. [2022-06-17 08:45:08.257574] dsdb_transaction_json_audit: 10
  7241. [2022-06-17 08:45:08.259190] dsdb_group_audit: 10
  7242. [2022-06-17 08:45:08.260920] dsdb_group_json_audit: 10
  7243. [2022-06-17 08:45:08.262435] lp_file_list_changed()
  7244. [2022-06-17 08:45:08.264128] file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Fri Jun 17 08:38:04 2022
  7245. [2022-06-17 08:45:08.265901]
  7246. [2022-06-17 08:45:08.267501] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  7247. [2022-06-17 08:45:08.269041] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  7248. [2022-06-17 08:45:08.270544] db_tdb_log_key: Locking key 6F1A4B46
  7249. [2022-06-17 08:45:08.272034] db_tdb_fetch_locked_internal: Allocated locked data 0xb5ef4cc0
  7250. [2022-06-17 08:45:08.273590] dbwrap_watched_subrec_wakeup_fn: No watchers
  7251. [2022-06-17 08:45:08.275105] smbXsrv_session_global_store: key '6F1A4B46' stored
  7252. [2022-06-17 08:45:08.276604] &global_blob: struct smbXsrv_session_globalB
  7253. [2022-06-17 08:45:08.278098] version : SMBXSRV_VERSION_0 (0)
  7254. [2022-06-17 08:45:08.279596] seqnum : 0x00000005 (5)
  7255. [2022-06-17 08:45:08.281083] info : union smbXsrv_session_globalU(case 0)
  7256. [2022-06-17 08:45:08.282575] info0 : *
  7257. [2022-06-17 08:45:08.284480] info0: struct smbXsrv_session_global0
  7258. [2022-06-17 08:45:08.286146] db_rec : *
  7259. [2022-06-17 08:45:08.287912] session_global_id : 0x6f1a4b46 (1863994182)
  7260. [2022-06-17 08:45:08.289560] session_wire_id : 0x000000006f1a4b46 (1863994182)
  7261. [2022-06-17 08:45:08.294248] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7262. [2022-06-17 08:45:08.303732] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  7263. [2022-06-17 08:45:08.305434] auth_time : Fri Jun 17 08:45:05 2022 UTC
  7264. [2022-06-17 08:45:08.307140] auth_session_info_seqnum : 0x00000001 (1)
  7265. [2022-06-17 08:45:08.308934] auth_session_info : *
  7266. [2022-06-17 08:45:08.310484] auth_session_info: struct auth_session_info
  7267. [2022-06-17 08:45:08.312240] security_token : *
  7268. [2022-06-17 08:45:08.315048] security_token: struct security_token
  7269. [2022-06-17 08:45:08.316697] num_sids : 0x00000007 (7)
  7270. [2022-06-17 08:45:08.318389] sids: ARRAY(7)
  7271. [2022-06-17 08:45:08.320132] sids : S-1-5-21-3939785350-4027435424-1589595352-132066
  7272. [2022-06-17 08:45:08.321815] sids : S-1-5-21-3939785350-4027435424-1589595352-513
  7273. [2022-06-17 08:45:08.323547] sids : S-1-22-2-65534
  7274. [2022-06-17 08:45:08.325104] sids : S-1-1-0
  7275. [2022-06-17 08:45:08.326762] sids : S-1-5-2
  7276. [2022-06-17 08:45:08.328512] sids : S-1-5-11
  7277. [2022-06-17 08:45:08.330139] sids : S-1-22-1-65533
  7278. [2022-06-17 08:45:08.331674] privilege_mask : 0x0000000000000000 (0)
  7279. [2022-06-17 08:45:08.333396] 0: SEC_PRIV_MACHINE_ACCOUNT_BIT
  7280. [2022-06-17 08:45:08.335065] 0: SEC_PRIV_PRINT_OPERATOR_BIT
  7281. [2022-06-17 08:45:08.336838] 0: SEC_PRIV_ADD_USERS_BIT
  7282. [2022-06-17 08:45:08.338380] 0: SEC_PRIV_DISK_OPERATOR_BIT
  7283. [2022-06-17 08:45:08.340043] 0: SEC_PRIV_REMOTE_SHUTDOWN_BIT
  7284. [2022-06-17 08:45:08.341681] 0: SEC_PRIV_BACKUP_BIT
  7285. [2022-06-17 08:45:08.343378] 0: SEC_PRIV_RESTORE_BIT
  7286. [2022-06-17 08:45:08.345052] 0: SEC_PRIV_TAKE_OWNERSHIP_BIT
  7287. [2022-06-17 08:45:08.346720] 0: SEC_PRIV_INCREASE_QUOTA_BIT
  7288. [2022-06-17 08:45:08.348464] 0: SEC_PRIV_SECURITY_BIT
  7289. [2022-06-17 08:45:08.349991] 0: SEC_PRIV_LOAD_DRIVER_BIT
  7290. [2022-06-17 08:45:08.351641] 0: SEC_PRIV_SYSTEM_PROFILE_BIT
  7291. [2022-06-17 08:45:08.353440] 0: SEC_PRIV_SYSTEMTIME_BIT
  7292. [2022-06-17 08:45:08.354989] 0: SEC_PRIV_PROFILE_SINGLE_PROCESS_BIT
  7293. [2022-06-17 08:45:08.356645] 0: SEC_PRIV_INCREASE_BASE_PRIORITY_BIT
  7294. [2022-06-17 08:45:08.358304] 0: SEC_PRIV_CREATE_PAGEFILE_BIT
  7295. [2022-06-17 08:45:08.359965] 0: SEC_PRIV_SHUTDOWN_BIT
  7296. [2022-06-17 08:45:08.361622] 0: SEC_PRIV_DEBUG_BIT
  7297. [2022-06-17 08:45:08.363309] 0: SEC_PRIV_SYSTEM_ENVIRONMENT_BIT
  7298. [2022-06-17 08:45:08.364964] 0: SEC_PRIV_CHANGE_NOTIFY_BIT
  7299. [2022-06-17 08:45:08.366620] 0: SEC_PRIV_UNDOCK_BIT
  7300. [2022-06-17 08:45:08.368265] 0: SEC_PRIV_ENABLE_DELEGATION_BIT
  7301. [2022-06-17 08:45:08.369931] 0: SEC_PRIV_MANAGE_VOLUME_BIT
  7302. [2022-06-17 08:45:08.371585] 0: SEC_PRIV_IMPERSONATE_BIT
  7303. [2022-06-17 08:45:08.373322] 0: SEC_PRIV_CREATE_GLOBAL_BIT
  7304. [2022-06-17 08:45:08.374992] rights_mask : 0x00000000 (0)
  7305. [2022-06-17 08:45:08.376757] 0: LSA_POLICY_MODE_INTERACTIVE
  7306. [2022-06-17 08:45:08.378404] 0: LSA_POLICY_MODE_NETWORK
  7307. [2022-06-17 08:45:08.379945] 0: LSA_POLICY_MODE_BATCH
  7308. [2022-06-17 08:45:08.381583] 0: LSA_POLICY_MODE_SERVICE
  7309. [2022-06-17 08:45:08.383344] 0: LSA_POLICY_MODE_PROXY
  7310. [2022-06-17 08:45:08.385055] 0: LSA_POLICY_MODE_DENY_INTERACTIVE
  7311. [2022-06-17 08:45:08.386719] 0: LSA_POLICY_MODE_DENY_NETWORK
  7312. [2022-06-17 08:45:08.388382] 0: LSA_POLICY_MODE_DENY_BATCH
  7313. [2022-06-17 08:45:08.390022] 0: LSA_POLICY_MODE_DENY_SERVICE
  7314. [2022-06-17 08:45:08.391667] 0: LSA_POLICY_MODE_REMOTE_INTERACTIVE
  7315. [2022-06-17 08:45:08.393364] 0: LSA_POLICY_MODE_DENY_REMOTE_INTERACTIVE
  7316. [2022-06-17 08:45:08.395154] 0x00: LSA_POLICY_MODE_ALL (0)
  7317. [2022-06-17 08:45:08.396703] 0x00: LSA_POLICY_MODE_ALL_NT4 (0)
  7318. [2022-06-17 08:45:08.398462] unix_token : *
  7319. [2022-06-17 08:45:08.400087] unix_token: struct security_unix_token
  7320. [2022-06-17 08:45:08.401621] uid : 0x000000000000fffd (65533)
  7321. [2022-06-17 08:45:08.403310] gid : 0x000000000000fffe (65534)
  7322. [2022-06-17 08:45:08.404976] ngroups : 0x00000001 (1)
  7323. [2022-06-17 08:45:08.406651] groups: ARRAY(1)
  7324. [2022-06-17 08:45:08.408416] groups : 0x000000000000fffe (65534)
  7325. [2022-06-17 08:45:08.409971] info : *
  7326. [2022-06-17 08:45:08.411472] info: struct auth_user_info
  7327. [2022-06-17 08:45:08.413016] account_name : *
  7328. [2022-06-17 08:45:08.414539] account_name : 'useruser'
  7329. [2022-06-17 08:45:08.416043] user_principal_name : NULL
  7330. [2022-06-17 08:45:08.417546] user_principal_constructed: 0x00 (0)
  7331. [2022-06-17 08:45:08.419049] domain_name : *
  7332. [2022-06-17 08:45:08.420541] domain_name : 'ZALUPA'
  7333. [2022-06-17 08:45:08.422047] dns_domain_name : NULL
  7334. [2022-06-17 08:45:08.423591] full_name : *
  7335. [2022-06-17 08:45:08.425300] full_name : 'nobody'
  7336. [2022-06-17 08:45:08.426823] logon_script : *
  7337. [2022-06-17 08:45:08.428318] logon_script : ''
  7338. [2022-06-17 08:45:08.429826] profile_path : *
  7339. [2022-06-17 08:45:08.431638] profile_path : '\\ZALUPA\useruser\profile'
  7340. [2022-06-17 08:45:08.433366] home_directory : *
  7341. [2022-06-17 08:45:08.435021] home_directory : '\\ZALUPA\useruser'
  7342. [2022-06-17 08:45:08.436675] home_drive : *
  7343. [2022-06-17 08:45:08.438332] home_drive : ''
  7344. [2022-06-17 08:45:08.440083] logon_server : *
  7345. [2022-06-17 08:45:08.441622] logon_server : 'ZALUPA'
  7346. [2022-06-17 08:45:08.443327] last_logon : NTTIME(0)
  7347. [2022-06-17 08:45:08.444851] last_logoff : Tue Jan 19 03:14:07 2038 UTC
  7348. [2022-06-17 08:45:08.446539] acct_expiry : Tue Jan 19 03:14:07 2038 UTC
  7349. [2022-06-17 08:45:08.448199] last_password_change : Thu Jun 16 22:30:51 2022 UTC
  7350. [2022-06-17 08:45:08.449851] allow_password_change : Thu Jun 16 22:30:51 2022 UTC
  7351. [2022-06-17 08:45:08.451509] force_password_change : Tue Jan 19 03:14:07 2038 UTC
  7352. [2022-06-17 08:45:08.453327] logon_count : 0x0000 (0)
  7353. [2022-06-17 08:45:08.454989] bad_password_count : 0x0000 (0)
  7354. [2022-06-17 08:45:08.456535] acct_flags : 0x00000010 (16)
  7355. [2022-06-17 08:45:08.458194] authenticated : 0x01 (1)
  7356. [2022-06-17 08:45:08.459841] unix_info : *
  7357. [2022-06-17 08:45:08.461475] unix_info: struct auth_user_info_unix
  7358. [2022-06-17 08:45:08.463417] unix_name : *
  7359. [2022-06-17 08:45:08.465013] unix_name : 'useruser'
  7360. [2022-06-17 08:45:08.466699] sanitized_username : *
  7361. [2022-06-17 08:45:08.468480] sanitized_username : 'useruser'
  7362. [2022-06-17 08:45:08.470128] torture : NULL
  7363. [2022-06-17 08:45:08.471660] credentials : NULL
  7364. [2022-06-17 08:45:08.473452] unique_session_token : 948521e3-7864-4f36-8058-4ed4b9d327d1
  7365. [2022-06-17 08:45:08.475009] connection_dialect : 0x0311 (785)
  7366. [2022-06-17 08:45:08.476757] signing_flags : 0x04 (4)
  7367. [2022-06-17 08:45:08.478290] 0: SMBXSRV_SIGNING_REQUIRED
  7368. [2022-06-17 08:45:08.479940] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  7369. [2022-06-17 08:45:08.481594] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  7370. [2022-06-17 08:45:08.483289] encryption_flags : 0x08 (8)
  7371. [2022-06-17 08:45:08.485059] 0: SMBXSRV_ENCRYPTION_REQUIRED
  7372. [2022-06-17 08:45:08.486591] 0: SMBXSRV_ENCRYPTION_DESIRED
  7373. [2022-06-17 08:45:08.488232] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  7374. [2022-06-17 08:45:08.489870] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  7375. [2022-06-17 08:45:08.491524] signing_key : *
  7376. [2022-06-17 08:45:08.493225] encryption_key : *
  7377. [2022-06-17 08:45:08.494875] decryption_key : *
  7378. [2022-06-17 08:45:08.496516] num_channels : 0x00000001 (1)
  7379. [2022-06-17 08:45:08.498152] channels: ARRAY(1)
  7380. [2022-06-17 08:45:08.500565] channels: struct smbXsrv_channel_global0
  7381. [2022-06-17 08:45:08.510223] server_id: struct server_id
  7382. [2022-06-17 08:45:08.512265] pid : 0x0000000000002574 (9588)
  7383. [2022-06-17 08:45:08.514161] task_id : 0x00000000 (0)
  7384. [2022-06-17 08:45:08.515865] vnn : 0xffffffff (4294967295)
  7385. [2022-06-17 08:45:08.517539] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  7386. [2022-06-17 08:45:08.519371] channel_id : 0x0000000000000000 (0)
  7387. [2022-06-17 08:45:08.521086] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7388. [2022-06-17 08:45:08.522762] local_address : 'ipv4:192.168.1.250:445'
  7389. [2022-06-17 08:45:08.532956] remote_address : 'ipv4:192.168.1.10:33730'
  7390. [2022-06-17 08:45:08.534811] remote_name : '192.168.1.10'
  7391. [2022-06-17 08:45:08.536540] signing_key : *
  7392. [2022-06-17 08:45:08.538221] auth_session_info_seqnum : 0x00000001 (1)
  7393. [2022-06-17 08:45:08.539874] connection : *
  7394. [2022-06-17 08:45:08.541514] encryption_cipher : 0x0002 (2)
  7395. [2022-06-17 08:45:08.543215] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  7396. [2022-06-17 08:45:08.544769] db_tdb_log_key: Unlocking key 6F1A4B46
  7397. [2022-06-17 08:45:08.546458] smbXsrv_session_update: global_id (0x6f1a4b46) stored
  7398. [2022-06-17 08:45:08.548199] &session_blob: struct smbXsrv_sessionB
  7399. [2022-06-17 08:45:08.549851] version : SMBXSRV_VERSION_0 (0)
  7400. [2022-06-17 08:45:08.551495] reserved : 0x00000000 (0)
  7401. [2022-06-17 08:45:08.553187] info : union smbXsrv_sessionU(case 0)
  7402. [2022-06-17 08:45:08.554848] info0 : *
  7403. [2022-06-17 08:45:08.556486] info0: struct smbXsrv_session
  7404. [2022-06-17 08:45:08.558133] table : *
  7405. [2022-06-17 08:45:08.559782] db_rec : NULL
  7406. [2022-06-17 08:45:08.561402] client : *
  7407. [2022-06-17 08:45:08.563078] local_id : 0x6f1a4b46 (1863994182)
  7408. [2022-06-17 08:45:08.564828] global : *
  7409. [2022-06-17 08:45:08.566507] global: struct smbXsrv_session_global0
  7410. [2022-06-17 08:45:08.568161] db_rec : NULL
  7411. [2022-06-17 08:45:08.569809] session_global_id : 0x6f1a4b46 (1863994182)
  7412. [2022-06-17 08:45:08.571466] session_wire_id : 0x000000006f1a4b46 (1863994182)
  7413. [2022-06-17 08:45:08.573176] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7414. [2022-06-17 08:45:08.574853] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  7415. [2022-06-17 08:45:08.576504] auth_time : Fri Jun 17 08:45:05 2022 UTC
  7416. [2022-06-17 08:45:08.578154] auth_session_info_seqnum : 0x00000001 (1)
  7417. [2022-06-17 08:45:08.579808] auth_session_info : *
  7418. [2022-06-17 08:45:08.581446] auth_session_info: struct auth_session_info
  7419. [2022-06-17 08:45:08.583145] security_token : *
  7420. [2022-06-17 08:45:08.584810] security_token: struct security_token
  7421. [2022-06-17 08:45:08.586466] num_sids : 0x00000007 (7)
  7422. [2022-06-17 08:45:08.588116] sids: ARRAY(7)
  7423. [2022-06-17 08:45:08.589758] sids : S-1-5-21-3939785350-4027435424-1589595352-132066
  7424. [2022-06-17 08:45:08.591432] sids : S-1-5-21-3939785350-4027435424-1589595352-513
  7425. [2022-06-17 08:45:08.593152] sids : S-1-22-2-65534
  7426. [2022-06-17 08:45:08.594696] sids : S-1-1-0
  7427. [2022-06-17 08:45:08.596508] sids : S-1-5-2
  7428. [2022-06-17 08:45:08.598169] sids : S-1-5-11
  7429. [2022-06-17 08:45:08.599825] sids : S-1-22-1-65533
  7430. [2022-06-17 08:45:08.601488] privilege_mask : 0x0000000000000000 (0)
  7431. [2022-06-17 08:45:08.603203] 0: SEC_PRIV_MACHINE_ACCOUNT_BIT
  7432. [2022-06-17 08:45:08.604874] 0: SEC_PRIV_PRINT_OPERATOR_BIT
  7433. [2022-06-17 08:45:08.606542] 0: SEC_PRIV_ADD_USERS_BIT
  7434. [2022-06-17 08:45:08.608212] 0: SEC_PRIV_DISK_OPERATOR_BIT
  7435. [2022-06-17 08:45:08.609886] 0: SEC_PRIV_REMOTE_SHUTDOWN_BIT
  7436. [2022-06-17 08:45:08.611548] 0: SEC_PRIV_BACKUP_BIT
  7437. [2022-06-17 08:45:08.613251] 0: SEC_PRIV_RESTORE_BIT
  7438. [2022-06-17 08:45:08.614911] 0: SEC_PRIV_TAKE_OWNERSHIP_BIT
  7439. [2022-06-17 08:45:08.616571] 0: SEC_PRIV_INCREASE_QUOTA_BIT
  7440. [2022-06-17 08:45:08.618236] 0: SEC_PRIV_SECURITY_BIT
  7441. [2022-06-17 08:45:08.619898] 0: SEC_PRIV_LOAD_DRIVER_BIT
  7442. [2022-06-17 08:45:08.621548] 0: SEC_PRIV_SYSTEM_PROFILE_BIT
  7443. [2022-06-17 08:45:08.623166] 0: SEC_PRIV_SYSTEMTIME_BIT
  7444. [2022-06-17 08:45:08.624700] 0: SEC_PRIV_PROFILE_SINGLE_PROCESS_BIT
  7445. [2022-06-17 08:45:08.626214] 0: SEC_PRIV_INCREASE_BASE_PRIORITY_BIT
  7446. [2022-06-17 08:45:08.627731] 0: SEC_PRIV_CREATE_PAGEFILE_BIT
  7447. [2022-06-17 08:45:08.629239] 0: SEC_PRIV_SHUTDOWN_BIT
  7448. [2022-06-17 08:45:08.630741] 0: SEC_PRIV_DEBUG_BIT
  7449. [2022-06-17 08:45:08.632240] 0: SEC_PRIV_SYSTEM_ENVIRONMENT_BIT
  7450. [2022-06-17 08:45:08.633789] 0: SEC_PRIV_CHANGE_NOTIFY_BIT
  7451. [2022-06-17 08:45:08.635304] 0: SEC_PRIV_UNDOCK_BIT
  7452. [2022-06-17 08:45:08.636986] 0: SEC_PRIV_ENABLE_DELEGATION_BIT
  7453. [2022-06-17 08:45:08.638528] 0: SEC_PRIV_MANAGE_VOLUME_BIT
  7454. [2022-06-17 08:45:08.640042] 0: SEC_PRIV_IMPERSONATE_BIT
  7455. [2022-06-17 08:45:08.641551] 0: SEC_PRIV_CREATE_GLOBAL_BIT
  7456. [2022-06-17 08:45:08.643116] rights_mask : 0x00000000 (0)
  7457. [2022-06-17 08:45:08.644651] 0: LSA_POLICY_MODE_INTERACTIVE
  7458. [2022-06-17 08:45:08.646163] 0: LSA_POLICY_MODE_NETWORK
  7459. [2022-06-17 08:45:08.647671] 0: LSA_POLICY_MODE_BATCH
  7460. [2022-06-17 08:45:08.649165] 0: LSA_POLICY_MODE_SERVICE
  7461. [2022-06-17 08:45:08.650677] 0: LSA_POLICY_MODE_PROXY
  7462. [2022-06-17 08:45:08.652342] 0: LSA_POLICY_MODE_DENY_INTERACTIVE
  7463. [2022-06-17 08:45:08.653996] 0: LSA_POLICY_MODE_DENY_NETWORK
  7464. [2022-06-17 08:45:08.655523] 0: LSA_POLICY_MODE_DENY_BATCH
  7465. [2022-06-17 08:45:08.657040] 0: LSA_POLICY_MODE_DENY_SERVICE
  7466. [2022-06-17 08:45:08.658560] 0: LSA_POLICY_MODE_REMOTE_INTERACTIVE
  7467. [2022-06-17 08:45:08.660078] 0: LSA_POLICY_MODE_DENY_REMOTE_INTERACTIVE
  7468. [2022-06-17 08:45:08.661585] 0x00: LSA_POLICY_MODE_ALL (0)
  7469. [2022-06-17 08:45:08.663137] 0x00: LSA_POLICY_MODE_ALL_NT4 (0)
  7470. [2022-06-17 08:45:08.664662] unix_token : *
  7471. [2022-06-17 08:45:08.666182] unix_token: struct security_unix_token
  7472. [2022-06-17 08:45:08.667851] uid : 0x000000000000fffd (65533)
  7473. [2022-06-17 08:45:08.669412] gid : 0x000000000000fffe (65534)
  7474. [2022-06-17 08:45:08.670940] ngroups : 0x00000001 (1)
  7475. [2022-06-17 08:45:08.672449] groups: ARRAY(1)
  7476. [2022-06-17 08:45:08.674032] groups : 0x000000000000fffe (65534)
  7477. [2022-06-17 08:45:08.675583] info : *
  7478. [2022-06-17 08:45:08.677105] info: struct auth_user_info
  7479. [2022-06-17 08:45:08.678604] account_name : *
  7480. [2022-06-17 08:45:08.680112] account_name : 'useruser'
  7481. [2022-06-17 08:45:08.681631] user_principal_name : NULL
  7482. [2022-06-17 08:45:08.683409] user_principal_constructed: 0x00 (0)
  7483. [2022-06-17 08:45:08.684958] domain_name : *
  7484. [2022-06-17 08:45:08.686478] domain_name : 'ZALUPA'
  7485. [2022-06-17 08:45:08.688002] dns_domain_name : NULL
  7486. [2022-06-17 08:45:08.689505] full_name : *
  7487. [2022-06-17 08:45:08.691018] full_name : 'nobody'
  7488. [2022-06-17 08:45:08.692675] logon_script : *
  7489. [2022-06-17 08:45:08.694240] logon_script : ''
  7490. [2022-06-17 08:45:08.695745] profile_path : *
  7491. [2022-06-17 08:45:08.697437] profile_path : '\\ZALUPA\useruser\profile'
  7492. [2022-06-17 08:45:08.701105] home_directory : *
  7493. [2022-06-17 08:45:08.702772] home_directory : '\\ZALUPA\useruser'
  7494. [2022-06-17 08:45:08.704404] home_drive : *
  7495. [2022-06-17 08:45:08.705927] home_drive : ''
  7496. [2022-06-17 08:45:08.707452] logon_server : *
  7497. [2022-06-17 08:45:08.708953] logon_server : 'ZALUPA'
  7498. [2022-06-17 08:45:08.710455] last_logon : NTTIME(0)
  7499. [2022-06-17 08:45:08.712127] last_logoff : Tue Jan 19 03:14:07 2038 UTC
  7500. [2022-06-17 08:45:08.713781] acct_expiry : Tue Jan 19 03:14:07 2038 UTC
  7501. [2022-06-17 08:45:08.715336] last_password_change : Thu Jun 16 22:30:51 2022 UTC
  7502. [2022-06-17 08:45:08.716870] allow_password_change : Thu Jun 16 22:30:51 2022 UTC
  7503. [2022-06-17 08:45:08.718394] force_password_change : Tue Jan 19 03:14:07 2038 UTC
  7504. [2022-06-17 08:45:08.719910] logon_count : 0x0000 (0)
  7505. [2022-06-17 08:45:08.721431] bad_password_count : 0x0000 (0)
  7506. [2022-06-17 08:45:08.722981] acct_flags : 0x00000010 (16)
  7507. [2022-06-17 08:45:08.724650] authenticated : 0x01 (1)
  7508. [2022-06-17 08:45:08.726193] unix_info : *
  7509. [2022-06-17 08:45:08.727894] unix_info: struct auth_user_info_unix
  7510. [2022-06-17 08:45:08.729448] unix_name : *
  7511. [2022-06-17 08:45:08.730957] unix_name : 'useruser'
  7512. [2022-06-17 08:45:08.732462] sanitized_username : *
  7513. [2022-06-17 08:45:08.734047] sanitized_username : 'useruser'
  7514. [2022-06-17 08:45:08.735568] torture : NULL
  7515. [2022-06-17 08:45:08.737095] credentials : NULL
  7516. [2022-06-17 08:45:08.738618] unique_session_token : 948521e3-7864-4f36-8058-4ed4b9d327d1
  7517. [2022-06-17 08:45:08.740143] connection_dialect : 0x0311 (785)
  7518. [2022-06-17 08:45:08.741651] signing_flags : 0x04 (4)
  7519. [2022-06-17 08:45:08.743414] 0: SMBXSRV_SIGNING_REQUIRED
  7520. [2022-06-17 08:45:08.744944] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  7521. [2022-06-17 08:45:08.746457] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  7522. [2022-06-17 08:45:08.747972] encryption_flags : 0x08 (8)
  7523. [2022-06-17 08:45:08.749467] 0: SMBXSRV_ENCRYPTION_REQUIRED
  7524. [2022-06-17 08:45:08.761557] 0: SMBXSRV_ENCRYPTION_DESIRED
  7525. [2022-06-17 08:45:08.763378] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  7526. [2022-06-17 08:45:08.765076] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  7527. [2022-06-17 08:45:08.766754] signing_key : *
  7528. [2022-06-17 08:45:08.768407] encryption_key : *
  7529. [2022-06-17 08:45:08.770052] decryption_key : *
  7530. [2022-06-17 08:45:08.771702] num_channels : 0x00000001 (1)
  7531. [2022-06-17 08:45:08.773398] channels: ARRAY(1)
  7532. [2022-06-17 08:45:08.775047] channels: struct smbXsrv_channel_global0
  7533. [2022-06-17 08:45:08.776693] server_id: struct server_id
  7534. [2022-06-17 08:45:08.778322] pid : 0x0000000000002574 (9588)
  7535. [2022-06-17 08:45:08.779988] task_id : 0x00000000 (0)
  7536. [2022-06-17 08:45:08.781659] vnn : 0xffffffff (4294967295)
  7537. [2022-06-17 08:45:08.783401] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  7538. [2022-06-17 08:45:08.785090] channel_id : 0x0000000000000000 (0)
  7539. [2022-06-17 08:45:08.786754] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7540. [2022-06-17 08:45:08.788402] local_address : 'ipv4:192.168.1.250:445'
  7541. [2022-06-17 08:45:08.790053] remote_address : 'ipv4:192.168.1.10:33730'
  7542. [2022-06-17 08:45:08.791707] remote_name : '192.168.1.10'
  7543. [2022-06-17 08:45:08.793409] signing_key : *
  7544. [2022-06-17 08:45:08.795079] auth_session_info_seqnum : 0x00000001 (1)
  7545. [2022-06-17 08:45:08.796739] connection : *
  7546. [2022-06-17 08:45:08.798388] encryption_cipher : 0x0002 (2)
  7547. [2022-06-17 08:45:08.800030] status : NT_STATUS_OK
  7548. [2022-06-17 08:45:08.801659] idle_time : Fri Jun 17 08:45:05 2022 UTC
  7549. [2022-06-17 08:45:08.803349] nonce_high_random : 0x1b89f68e6094ef6d (1984388202199576429)
  7550. [2022-06-17 08:45:08.804891] nonce_high_max : 0x00000000ffffffff (4294967295)
  7551. [2022-06-17 08:45:08.806414] nonce_high : 0x0000000000000000 (0)
  7552. [2022-06-17 08:45:08.807921] nonce_low : 0x0000000000000000 (0)
  7553. [2022-06-17 08:45:08.809433] tcon_table : *
  7554. [2022-06-17 08:45:08.810925] homes_snum : 0xffffffff (4294967295)
  7555. [2022-06-17 08:45:08.812428] pending_auth : NULL
  7556. [2022-06-17 08:45:08.813996] smbd_smb2_request_done_ex: mid [2] idx[1] status[NT_STATUS_OK] body[8] dyn[yes:29] at ../../source3/smbd/smb2_sesssetup.c:183
  7557. [2022-06-17 08:45:08.815538] smb2_set_operation_credit: smb2_set_operation_credit: requested 8192, charge 1, granted 8192, current possible/max 8192/8192, total granted/max/low/range 8192/8192/3/8192
  7558. [2022-06-17 08:45:08.817111] signed SMB2 message
  7559. [2022-06-17 08:45:08.819034] smbd_smb2_request idx[1] of 5 vectors
  7560. [2022-06-17 08:45:08.820685] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 3 (position 3) from bitmap
  7561. [2022-06-17 08:45:08.822350] smbd_smb2_request_dispatch: opcode[SMB2_OP_TCON] mid = 3
  7562. [2022-06-17 08:45:08.824084] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  7563. [2022-06-17 08:45:08.825744] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  7564. [2022-06-17 08:45:08.827398] db_tdb_log_key: Locking key 6F1A4B46
  7565. [2022-06-17 08:45:08.829029] db_tdb_fetch_locked_internal: Allocated locked data 0xb51605d0
  7566. [2022-06-17 08:45:08.830674] dbwrap_watched_subrec_wakeup_fn: No watchers
  7567. [2022-06-17 08:45:08.832331] smbXsrv_session_global_store: key '6F1A4B46' stored
  7568. [2022-06-17 08:45:08.834062] &global_blob: struct smbXsrv_session_globalB
  7569. [2022-06-17 08:45:08.835724] version : SMBXSRV_VERSION_0 (0)
  7570. [2022-06-17 08:45:08.837361] seqnum : 0x00000006 (6)
  7571. [2022-06-17 08:45:08.838992] info : union smbXsrv_session_globalU(case 0)
  7572. [2022-06-17 08:45:08.840629] info0 : *
  7573. [2022-06-17 08:45:08.842264] info0: struct smbXsrv_session_global0
  7574. [2022-06-17 08:45:08.843851] db_rec : *
  7575. [2022-06-17 08:45:08.845485] session_global_id : 0x6f1a4b46 (1863994182)
  7576. [2022-06-17 08:45:08.847140] session_wire_id : 0x000000006f1a4b46 (1863994182)
  7577. [2022-06-17 08:45:08.848791] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7578. [2022-06-17 08:45:08.850438] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  7579. [2022-06-17 08:45:08.852091] auth_time : Fri Jun 17 08:45:05 2022 UTC
  7580. [2022-06-17 08:45:08.853785] auth_session_info_seqnum : 0x00000001 (1)
  7581. [2022-06-17 08:45:08.855438] auth_session_info : *
  7582. [2022-06-17 08:45:08.857076] auth_session_info: struct auth_session_info
  7583. [2022-06-17 08:45:08.858724] security_token : *
  7584. [2022-06-17 08:45:08.860362] security_token: struct security_token
  7585. [2022-06-17 08:45:08.862017] num_sids : 0x00000007 (7)
  7586. [2022-06-17 08:45:08.863738] sids: ARRAY(7)
  7587. [2022-06-17 08:45:08.865400] sids : S-1-5-21-3939785350-4027435424-1589595352-132066
  7588. [2022-06-17 08:45:08.867083] sids : S-1-5-21-3939785350-4027435424-1589595352-513
  7589. [2022-06-17 08:45:08.868759] sids : S-1-22-2-65534
  7590. [2022-06-17 08:45:08.870419] sids : S-1-1-0
  7591. [2022-06-17 08:45:08.872055] sids : S-1-5-2
  7592. [2022-06-17 08:45:08.873744] sids : S-1-5-11
  7593. [2022-06-17 08:45:08.875409] sids : S-1-22-1-65533
  7594. [2022-06-17 08:45:08.876943] privilege_mask : 0x0000000000000000 (0)
  7595. [2022-06-17 08:45:08.878472] 0: SEC_PRIV_MACHINE_ACCOUNT_BIT
  7596. [2022-06-17 08:45:08.880220] 0: SEC_PRIV_PRINT_OPERATOR_BIT
  7597. [2022-06-17 08:45:08.881751] 0: SEC_PRIV_ADD_USERS_BIT
  7598. [2022-06-17 08:45:08.883606] 0: SEC_PRIV_DISK_OPERATOR_BIT
  7599. [2022-06-17 08:45:08.885275] 0: SEC_PRIV_REMOTE_SHUTDOWN_BIT
  7600. [2022-06-17 08:45:08.886930] 0: SEC_PRIV_BACKUP_BIT
  7601. [2022-06-17 08:45:08.888580] 0: SEC_PRIV_RESTORE_BIT
  7602. [2022-06-17 08:45:08.890234] 0: SEC_PRIV_TAKE_OWNERSHIP_BIT
  7603. [2022-06-17 08:45:08.891890] 0: SEC_PRIV_INCREASE_QUOTA_BIT
  7604. [2022-06-17 08:45:08.893593] 0: SEC_PRIV_SECURITY_BIT
  7605. [2022-06-17 08:45:08.895242] 0: SEC_PRIV_LOAD_DRIVER_BIT
  7606. [2022-06-17 08:45:08.896878] 0: SEC_PRIV_SYSTEM_PROFILE_BIT
  7607. [2022-06-17 08:45:08.898536] 0: SEC_PRIV_SYSTEMTIME_BIT
  7608. [2022-06-17 08:45:08.913051] 0: SEC_PRIV_PROFILE_SINGLE_PROCESS_BIT
  7609. [2022-06-17 08:45:08.914819] 0: SEC_PRIV_INCREASE_BASE_PRIORITY_BIT
  7610. [2022-06-17 08:45:08.916695] 0: SEC_PRIV_CREATE_PAGEFILE_BIT
  7611. [2022-06-17 08:45:08.918388] 0: SEC_PRIV_SHUTDOWN_BIT
  7612. [2022-06-17 08:45:08.920072] 0: SEC_PRIV_DEBUG_BIT
  7613. [2022-06-17 08:45:08.921720] 0: SEC_PRIV_SYSTEM_ENVIRONMENT_BIT
  7614. [2022-06-17 08:45:08.923417] 0: SEC_PRIV_CHANGE_NOTIFY_BIT
  7615. [2022-06-17 08:45:08.925088] 0: SEC_PRIV_UNDOCK_BIT
  7616. [2022-06-17 08:45:08.926759] 0: SEC_PRIV_ENABLE_DELEGATION_BIT
  7617. [2022-06-17 08:45:08.928424] 0: SEC_PRIV_MANAGE_VOLUME_BIT
  7618. [2022-06-17 08:45:08.930079] 0: SEC_PRIV_IMPERSONATE_BIT
  7619. [2022-06-17 08:45:08.933323] 0: SEC_PRIV_CREATE_GLOBAL_BIT
  7620. [2022-06-17 08:45:08.935110] rights_mask : 0x00000000 (0)
  7621. [2022-06-17 08:45:08.936803] 0: LSA_POLICY_MODE_INTERACTIVE
  7622. [2022-06-17 08:45:08.938469] 0: LSA_POLICY_MODE_NETWORK
  7623. [2022-06-17 08:45:08.940113] 0: LSA_POLICY_MODE_BATCH
  7624. [2022-06-17 08:45:08.941767] 0: LSA_POLICY_MODE_SERVICE
  7625. [2022-06-17 08:45:08.943497] 0: LSA_POLICY_MODE_PROXY
  7626. [2022-06-17 08:45:08.945175] 0: LSA_POLICY_MODE_DENY_INTERACTIVE
  7627. [2022-06-17 08:45:08.946863] 0: LSA_POLICY_MODE_DENY_NETWORK
  7628. [2022-06-17 08:45:08.948505] 0: LSA_POLICY_MODE_DENY_BATCH
  7629. [2022-06-17 08:45:08.950160] 0: LSA_POLICY_MODE_DENY_SERVICE
  7630. [2022-06-17 08:45:08.951799] 0: LSA_POLICY_MODE_REMOTE_INTERACTIVE
  7631. [2022-06-17 08:45:08.953389] 0: LSA_POLICY_MODE_DENY_REMOTE_INTERACTIVE
  7632. [2022-06-17 08:45:08.955147] 0x00: LSA_POLICY_MODE_ALL (0)
  7633. [2022-06-17 08:45:08.956806] 0x00: LSA_POLICY_MODE_ALL_NT4 (0)
  7634. [2022-06-17 08:45:08.958459] unix_token : *
  7635. [2022-06-17 08:45:08.960098] unix_token: struct security_unix_token
  7636. [2022-06-17 08:45:08.961723] uid : 0x000000000000fffd (65533)
  7637. [2022-06-17 08:45:08.963430] gid : 0x000000000000fffe (65534)
  7638. [2022-06-17 08:45:08.965099] ngroups : 0x00000001 (1)
  7639. [2022-06-17 08:45:08.966761] groups: ARRAY(1)
  7640. [2022-06-17 08:45:08.968407] groups : 0x000000000000fffe (65534)
  7641. [2022-06-17 08:45:08.970070] info : *
  7642. [2022-06-17 08:45:08.971699] info: struct auth_user_info
  7643. [2022-06-17 08:45:08.973401] account_name : *
  7644. [2022-06-17 08:45:08.975055] account_name : 'useruser'
  7645. [2022-06-17 08:45:08.976705] user_principal_name : NULL
  7646. [2022-06-17 08:45:08.978231] user_principal_constructed: 0x00 (0)
  7647. [2022-06-17 08:45:08.980025] domain_name : *
  7648. [2022-06-17 08:45:08.981675] domain_name : 'ZALUPA'
  7649. [2022-06-17 08:45:08.983364] dns_domain_name : NULL
  7650. [2022-06-17 08:45:08.985022] full_name : *
  7651. [2022-06-17 08:45:08.986659] full_name : 'nobody'
  7652. [2022-06-17 08:45:08.988293] logon_script : *
  7653. [2022-06-17 08:45:08.989937] logon_script : ''
  7654. [2022-06-17 08:45:08.991592] profile_path : *
  7655. [2022-06-17 08:45:08.993286] profile_path : '\\ZALUPA\useruser\profile'
  7656. [2022-06-17 08:45:08.994951] home_directory : *
  7657. [2022-06-17 08:45:08.996594] home_directory : '\\ZALUPA\useruser'
  7658. [2022-06-17 08:45:08.998238] home_drive : *
  7659. [2022-06-17 08:45:08.999887] home_drive : ''
  7660. [2022-06-17 08:45:09.001530] logon_server : *
  7661. [2022-06-17 08:45:09.003247] logon_server : 'ZALUPA'
  7662. [2022-06-17 08:45:09.004915] last_logon : NTTIME(0)
  7663. [2022-06-17 08:45:09.006585] last_logoff : Tue Jan 19 03:14:07 2038 UTC
  7664. [2022-06-17 08:45:09.008242] acct_expiry : Tue Jan 19 03:14:07 2038 UTC
  7665. [2022-06-17 08:45:09.009896] last_password_change : Thu Jun 16 22:30:51 2022 UTC
  7666. [2022-06-17 08:45:09.011550] allow_password_change : Thu Jun 16 22:30:51 2022 UTC
  7667. [2022-06-17 08:45:09.013243] force_password_change : Tue Jan 19 03:14:07 2038 UTC
  7668. [2022-06-17 08:45:09.014909] logon_count : 0x0000 (0)
  7669. [2022-06-17 08:45:09.016574] bad_password_count : 0x0000 (0)
  7670. [2022-06-17 08:45:09.018226] acct_flags : 0x00000010 (16)
  7671. [2022-06-17 08:45:09.019878] authenticated : 0x01 (1)
  7672. [2022-06-17 08:45:09.021523] unix_info : *
  7673. [2022-06-17 08:45:09.023205] unix_info: struct auth_user_info_unix
  7674. [2022-06-17 08:45:09.024861] unix_name : *
  7675. [2022-06-17 08:45:09.026526] unix_name : 'useruser'
  7676. [2022-06-17 08:45:09.028183] sanitized_username : *
  7677. [2022-06-17 08:45:09.029826] sanitized_username : 'useruser'
  7678. [2022-06-17 08:45:09.031474] torture : NULL
  7679. [2022-06-17 08:45:09.033160] credentials : NULL
  7680. [2022-06-17 08:45:09.034825] unique_session_token : 948521e3-7864-4f36-8058-4ed4b9d327d1
  7681. [2022-06-17 08:45:09.036483] connection_dialect : 0x0311 (785)
  7682. [2022-06-17 08:45:09.038124] signing_flags : 0x06 (6)
  7683. [2022-06-17 08:45:09.039771] 0: SMBXSRV_SIGNING_REQUIRED
  7684. [2022-06-17 08:45:09.041416] 1: SMBXSRV_PROCESSED_SIGNED_PACKET
  7685. [2022-06-17 08:45:09.043113] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  7686. [2022-06-17 08:45:09.044766] encryption_flags : 0x08 (8)
  7687. [2022-06-17 08:45:09.046407] 0: SMBXSRV_ENCRYPTION_REQUIRED
  7688. [2022-06-17 08:45:09.048052] 0: SMBXSRV_ENCRYPTION_DESIRED
  7689. [2022-06-17 08:45:09.049693] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  7690. [2022-06-17 08:45:09.051343] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  7691. [2022-06-17 08:45:09.053032] signing_key : *
  7692. [2022-06-17 08:45:09.054691] encryption_key : *
  7693. [2022-06-17 08:45:09.056323] decryption_key : *
  7694. [2022-06-17 08:45:09.057949] num_channels : 0x00000001 (1)
  7695. [2022-06-17 08:45:09.059583] channels: ARRAY(1)
  7696. [2022-06-17 08:45:09.061216] channels: struct smbXsrv_channel_global0
  7697. [2022-06-17 08:45:09.062907] server_id: struct server_id
  7698. [2022-06-17 08:45:09.064581] pid : 0x0000000000002574 (9588)
  7699. [2022-06-17 08:45:09.066238] task_id : 0x00000000 (0)
  7700. [2022-06-17 08:45:09.067967] vnn : 0xffffffff (4294967295)
  7701. [2022-06-17 08:45:09.069677] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  7702. [2022-06-17 08:45:09.071339] channel_id : 0x0000000000000000 (0)
  7703. [2022-06-17 08:45:09.073036] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7704. [2022-06-17 08:45:09.074711] local_address : 'ipv4:192.168.1.250:445'
  7705. [2022-06-17 08:45:09.076377] remote_address : 'ipv4:192.168.1.10:33730'
  7706. [2022-06-17 08:45:09.078029] remote_name : '192.168.1.10'
  7707. [2022-06-17 08:45:09.079674] signing_key : *
  7708. [2022-06-17 08:45:09.081292] auth_session_info_seqnum : 0x00000001 (1)
  7709. [2022-06-17 08:45:09.082967] connection : *
  7710. [2022-06-17 08:45:09.084619] encryption_cipher : 0x0002 (2)
  7711. [2022-06-17 08:45:09.086270] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  7712. [2022-06-17 08:45:09.087942] db_tdb_log_key: Unlocking key 6F1A4B46
  7713. [2022-06-17 08:45:09.089575] smbXsrv_session_update: global_id (0x6f1a4b46) stored
  7714. [2022-06-17 08:45:09.091209] &session_blob: struct smbXsrv_sessionB
  7715. [2022-06-17 08:45:09.092846] version : SMBXSRV_VERSION_0 (0)
  7716. [2022-06-17 08:45:09.094539] reserved : 0x00000000 (0)
  7717. [2022-06-17 08:45:09.096188] info : union smbXsrv_sessionU(case 0)
  7718. [2022-06-17 08:45:09.097834] info0 : *
  7719. [2022-06-17 08:45:09.099464] info0: struct smbXsrv_session
  7720. [2022-06-17 08:45:09.101111] table : *
  7721. [2022-06-17 08:45:09.102744] db_rec : NULL
  7722. [2022-06-17 08:45:09.104454] client : *
  7723. [2022-06-17 08:45:09.106100] local_id : 0x6f1a4b46 (1863994182)
  7724. [2022-06-17 08:45:09.107732] global : *
  7725. [2022-06-17 08:45:09.109359] global: struct smbXsrv_session_global0
  7726. [2022-06-17 08:45:09.110998] db_rec : NULL
  7727. [2022-06-17 08:45:09.112521] session_global_id : 0x6f1a4b46 (1863994182)
  7728. [2022-06-17 08:45:09.114110] session_wire_id : 0x000000006f1a4b46 (1863994182)
  7729. [2022-06-17 08:45:09.115631] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7730. [2022-06-17 08:45:09.117137] expiration_time : Tue Jan 19 03:14:07 2038 UTC
  7731. [2022-06-17 08:45:09.118634] auth_time : Fri Jun 17 08:45:05 2022 UTC
  7732. [2022-06-17 08:45:09.125078] auth_session_info_seqnum : 0x00000001 (1)
  7733. [2022-06-17 08:45:09.126940] auth_session_info : *
  7734. [2022-06-17 08:45:09.128550] auth_session_info: struct auth_session_info
  7735. [2022-06-17 08:45:09.130104] security_token : *
  7736. [2022-06-17 08:45:09.131619] security_token: struct security_token
  7737. [2022-06-17 08:45:09.133194] num_sids : 0x00000007 (7)
  7738. [2022-06-17 08:45:09.134729] sids: ARRAY(7)
  7739. [2022-06-17 08:45:09.136233] sids : S-1-5-21-3939785350-4027435424-1589595352-132066
  7740. [2022-06-17 08:45:09.137758] sids : S-1-5-21-3939785350-4027435424-1589595352-513
  7741. [2022-06-17 08:45:09.139285] sids : S-1-22-2-65534
  7742. [2022-06-17 08:45:09.140800] sids : S-1-1-0
  7743. [2022-06-17 08:45:09.142450] sids : S-1-5-2
  7744. [2022-06-17 08:45:09.144074] sids : S-1-5-11
  7745. [2022-06-17 08:45:09.145603] sids : S-1-22-1-65533
  7746. [2022-06-17 08:45:09.147122] privilege_mask : 0x0000000000000000 (0)
  7747. [2022-06-17 08:45:09.148639] 0: SEC_PRIV_MACHINE_ACCOUNT_BIT
  7748. [2022-06-17 08:45:09.150145] 0: SEC_PRIV_PRINT_OPERATOR_BIT
  7749. [2022-06-17 08:45:09.151657] 0: SEC_PRIV_ADD_USERS_BIT
  7750. [2022-06-17 08:45:09.153224] 0: SEC_PRIV_DISK_OPERATOR_BIT
  7751. [2022-06-17 08:45:09.154752] 0: SEC_PRIV_REMOTE_SHUTDOWN_BIT
  7752. [2022-06-17 08:45:09.156258] 0: SEC_PRIV_BACKUP_BIT
  7753. [2022-06-17 08:45:09.157984] 0: SEC_PRIV_RESTORE_BIT
  7754. [2022-06-17 08:45:09.159511] 0: SEC_PRIV_TAKE_OWNERSHIP_BIT
  7755. [2022-06-17 08:45:09.161030] 0: SEC_PRIV_INCREASE_QUOTA_BIT
  7756. [2022-06-17 08:45:09.162544] 0: SEC_PRIV_SECURITY_BIT
  7757. [2022-06-17 08:45:09.164138] 0: SEC_PRIV_LOAD_DRIVER_BIT
  7758. [2022-06-17 08:45:09.165662] 0: SEC_PRIV_SYSTEM_PROFILE_BIT
  7759. [2022-06-17 08:45:09.167173] 0: SEC_PRIV_SYSTEMTIME_BIT
  7760. [2022-06-17 08:45:09.168682] 0: SEC_PRIV_PROFILE_SINGLE_PROCESS_BIT
  7761. [2022-06-17 08:45:09.170188] 0: SEC_PRIV_INCREASE_BASE_PRIORITY_BIT
  7762. [2022-06-17 08:45:09.171699] 0: SEC_PRIV_CREATE_PAGEFILE_BIT
  7763. [2022-06-17 08:45:09.176152] 0: SEC_PRIV_SHUTDOWN_BIT
  7764. [2022-06-17 08:45:09.177770] 0: SEC_PRIV_DEBUG_BIT
  7765. [2022-06-17 08:45:09.179319] 0: SEC_PRIV_SYSTEM_ENVIRONMENT_BIT
  7766. [2022-06-17 08:45:09.180856] 0: SEC_PRIV_CHANGE_NOTIFY_BIT
  7767. [2022-06-17 08:45:09.182371] 0: SEC_PRIV_UNDOCK_BIT
  7768. [2022-06-17 08:45:09.183966] 0: SEC_PRIV_ENABLE_DELEGATION_BIT
  7769. [2022-06-17 08:45:09.191776] 0: SEC_PRIV_MANAGE_VOLUME_BIT
  7770. [2022-06-17 08:45:09.193450] 0: SEC_PRIV_IMPERSONATE_BIT
  7771. [2022-06-17 08:45:09.195017] 0: SEC_PRIV_CREATE_GLOBAL_BIT
  7772. [2022-06-17 08:45:09.196668] rights_mask : 0x00000000 (0)
  7773. [2022-06-17 08:45:09.198344] 0: LSA_POLICY_MODE_INTERACTIVE
  7774. [2022-06-17 08:45:09.200020] 0: LSA_POLICY_MODE_NETWORK
  7775. [2022-06-17 08:45:09.201679] 0: LSA_POLICY_MODE_BATCH
  7776. [2022-06-17 08:45:09.203640] 0: LSA_POLICY_MODE_SERVICE
  7777. [2022-06-17 08:45:09.205331] 0: LSA_POLICY_MODE_PROXY
  7778. [2022-06-17 08:45:09.206987] 0: LSA_POLICY_MODE_DENY_INTERACTIVE
  7779. [2022-06-17 08:45:09.208647] 0: LSA_POLICY_MODE_DENY_NETWORK
  7780. [2022-06-17 08:45:09.210307] 0: LSA_POLICY_MODE_DENY_BATCH
  7781. [2022-06-17 08:45:09.211962] 0: LSA_POLICY_MODE_DENY_SERVICE
  7782. [2022-06-17 08:45:09.213699] 0: LSA_POLICY_MODE_REMOTE_INTERACTIVE
  7783. [2022-06-17 08:45:09.215370] 0: LSA_POLICY_MODE_DENY_REMOTE_INTERACTIVE
  7784. [2022-06-17 08:45:09.217032] 0x00: LSA_POLICY_MODE_ALL (0)
  7785. [2022-06-17 08:45:09.218706] 0x00: LSA_POLICY_MODE_ALL_NT4 (0)
  7786. [2022-06-17 08:45:09.220372] unix_token : *
  7787. [2022-06-17 08:45:09.222032] unix_token: struct security_unix_token
  7788. [2022-06-17 08:45:09.223730] uid : 0x000000000000fffd (65533)
  7789. [2022-06-17 08:45:09.225417] gid : 0x000000000000fffe (65534)
  7790. [2022-06-17 08:45:09.226957] ngroups : 0x00000001 (1)
  7791. [2022-06-17 08:45:09.228757] groups: ARRAY(1)
  7792. [2022-06-17 08:45:09.230413] groups : 0x000000000000fffe (65534)
  7793. [2022-06-17 08:45:09.232094] info : *
  7794. [2022-06-17 08:45:09.233801] info: struct auth_user_info
  7795. [2022-06-17 08:45:09.235466] account_name : *
  7796. [2022-06-17 08:45:09.237113] account_name : 'useruser'
  7797. [2022-06-17 08:45:09.238773] user_principal_name : NULL
  7798. [2022-06-17 08:45:09.240434] user_principal_constructed: 0x00 (0)
  7799. [2022-06-17 08:45:09.242081] domain_name : *
  7800. [2022-06-17 08:45:09.243661] domain_name : 'ZALUPA'
  7801. [2022-06-17 08:45:09.245323] dns_domain_name : NULL
  7802. [2022-06-17 08:45:09.246982] full_name : *
  7803. [2022-06-17 08:45:09.248632] full_name : 'nobody'
  7804. [2022-06-17 08:45:09.250279] logon_script : *
  7805. [2022-06-17 08:45:09.251924] logon_script : ''
  7806. [2022-06-17 08:45:09.253631] profile_path : *
  7807. [2022-06-17 08:45:09.255297] profile_path : '\\ZALUPA\useruser\profile'
  7808. [2022-06-17 08:45:09.256990] home_directory : *
  7809. [2022-06-17 08:45:09.258652] home_directory : '\\ZALUPA\useruser'
  7810. [2022-06-17 08:45:09.260312] home_drive : *
  7811. [2022-06-17 08:45:09.261958] home_drive : ''
  7812. [2022-06-17 08:45:09.263658] logon_server : *
  7813. [2022-06-17 08:45:09.265325] logon_server : 'ZALUPA'
  7814. [2022-06-17 08:45:09.266982] last_logon : NTTIME(0)
  7815. [2022-06-17 08:45:09.268641] last_logoff : Tue Jan 19 03:14:07 2038 UTC
  7816. [2022-06-17 08:45:09.270315] acct_expiry : Tue Jan 19 03:14:07 2038 UTC
  7817. [2022-06-17 08:45:09.271983] last_password_change : Thu Jun 16 22:30:51 2022 UTC
  7818. [2022-06-17 08:45:09.273710] allow_password_change : Thu Jun 16 22:30:51 2022 UTC
  7819. [2022-06-17 08:45:09.275395] force_password_change : Tue Jan 19 03:14:07 2038 UTC
  7820. [2022-06-17 08:45:09.277067] logon_count : 0x0000 (0)
  7821. [2022-06-17 08:45:09.278733] bad_password_count : 0x0000 (0)
  7822. [2022-06-17 08:45:09.280395] acct_flags : 0x00000010 (16)
  7823. [2022-06-17 08:45:09.282053] authenticated : 0x01 (1)
  7824. [2022-06-17 08:45:09.283763] unix_info : *
  7825. [2022-06-17 08:45:09.285306] unix_info: struct auth_user_info_unix
  7826. [2022-06-17 08:45:09.286816] unix_name : *
  7827. [2022-06-17 08:45:09.288456] unix_name : 'useruser'
  7828. [2022-06-17 08:45:09.290125] sanitized_username : *
  7829. [2022-06-17 08:45:09.291657] sanitized_username : 'useruser'
  7830. [2022-06-17 08:45:09.293233] torture : NULL
  7831. [2022-06-17 08:45:09.294997] credentials : NULL
  7832. [2022-06-17 08:45:09.296654] unique_session_token : 948521e3-7864-4f36-8058-4ed4b9d327d1
  7833. [2022-06-17 08:45:09.298322] connection_dialect : 0x0311 (785)
  7834. [2022-06-17 08:45:09.299959] signing_flags : 0x06 (6)
  7835. [2022-06-17 08:45:09.301604] 0: SMBXSRV_SIGNING_REQUIRED
  7836. [2022-06-17 08:45:09.303302] 1: SMBXSRV_PROCESSED_SIGNED_PACKET
  7837. [2022-06-17 08:45:09.307758] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  7838. [2022-06-17 08:45:09.313543] encryption_flags : 0x08 (8)
  7839. [2022-06-17 08:45:09.315381] 0: SMBXSRV_ENCRYPTION_REQUIRED
  7840. [2022-06-17 08:45:09.317083] 0: SMBXSRV_ENCRYPTION_DESIRED
  7841. [2022-06-17 08:45:09.323473] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  7842. [2022-06-17 08:45:09.325200] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  7843. [2022-06-17 08:45:09.326868] signing_key : *
  7844. [2022-06-17 08:45:09.328535] encryption_key : *
  7845. [2022-06-17 08:45:09.330200] decryption_key : *
  7846. [2022-06-17 08:45:09.333159] num_channels : 0x00000001 (1)
  7847. [2022-06-17 08:45:09.334858] channels: ARRAY(1)
  7848. [2022-06-17 08:45:09.336517] channels: struct smbXsrv_channel_global0
  7849. [2022-06-17 08:45:09.338158] server_id: struct server_id
  7850. [2022-06-17 08:45:09.339794] pid : 0x0000000000002574 (9588)
  7851. [2022-06-17 08:45:09.341464] task_id : 0x00000000 (0)
  7852. [2022-06-17 08:45:09.343191] vnn : 0xffffffff (4294967295)
  7853. [2022-06-17 08:45:09.344871] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  7854. [2022-06-17 08:45:09.346551] channel_id : 0x0000000000000000 (0)
  7855. [2022-06-17 08:45:09.348072] creation_time : Fri Jun 17 08:45:05 2022 UTC
  7856. [2022-06-17 08:45:09.349591] local_address : 'ipv4:192.168.1.250:445'
  7857. [2022-06-17 08:45:09.351338] remote_address : 'ipv4:192.168.1.10:33730'
  7858. [2022-06-17 08:45:09.353042] remote_name : '192.168.1.10'
  7859. [2022-06-17 08:45:09.354724] signing_key : *
  7860. [2022-06-17 08:45:09.356388] auth_session_info_seqnum : 0x00000001 (1)
  7861. [2022-06-17 08:45:09.358049] connection : *
  7862. [2022-06-17 08:45:09.359715] encryption_cipher : 0x0002 (2)
  7863. [2022-06-17 08:45:09.361368] status : NT_STATUS_OK
  7864. [2022-06-17 08:45:09.363782] idle_time : Fri Jun 17 08:45:07 2022 UTC
  7865. [2022-06-17 08:45:09.365455] nonce_high_random : 0x1b89f68e6094ef6d (1984388202199576429)
  7866. [2022-06-17 08:45:09.367128] nonce_high_max : 0x00000000ffffffff (4294967295)
  7867. [2022-06-17 08:45:09.368794] nonce_high : 0x0000000000000000 (0)
  7868. [2022-06-17 08:45:09.370466] nonce_low : 0x0000000000000000 (0)
  7869. [2022-06-17 08:45:09.372106] tcon_table : *
  7870. [2022-06-17 08:45:09.373804] homes_snum : 0xffffffff (4294967295)
  7871. [2022-06-17 08:45:09.375474] pending_auth : NULL
  7872. [2022-06-17 08:45:09.377117] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  7873. [2022-06-17 08:45:09.378764] Security token: (NULL)
  7874. [2022-06-17 08:45:09.380391] UNIX token of user 0
  7875. [2022-06-17 08:45:09.382009] Primary group is 0 and contains 0 supplementary groups
  7876. [2022-06-17 08:45:09.383710] change_to_root_user: now uid=(0,0) gid=(0,0)
  7877. [2022-06-17 08:45:09.385379] smbd_smb2_tree_connect: path[\\192.168.1.250\IPC$] share[IPC$]
  7878. [2022-06-17 08:45:09.386909] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  7879. [2022-06-17 08:45:09.388680] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  7880. [2022-06-17 08:45:09.390337] db_tdb_log_key: Locking key 5676C97C
  7881. [2022-06-17 08:45:09.391976] db_tdb_fetch_locked_internal: Allocated locked data 0xb5bd9e10
  7882. [2022-06-17 08:45:09.393589] smbXsrv_tcon_global_store: key '5676C97C' stored
  7883. [2022-06-17 08:45:09.395247] &global_blob: struct smbXsrv_tcon_globalB
  7884. [2022-06-17 08:45:09.396890] version : SMBXSRV_VERSION_0 (0)
  7885. [2022-06-17 08:45:09.398518] seqnum : 0x00000001 (1)
  7886. [2022-06-17 08:45:09.400158] info : union smbXsrv_tcon_globalU(case 0)
  7887. [2022-06-17 08:45:09.401808] info0 : *
  7888. [2022-06-17 08:45:09.403510] info0: struct smbXsrv_tcon_global0
  7889. [2022-06-17 08:45:09.405168] db_rec : *
  7890. [2022-06-17 08:45:09.406817] tcon_global_id : 0x5676c97c (1450625404)
  7891. [2022-06-17 08:45:09.408458] tcon_wire_id : 0x5676c97c (1450625404)
  7892. [2022-06-17 08:45:09.410097] server_id: struct server_id
  7893. [2022-06-17 08:45:09.411742] pid : 0x0000000000002574 (9588)
  7894. [2022-06-17 08:45:09.413434] task_id : 0x00000000 (0)
  7895. [2022-06-17 08:45:09.415115] vnn : 0xffffffff (4294967295)
  7896. [2022-06-17 08:45:09.416774] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  7897. [2022-06-17 08:45:09.418436] creation_time : Fri Jun 17 08:45:07 2022 UTC
  7898. [2022-06-17 08:45:09.420081] share_name : NULL
  7899. [2022-06-17 08:45:09.421721] encryption_flags : 0x00 (0)
  7900. [2022-06-17 08:45:09.423480] 0: SMBXSRV_ENCRYPTION_REQUIRED
  7901. [2022-06-17 08:45:09.425187] 0: SMBXSRV_ENCRYPTION_DESIRED
  7902. [2022-06-17 08:45:09.426713] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  7903. [2022-06-17 08:45:09.428225] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  7904. [2022-06-17 08:45:09.430008] session_global_id : 0x00000000 (0)
  7905. [2022-06-17 08:45:09.431672] signing_flags : 0x00 (0)
  7906. [2022-06-17 08:45:09.433362] 0: SMBXSRV_SIGNING_REQUIRED
  7907. [2022-06-17 08:45:09.435011] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  7908. [2022-06-17 08:45:09.436650] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  7909. [2022-06-17 08:45:09.438283] db_tdb_log_key: Unlocking key 5676C97C
  7910. [2022-06-17 08:45:09.439925] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  7911. [2022-06-17 08:45:09.441580] smbXsrv_tcon_create: global_id (0x5676c97c) stored
  7912. [2022-06-17 08:45:09.443155] &tcon_blob: struct smbXsrv_tconB
  7913. [2022-06-17 08:45:09.444836] version : SMBXSRV_VERSION_0 (0)
  7914. [2022-06-17 08:45:09.446345] reserved : 0x00000000 (0)
  7915. [2022-06-17 08:45:09.448084] info : union smbXsrv_tconU(case 0)
  7916. [2022-06-17 08:45:09.449726] info0 : *
  7917. [2022-06-17 08:45:09.451243] info0: struct smbXsrv_tcon
  7918. [2022-06-17 08:45:09.452739] table : *
  7919. [2022-06-17 08:45:09.454306] db_rec : NULL
  7920. [2022-06-17 08:45:09.455810] local_id : 0x5676c97c (1450625404)
  7921. [2022-06-17 08:45:09.457317] global : *
  7922. [2022-06-17 08:45:09.458806] global: struct smbXsrv_tcon_global0
  7923. [2022-06-17 08:45:09.460566] db_rec : NULL
  7924. [2022-06-17 08:45:09.462221] tcon_global_id : 0x5676c97c (1450625404)
  7925. [2022-06-17 08:45:09.463924] tcon_wire_id : 0x5676c97c (1450625404)
  7926. [2022-06-17 08:45:09.465593] server_id: struct server_id
  7927. [2022-06-17 08:45:09.467240] pid : 0x0000000000002574 (9588)
  7928. [2022-06-17 08:45:09.468894] task_id : 0x00000000 (0)
  7929. [2022-06-17 08:45:09.470532] vnn : 0xffffffff (4294967295)
  7930. [2022-06-17 08:45:09.472179] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  7931. [2022-06-17 08:45:09.473899] creation_time : Fri Jun 17 08:45:07 2022 UTC
  7932. [2022-06-17 08:45:09.475557] share_name : NULL
  7933. [2022-06-17 08:45:09.477202] encryption_flags : 0x00 (0)
  7934. [2022-06-17 08:45:09.478854] 0: SMBXSRV_ENCRYPTION_REQUIRED
  7935. [2022-06-17 08:45:09.480493] 0: SMBXSRV_ENCRYPTION_DESIRED
  7936. [2022-06-17 08:45:09.482150] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  7937. [2022-06-17 08:45:09.483865] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  7938. [2022-06-17 08:45:09.485520] session_global_id : 0x00000000 (0)
  7939. [2022-06-17 08:45:09.487171] signing_flags : 0x00 (0)
  7940. [2022-06-17 08:45:09.488821] 0: SMBXSRV_SIGNING_REQUIRED
  7941. [2022-06-17 08:45:09.490463] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  7942. [2022-06-17 08:45:09.492117] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  7943. [2022-06-17 08:45:09.493814] status : NT_STATUS_INTERNAL_ERROR
  7944. [2022-06-17 08:45:09.495461] idle_time : Fri Jun 17 08:45:07 2022 UTC
  7945. [2022-06-17 08:45:09.497112] compat : NULL
  7946. [2022-06-17 08:45:09.498748] Allowed connection from 192.168.1.10 (192.168.1.10)
  7947. [2022-06-17 08:45:09.500391] string_to_sid: SID root is not in a valid format
  7948. [2022-06-17 08:45:09.502023] lookup_name: ZALUPA\root => domain=[ZALUPA], name=[root]
  7949. [2022-06-17 08:45:09.503715] lookup_name: flags = 0x073
  7950. [2022-06-17 08:45:09.505340] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7951. [2022-06-17 08:45:09.506968] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7952. [2022-06-17 08:45:09.508605] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7953. [2022-06-17 08:45:09.510250] Security token: (NULL)
  7954. [2022-06-17 08:45:09.511873] UNIX token of user 0
  7955. [2022-06-17 08:45:09.513535] Primary group is 0 and contains 0 supplementary groups
  7956. [2022-06-17 08:45:09.515180] getsampwnam (smbpasswd): search by name: root
  7957. [2022-06-17 08:45:09.516825] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  7958. [2022-06-17 08:45:09.518465] getsmbfilepwent: skipping comment or blank line
  7959. [2022-06-17 08:45:09.520098] getsmbfilepwent: LM password for user nobody invalidated
  7960. [2022-06-17 08:45:09.521725] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  7961. [2022-06-17 08:45:09.523436] getsmbfilepwent: LM password for user useruser invalidated
  7962. [2022-06-17 08:45:09.525098] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  7963. [2022-06-17 08:45:09.526727] getsmbfilepwent: end of file reached.
  7964. [2022-06-17 08:45:09.528369] endsmbfilepwent_internal: closed password file.
  7965. [2022-06-17 08:45:09.530000] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7966. [2022-06-17 08:45:09.531625] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7967. [2022-06-17 08:45:09.533307] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7968. [2022-06-17 08:45:09.534955] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7969. [2022-06-17 08:45:09.536613] Security token: (NULL)
  7970. [2022-06-17 08:45:09.538229] UNIX token of user 0
  7971. [2022-06-17 08:45:09.539844] Primary group is 0 and contains 0 supplementary groups
  7972. [2022-06-17 08:45:09.541481] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  7973. [2022-06-17 08:45:09.543169] lookup_name: Unix User\root => domain=[Unix User], name=[root]
  7974. [2022-06-17 08:45:09.544822] lookup_name: flags = 0x073
  7975. [2022-06-17 08:45:09.546441] Finding user root
  7976. [2022-06-17 08:45:09.548060] Trying _Get_Pwnam(), username as lowercase is root
  7977. [2022-06-17 08:45:09.549701] Get_Pwnam_internals did find user [root]!
  7978. [2022-06-17 08:45:09.551341] user_ok_token: share IPC$ is ok for unix user useruser
  7979. [2022-06-17 08:45:09.563043] set_conn_connectpath: service IPC$, connectpath = /tmp
  7980. [2022-06-17 08:45:09.564946] make_connection_snum: Connect path is '/tmp' for service [IPC$]
  7981. [2022-06-17 08:45:09.566773] string_to_sid: SID root is not in a valid format
  7982. [2022-06-17 08:45:09.568446] lookup_name: ZALUPA\root => domain=[ZALUPA], name=[root]
  7983. [2022-06-17 08:45:09.570110] lookup_name: flags = 0x073
  7984. [2022-06-17 08:45:09.571746] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  7985. [2022-06-17 08:45:09.573440] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  7986. [2022-06-17 08:45:09.575091] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  7987. [2022-06-17 08:45:09.579309] Security token: (NULL)
  7988. [2022-06-17 08:45:09.581028] UNIX token of user 0
  7989. [2022-06-17 08:45:09.582684] Primary group is 0 and contains 0 supplementary groups
  7990. [2022-06-17 08:45:09.584427] getsampwnam (smbpasswd): search by name: root
  7991. [2022-06-17 08:45:09.586088] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  7992. [2022-06-17 08:45:09.587738] getsmbfilepwent: skipping comment or blank line
  7993. [2022-06-17 08:45:09.589387] getsmbfilepwent: LM password for user nobody invalidated
  7994. [2022-06-17 08:45:09.591026] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  7995. [2022-06-17 08:45:09.592683] getsmbfilepwent: LM password for user useruser invalidated
  7996. [2022-06-17 08:45:09.594400] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  7997. [2022-06-17 08:45:09.596049] getsmbfilepwent: end of file reached.
  7998. [2022-06-17 08:45:09.597692] endsmbfilepwent_internal: closed password file.
  7999. [2022-06-17 08:45:09.599349] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8000. [2022-06-17 08:45:09.600987] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8001. [2022-06-17 08:45:09.602611] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8002. [2022-06-17 08:45:09.604320] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8003. [2022-06-17 08:45:09.605966] Security token: (NULL)
  8004. [2022-06-17 08:45:09.607586] UNIX token of user 0
  8005. [2022-06-17 08:45:09.609210] Primary group is 0 and contains 0 supplementary groups
  8006. [2022-06-17 08:45:09.610738] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8007. [2022-06-17 08:45:09.612475] lookup_name: Unix User\root => domain=[Unix User], name=[root]
  8008. [2022-06-17 08:45:09.614204] lookup_name: flags = 0x073
  8009. [2022-06-17 08:45:09.615828] Finding user root
  8010. [2022-06-17 08:45:09.617416] Trying _Get_Pwnam(), username as lowercase is root
  8011. [2022-06-17 08:45:09.619055] Get_Pwnam_internals did find user [root]!
  8012. [2022-06-17 08:45:09.620691] user_ok_token: share IPC$ is ok for unix user useruser
  8013. [2022-06-17 08:45:09.622333] is_share_read_only_for_user: share IPC$ is read-only for unix user useruser
  8014. [2022-06-17 08:45:09.624065] se_file_access_check: MAX desired = 0x2000000 mapped to 0x1f01ff
  8015. [2022-06-17 08:45:09.625725] Initialising default vfs hooks
  8016. [2022-06-17 08:45:09.627229] vfs_find_backend_entry called for /[Default VFS]/
  8017. [2022-06-17 08:45:09.628951] Successfully added vfs backend '/[Default VFS]/'
  8018. [2022-06-17 08:45:09.630588] vfs_find_backend_entry called for vfs_not_implemented
  8019. [2022-06-17 08:45:09.632213] Successfully added vfs backend 'vfs_not_implemented'
  8020. [2022-06-17 08:45:09.633903] Initialising custom vfs hooks from [/[Default VFS]/]
  8021. [2022-06-17 08:45:09.635570] vfs_find_backend_entry called for /[Default VFS]/
  8022. [2022-06-17 08:45:09.637220] Successfully loaded vfs module [/[Default VFS]/] with the new modules system
  8023. [2022-06-17 08:45:09.638883] set_conn_connectpath: service IPC$, connectpath = /tmp
  8024. [2022-06-17 08:45:09.640525] string_to_sid: SID root is not in a valid format
  8025. [2022-06-17 08:45:09.642155] lookup_name: ZALUPA\root => domain=[ZALUPA], name=[root]
  8026. [2022-06-17 08:45:09.643914] lookup_name: flags = 0x073
  8027. [2022-06-17 08:45:09.645557] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8028. [2022-06-17 08:45:09.647207] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8029. [2022-06-17 08:45:09.648858] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8030. [2022-06-17 08:45:09.650494] Security token: (NULL)
  8031. [2022-06-17 08:45:09.652104] UNIX token of user 0
  8032. [2022-06-17 08:45:09.653766] Primary group is 0 and contains 0 supplementary groups
  8033. [2022-06-17 08:45:09.655415] getsampwnam (smbpasswd): search by name: root
  8034. [2022-06-17 08:45:09.657059] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  8035. [2022-06-17 08:45:09.658710] getsmbfilepwent: skipping comment or blank line
  8036. [2022-06-17 08:45:09.660338] getsmbfilepwent: LM password for user nobody invalidated
  8037. [2022-06-17 08:45:09.661975] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  8038. [2022-06-17 08:45:09.663688] getsmbfilepwent: LM password for user useruser invalidated
  8039. [2022-06-17 08:45:09.665349] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  8040. [2022-06-17 08:45:09.666987] getsmbfilepwent: end of file reached.
  8041. [2022-06-17 08:45:09.668614] endsmbfilepwent_internal: closed password file.
  8042. [2022-06-17 08:45:09.670251] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8043. [2022-06-17 08:45:09.671878] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8044. [2022-06-17 08:45:09.673572] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8045. [2022-06-17 08:45:09.675212] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8046. [2022-06-17 08:45:09.676850] Security token: (NULL)
  8047. [2022-06-17 08:45:09.678348] UNIX token of user 0
  8048. [2022-06-17 08:45:09.680074] Primary group is 0 and contains 0 supplementary groups
  8049. [2022-06-17 08:45:09.681712] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8050. [2022-06-17 08:45:09.683395] lookup_name: Unix User\root => domain=[Unix User], name=[root]
  8051. [2022-06-17 08:45:09.685063] lookup_name: flags = 0x073
  8052. [2022-06-17 08:45:09.686684] Finding user root
  8053. [2022-06-17 08:45:09.688293] Trying _Get_Pwnam(), username as lowercase is root
  8054. [2022-06-17 08:45:09.689928] Get_Pwnam_internals did find user [root]!
  8055. [2022-06-17 08:45:09.691570] user_ok_token: share IPC$ is ok for unix user useruser
  8056. [2022-06-17 08:45:09.693336] is_share_read_only_for_user: share IPC$ is read-only for unix user useruser
  8057. [2022-06-17 08:45:09.695024] se_file_access_check: MAX desired = 0x2000000 mapped to 0x1f01ff
  8058. [2022-06-17 08:45:09.696559] setting sec ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  8059. [2022-06-17 08:45:09.698305] Security token SIDs (7):
  8060. [2022-06-17 08:45:09.699910] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-132066
  8061. [2022-06-17 08:45:09.701545] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-513
  8062. [2022-06-17 08:45:09.703238] SID[ 2]: S-1-22-2-65534
  8063. [2022-06-17 08:45:09.704896] SID[ 3]: S-1-1-0
  8064. [2022-06-17 08:45:09.706525] SID[ 4]: S-1-5-2
  8065. [2022-06-17 08:45:09.708156] SID[ 5]: S-1-5-11
  8066. [2022-06-17 08:45:09.709775] SID[ 6]: S-1-22-1-65533
  8067. [2022-06-17 08:45:09.711389] Privileges (0x 0):
  8068. [2022-06-17 08:45:09.713051] Rights (0x 0):
  8069. [2022-06-17 08:45:09.714691] UNIX token of user 65533
  8070. [2022-06-17 08:45:09.716319] Primary group is 65534 and contains 1 supplementary groups
  8071. [2022-06-17 08:45:09.717960] Group[ 0]: 65534
  8072. [2022-06-17 08:45:09.719588] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/root]
  8073. [2022-06-17 08:45:09.721240] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8074. [2022-06-17 08:45:09.722758] Security token: (NULL)
  8075. [2022-06-17 08:45:09.724525] UNIX token of user 0
  8076. [2022-06-17 08:45:09.726148] Primary group is 0 and contains 0 supplementary groups
  8077. [2022-06-17 08:45:09.727784] change_to_root_user: now uid=(0,0) gid=(0,0)
  8078. [2022-06-17 08:45:09.729413] set_conn_connectpath: service IPC$, connectpath = /tmp
  8079. [2022-06-17 08:45:09.731067] vfswrap_fs_capabilities: timestamp resolution of sec available on share IPC$, directory /tmp
  8080. [2022-06-17 08:45:09.732736] linups (ipv4:192.168.1.10:33730) connect to service IPC$ initially as user useruser (uid=65533, gid=65534) (pid 9588)
  8081. [2022-06-17 08:45:09.734481] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8082. [2022-06-17 08:45:09.736122] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  8083. [2022-06-17 08:45:09.737762] db_tdb_log_key: Locking key 5676C97C
  8084. [2022-06-17 08:45:09.739380] db_tdb_fetch_locked_internal: Allocated locked data 0xb5444e80
  8085. [2022-06-17 08:45:09.741016] smbXsrv_tcon_global_store: key '5676C97C' stored
  8086. [2022-06-17 08:45:09.742541] &global_blob: struct smbXsrv_tcon_globalB
  8087. [2022-06-17 08:45:09.744395] version : SMBXSRV_VERSION_0 (0)
  8088. [2022-06-17 08:45:09.746052] seqnum : 0x00000002 (2)
  8089. [2022-06-17 08:45:09.747698] info : union smbXsrv_tcon_globalU(case 0)
  8090. [2022-06-17 08:45:09.749343] info0 : *
  8091. [2022-06-17 08:45:09.750979] info0: struct smbXsrv_tcon_global0
  8092. [2022-06-17 08:45:09.752605] db_rec : *
  8093. [2022-06-17 08:45:09.754321] tcon_global_id : 0x5676c97c (1450625404)
  8094. [2022-06-17 08:45:09.755975] tcon_wire_id : 0x5676c97c (1450625404)
  8095. [2022-06-17 08:45:09.757629] server_id: struct server_id
  8096. [2022-06-17 08:45:09.759275] pid : 0x0000000000002574 (9588)
  8097. [2022-06-17 08:45:09.760925] task_id : 0x00000000 (0)
  8098. [2022-06-17 08:45:09.762565] vnn : 0xffffffff (4294967295)
  8099. [2022-06-17 08:45:09.764302] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8100. [2022-06-17 08:45:09.765964] creation_time : Fri Jun 17 08:45:07 2022 UTC
  8101. [2022-06-17 08:45:09.767622] share_name : 'IPC$'
  8102. [2022-06-17 08:45:09.769256] encryption_flags : 0x00 (0)
  8103. [2022-06-17 08:45:09.770900] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8104. [2022-06-17 08:45:09.772521] 0: SMBXSRV_ENCRYPTION_DESIRED
  8105. [2022-06-17 08:45:09.774239] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8106. [2022-06-17 08:45:09.775898] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8107. [2022-06-17 08:45:09.777551] session_global_id : 0x6f1a4b46 (1863994182)
  8108. [2022-06-17 08:45:09.779199] signing_flags : 0x00 (0)
  8109. [2022-06-17 08:45:09.780846] 0: SMBXSRV_SIGNING_REQUIRED
  8110. [2022-06-17 08:45:09.782484] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8111. [2022-06-17 08:45:09.784196] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8112. [2022-06-17 08:45:09.785841] db_tdb_log_key: Unlocking key 5676C97C
  8113. [2022-06-17 08:45:09.787468] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8114. [2022-06-17 08:45:09.789121] smbXsrv_tcon_update: global_id (0x5676c97c) stored
  8115. [2022-06-17 08:45:09.790760] &tcon_blob: struct smbXsrv_tconB
  8116. [2022-06-17 08:45:09.792398] version : SMBXSRV_VERSION_0 (0)
  8117. [2022-06-17 08:45:09.794127] reserved : 0x00000000 (0)
  8118. [2022-06-17 08:45:09.795779] info : union smbXsrv_tconU(case 0)
  8119. [2022-06-17 08:45:09.797433] info0 : *
  8120. [2022-06-17 08:45:09.799053] info0: struct smbXsrv_tcon
  8121. [2022-06-17 08:45:09.800682] table : *
  8122. [2022-06-17 08:45:09.802316] db_rec : NULL
  8123. [2022-06-17 08:45:09.804066] local_id : 0x5676c97c (1450625404)
  8124. [2022-06-17 08:45:09.805727] global : *
  8125. [2022-06-17 08:45:09.807359] global: struct smbXsrv_tcon_global0
  8126. [2022-06-17 08:45:09.808993] db_rec : NULL
  8127. [2022-06-17 08:45:09.810504] tcon_global_id : 0x5676c97c (1450625404)
  8128. [2022-06-17 08:45:09.812147] tcon_wire_id : 0x5676c97c (1450625404)
  8129. [2022-06-17 08:45:09.813864] server_id: struct server_id
  8130. [2022-06-17 08:45:09.815527] pid : 0x0000000000002574 (9588)
  8131. [2022-06-17 08:45:09.817193] task_id : 0x00000000 (0)
  8132. [2022-06-17 08:45:09.818847] vnn : 0xffffffff (4294967295)
  8133. [2022-06-17 08:45:09.820501] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8134. [2022-06-17 08:45:09.822169] creation_time : Fri Jun 17 08:45:07 2022 UTC
  8135. [2022-06-17 08:45:09.823866] share_name : 'IPC$'
  8136. [2022-06-17 08:45:09.825504] encryption_flags : 0x00 (0)
  8137. [2022-06-17 08:45:09.827037] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8138. [2022-06-17 08:45:09.830096] 0: SMBXSRV_ENCRYPTION_DESIRED
  8139. [2022-06-17 08:45:09.836689] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8140. [2022-06-17 08:45:09.839108] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8141. [2022-06-17 08:45:09.840841] session_global_id : 0x6f1a4b46 (1863994182)
  8142. [2022-06-17 08:45:09.842519] signing_flags : 0x00 (0)
  8143. [2022-06-17 08:45:09.844259] 0: SMBXSRV_SIGNING_REQUIRED
  8144. [2022-06-17 08:45:09.845925] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8145. [2022-06-17 08:45:09.847589] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8146. [2022-06-17 08:45:09.849238] status : NT_STATUS_OK
  8147. [2022-06-17 08:45:09.850890] idle_time : Fri Jun 17 08:45:07 2022 UTC
  8148. [2022-06-17 08:45:09.852534] compat : *
  8149. [2022-06-17 08:45:09.854271] smbd_smb2_request_done_ex: mid [3] idx[1] status[NT_STATUS_OK] body[16] dyn[no:0] at ../../source3/smbd/smb2_tcon.c:186
  8150. [2022-06-17 08:45:09.855948] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/4/8192
  8151. [2022-06-17 08:45:09.857668] signed SMB2 message
  8152. [2022-06-17 08:45:09.859292] smbd_smb2_request idx[1] of 5 vectors
  8153. [2022-06-17 08:45:09.860941] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 4 (position 4) from bitmap
  8154. [2022-06-17 08:45:09.862610] smbd_smb2_request_dispatch: opcode[SMB2_OP_IOCTL] mid = 4
  8155. [2022-06-17 08:45:09.864343] setting sec ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  8156. [2022-06-17 08:45:09.865999] Security token SIDs (7):
  8157. [2022-06-17 08:45:09.867610] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-132066
  8158. [2022-06-17 08:45:09.869245] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-513
  8159. [2022-06-17 08:45:09.870888] SID[ 2]: S-1-22-2-65534
  8160. [2022-06-17 08:45:09.872519] SID[ 3]: S-1-1-0
  8161. [2022-06-17 08:45:09.874230] SID[ 4]: S-1-5-2
  8162. [2022-06-17 08:45:09.875860] SID[ 5]: S-1-5-11
  8163. [2022-06-17 08:45:09.877354] SID[ 6]: S-1-22-1-65533
  8164. [2022-06-17 08:45:09.879049] Privileges (0x 0):
  8165. [2022-06-17 08:45:09.880687] Rights (0x 0):
  8166. [2022-06-17 08:45:09.882321] UNIX token of user 65533
  8167. [2022-06-17 08:45:09.884035] Primary group is 65534 and contains 1 supplementary groups
  8168. [2022-06-17 08:45:09.885683] Group[ 0]: 65534
  8169. [2022-06-17 08:45:09.887306] vfs_ChDir to /tmp
  8170. [2022-06-17 08:45:09.888918] vfs_ChDir: vfs_ChDir got /tmp
  8171. [2022-06-17 08:45:09.890548] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/tmp]
  8172. [2022-06-17 08:45:09.892201] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8173. [2022-06-17 08:45:09.893906] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  8174. [2022-06-17 08:45:09.895696] db_tdb_log_key: Locking key 5676C97C
  8175. [2022-06-17 08:45:09.897339] db_tdb_fetch_locked_internal: Allocated locked data 0xb56bbee0
  8176. [2022-06-17 08:45:09.898987] smbXsrv_tcon_global_store: key '5676C97C' stored
  8177. [2022-06-17 08:45:09.900623] &global_blob: struct smbXsrv_tcon_globalB
  8178. [2022-06-17 08:45:09.902258] version : SMBXSRV_VERSION_0 (0)
  8179. [2022-06-17 08:45:09.903978] seqnum : 0x00000003 (3)
  8180. [2022-06-17 08:45:09.905643] info : union smbXsrv_tcon_globalU(case 0)
  8181. [2022-06-17 08:45:09.907302] info0 : *
  8182. [2022-06-17 08:45:09.908945] info0: struct smbXsrv_tcon_global0
  8183. [2022-06-17 08:45:09.910581] db_rec : *
  8184. [2022-06-17 08:45:09.912215] tcon_global_id : 0x5676c97c (1450625404)
  8185. [2022-06-17 08:45:09.913900] tcon_wire_id : 0x5676c97c (1450625404)
  8186. [2022-06-17 08:45:09.915552] server_id: struct server_id
  8187. [2022-06-17 08:45:09.917187] pid : 0x0000000000002574 (9588)
  8188. [2022-06-17 08:45:09.918846] task_id : 0x00000000 (0)
  8189. [2022-06-17 08:45:09.920510] vnn : 0xffffffff (4294967295)
  8190. [2022-06-17 08:45:09.922162] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8191. [2022-06-17 08:45:09.923881] creation_time : Fri Jun 17 08:45:07 2022 UTC
  8192. [2022-06-17 08:45:09.925540] share_name : 'IPC$'
  8193. [2022-06-17 08:45:09.927183] encryption_flags : 0x08 (8)
  8194. [2022-06-17 08:45:09.928822] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8195. [2022-06-17 08:45:09.930453] 0: SMBXSRV_ENCRYPTION_DESIRED
  8196. [2022-06-17 08:45:09.932090] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8197. [2022-06-17 08:45:09.933799] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8198. [2022-06-17 08:45:09.935461] session_global_id : 0x6f1a4b46 (1863994182)
  8199. [2022-06-17 08:45:09.937108] signing_flags : 0x04 (4)
  8200. [2022-06-17 08:45:09.938742] 0: SMBXSRV_SIGNING_REQUIRED
  8201. [2022-06-17 08:45:09.940350] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8202. [2022-06-17 08:45:09.941872] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8203. [2022-06-17 08:45:09.943553] db_tdb_log_key: Unlocking key 5676C97C
  8204. [2022-06-17 08:45:09.945220] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8205. [2022-06-17 08:45:09.946879] smbXsrv_tcon_update: global_id (0x5676c97c) stored
  8206. [2022-06-17 08:45:09.948521] &tcon_blob: struct smbXsrv_tconB
  8207. [2022-06-17 08:45:09.950168] version : SMBXSRV_VERSION_0 (0)
  8208. [2022-06-17 08:45:09.951805] reserved : 0x00000000 (0)
  8209. [2022-06-17 08:45:09.953499] info : union smbXsrv_tconU(case 0)
  8210. [2022-06-17 08:45:09.955150] info0 : *
  8211. [2022-06-17 08:45:09.956797] info0: struct smbXsrv_tcon
  8212. [2022-06-17 08:45:09.958429] table : *
  8213. [2022-06-17 08:45:09.959958] db_rec : NULL
  8214. [2022-06-17 08:45:09.961452] local_id : 0x5676c97c (1450625404)
  8215. [2022-06-17 08:45:09.963292] global : *
  8216. [2022-06-17 08:45:09.964947] global: struct smbXsrv_tcon_global0
  8217. [2022-06-17 08:45:09.966583] db_rec : NULL
  8218. [2022-06-17 08:45:09.968215] tcon_global_id : 0x5676c97c (1450625404)
  8219. [2022-06-17 08:45:09.969867] tcon_wire_id : 0x5676c97c (1450625404)
  8220. [2022-06-17 08:45:09.971524] server_id: struct server_id
  8221. [2022-06-17 08:45:09.973206] pid : 0x0000000000002574 (9588)
  8222. [2022-06-17 08:45:09.974876] task_id : 0x00000000 (0)
  8223. [2022-06-17 08:45:09.976526] vnn : 0xffffffff (4294967295)
  8224. [2022-06-17 08:45:09.978157] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8225. [2022-06-17 08:45:09.979854] creation_time : Fri Jun 17 08:45:07 2022 UTC
  8226. [2022-06-17 08:45:09.981518] share_name : 'IPC$'
  8227. [2022-06-17 08:45:09.983107] encryption_flags : 0x08 (8)
  8228. [2022-06-17 08:45:09.984878] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8229. [2022-06-17 08:45:09.986532] 0: SMBXSRV_ENCRYPTION_DESIRED
  8230. [2022-06-17 08:45:09.988061] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8231. [2022-06-17 08:45:09.989839] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8232. [2022-06-17 08:45:09.991476] session_global_id : 0x6f1a4b46 (1863994182)
  8233. [2022-06-17 08:45:09.993191] signing_flags : 0x04 (4)
  8234. [2022-06-17 08:45:09.994854] 0: SMBXSRV_SIGNING_REQUIRED
  8235. [2022-06-17 08:45:09.996510] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8236. [2022-06-17 08:45:09.998140] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8237. [2022-06-17 08:45:09.999774] status : NT_STATUS_OK
  8238. [2022-06-17 08:45:10.001406] idle_time : Fri Jun 17 08:45:08 2022 UTC
  8239. [2022-06-17 08:45:10.003087] compat : *
  8240. [2022-06-17 08:45:10.004749] smbd_smb2_request_verify_creditcharge: mid 4, CreditCharge: 1, NeededCharge: 1
  8241. [2022-06-17 08:45:10.006413] smbd_smb2_ioctl: ctl_code[0x00060194] <no handle>, fnum [fsp is NULL]
  8242. [2022-06-17 08:45:10.008076] dfs_GetDFSReferral: struct dfs_GetDFSReferral
  8243. [2022-06-17 08:45:10.009708] in: struct dfs_GetDFSReferral
  8244. [2022-06-17 08:45:10.011337] req: struct dfs_GetDFSReferral_in
  8245. [2022-06-17 08:45:10.013019] max_referral_level : 0x0003 (3)
  8246. [2022-06-17 08:45:10.014671] servername : '\192.168.1.250\shr'
  8247. [2022-06-17 08:45:10.016326] parse_dfs_path: temp = |192.168.1.250\shr| after trimming \'s
  8248. [2022-06-17 08:45:10.017982] parse_dfs_path: hostname: 192.168.1.250
  8249. [2022-06-17 08:45:10.019616] parse_dfs_path: servicename: shr
  8250. [2022-06-17 08:45:10.021249] get_referred_path: |shr| in dfs path \192.168.1.250\shr is not a dfs root.
  8251. [2022-06-17 08:45:10.022942] smbd_smb2_request_ioctl_done: smbd_smb2_ioctl_recv returned 0 status NT_STATUS_NOT_FOUND
  8252. [2022-06-17 08:45:10.024620] smbd_smb2_request_error_ex: smbd_smb2_request_error_ex: idx[1] status[NT_STATUS_NOT_FOUND] || at ../../source3/smbd/smb2_ioctl.c:353
  8253. [2022-06-17 08:45:10.026584] smbd_smb2_request_done_ex: mid [4] idx[1] status[NT_STATUS_NOT_FOUND] body[8] dyn[yes:1] at ../../source3/smbd/smb2_server.c:3909
  8254. [2022-06-17 08:45:10.028291] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/5/8192
  8255. [2022-06-17 08:45:10.030023] smbd_smb2_request idx[1] of 5 vectors
  8256. [2022-06-17 08:45:10.031668] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 5 (position 5) from bitmap
  8257. [2022-06-17 08:45:10.033404] smbd_smb2_request_dispatch: opcode[SMB2_OP_TDIS] mid = 5
  8258. [2022-06-17 08:45:10.035056] change_to_user_impersonate: Skipping user change - already user
  8259. [2022-06-17 08:45:10.036705] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/tmp]
  8260. [2022-06-17 08:45:10.038359] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8261. [2022-06-17 08:45:10.039992] Security token: (NULL)
  8262. [2022-06-17 08:45:10.041608] UNIX token of user 0
  8263. [2022-06-17 08:45:10.043275] Primary group is 0 and contains 0 supplementary groups
  8264. [2022-06-17 08:45:10.044938] change_to_root_user: now uid=(0,0) gid=(0,0)
  8265. [2022-06-17 08:45:10.046581] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8266. [2022-06-17 08:45:10.048210] Security token: (NULL)
  8267. [2022-06-17 08:45:10.049834] UNIX token of user 0
  8268. [2022-06-17 08:45:10.051448] Primary group is 0 and contains 0 supplementary groups
  8269. [2022-06-17 08:45:10.053146] change_to_root_user: now uid=(0,0) gid=(0,0)
  8270. [2022-06-17 08:45:10.054811] vfs_ChDir to /tmp
  8271. [2022-06-17 08:45:10.056446] vfs_ChDir: vfs_ChDir got /tmp
  8272. [2022-06-17 08:45:10.058071] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8273. [2022-06-17 08:45:10.059705] Security token: (NULL)
  8274. [2022-06-17 08:45:10.061320] UNIX token of user 0
  8275. [2022-06-17 08:45:10.063206] Primary group is 0 and contains 0 supplementary groups
  8276. [2022-06-17 08:45:10.064951] change_to_root_user: now uid=(0,0) gid=(0,0)
  8277. [2022-06-17 08:45:10.066632] linups (ipv4:192.168.1.10:33730) closed connection to service IPC$
  8278. [2022-06-17 08:45:10.068375] vfs_ChDir to /
  8279. [2022-06-17 08:45:10.070016] vfs_ChDir: vfs_ChDir got /
  8280. [2022-06-17 08:45:10.071622] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8281. [2022-06-17 08:45:10.073298] Security token: (NULL)
  8282. [2022-06-17 08:45:10.074928] UNIX token of user 0
  8283. [2022-06-17 08:45:10.076644] Primary group is 0 and contains 0 supplementary groups
  8284. [2022-06-17 08:45:10.078322] change_to_root_user: now uid=(0,0) gid=(0,0)
  8285. [2022-06-17 08:45:10.079975] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8286. [2022-06-17 08:45:10.081628] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  8287. [2022-06-17 08:45:10.083318] db_tdb_log_key: Locking key 5676C97C
  8288. [2022-06-17 08:45:10.084955] db_tdb_fetch_locked_internal: Allocated locked data 0xb5c3ee70
  8289. [2022-06-17 08:45:10.086608] db_tdb_log_key: Unlocking key 5676C97C
  8290. [2022-06-17 08:45:10.088226] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8291. [2022-06-17 08:45:10.089878] smbd_smb2_request_done_ex: mid [5] idx[1] status[NT_STATUS_OK] body[4] dyn[no:0] at ../../source3/smbd/smb2_tcon.c:560
  8292. [2022-06-17 08:45:10.091568] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/6/8192
  8293. [2022-06-17 08:45:10.093340] smbd_smb2_request idx[1] of 5 vectors
  8294. [2022-06-17 08:45:10.094993] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 6 (position 6) from bitmap
  8295. [2022-06-17 08:45:10.096663] smbd_smb2_request_dispatch: opcode[SMB2_OP_TCON] mid = 6
  8296. [2022-06-17 08:45:10.098300] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8297. [2022-06-17 08:45:10.099934] Security token: (NULL)
  8298. [2022-06-17 08:45:10.101543] UNIX token of user 0
  8299. [2022-06-17 08:45:10.103216] Primary group is 0 and contains 0 supplementary groups
  8300. [2022-06-17 08:45:10.104871] change_to_root_user: now uid=(0,0) gid=(0,0)
  8301. [2022-06-17 08:45:10.106508] smbd_smb2_tree_connect: path[\\192.168.1.250\shr] share[shr]
  8302. [2022-06-17 08:45:10.108147] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8303. [2022-06-17 08:45:10.109800] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  8304. [2022-06-17 08:45:10.111325] db_tdb_log_key: Locking key E48C8ACD
  8305. [2022-06-17 08:45:10.113138] db_tdb_fetch_locked_internal: Allocated locked data 0xb5f16c70
  8306. [2022-06-17 08:45:10.114809] smbXsrv_tcon_global_store: key 'E48C8ACD' stored
  8307. [2022-06-17 08:45:10.116456] &global_blob: struct smbXsrv_tcon_globalB
  8308. [2022-06-17 08:45:10.118096] version : SMBXSRV_VERSION_0 (0)
  8309. [2022-06-17 08:45:10.119751] seqnum : 0x00000001 (1)
  8310. [2022-06-17 08:45:10.121400] info : union smbXsrv_tcon_globalU(case 0)
  8311. [2022-06-17 08:45:10.123087] info0 : *
  8312. [2022-06-17 08:45:10.124725] info0: struct smbXsrv_tcon_global0
  8313. [2022-06-17 08:45:10.126369] db_rec : *
  8314. [2022-06-17 08:45:10.128014] tcon_global_id : 0xe48c8acd (3834415821)
  8315. [2022-06-17 08:45:10.129674] tcon_wire_id : 0xe48c8acd (3834415821)
  8316. [2022-06-17 08:45:10.131309] server_id: struct server_id
  8317. [2022-06-17 08:45:10.132987] pid : 0x0000000000002574 (9588)
  8318. [2022-06-17 08:45:10.134645] task_id : 0x00000000 (0)
  8319. [2022-06-17 08:45:10.136296] vnn : 0xffffffff (4294967295)
  8320. [2022-06-17 08:45:10.137944] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8321. [2022-06-17 08:45:10.139598] creation_time : Fri Jun 17 08:45:08 2022 UTC
  8322. [2022-06-17 08:45:10.141234] share_name : NULL
  8323. [2022-06-17 08:45:10.142925] encryption_flags : 0x00 (0)
  8324. [2022-06-17 08:45:10.144588] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8325. [2022-06-17 08:45:10.146231] 0: SMBXSRV_ENCRYPTION_DESIRED
  8326. [2022-06-17 08:45:10.147880] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8327. [2022-06-17 08:45:10.149521] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8328. [2022-06-17 08:45:10.151166] session_global_id : 0x00000000 (0)
  8329. [2022-06-17 08:45:10.152796] signing_flags : 0x00 (0)
  8330. [2022-06-17 08:45:10.154509] 0: SMBXSRV_SIGNING_REQUIRED
  8331. [2022-06-17 08:45:10.156158] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8332. [2022-06-17 08:45:10.157797] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8333. [2022-06-17 08:45:10.159431] db_tdb_log_key: Unlocking key E48C8ACD
  8334. [2022-06-17 08:45:10.161058] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8335. [2022-06-17 08:45:10.162714] smbXsrv_tcon_create: global_id (0xe48c8acd) stored
  8336. [2022-06-17 08:45:10.164435] &tcon_blob: struct smbXsrv_tconB
  8337. [2022-06-17 08:45:10.166071] version : SMBXSRV_VERSION_0 (0)
  8338. [2022-06-17 08:45:10.167709] reserved : 0x00000000 (0)
  8339. [2022-06-17 08:45:10.169337] info : union smbXsrv_tconU(case 0)
  8340. [2022-06-17 08:45:10.170967] info0 : *
  8341. [2022-06-17 08:45:10.172488] info0: struct smbXsrv_tcon
  8342. [2022-06-17 08:45:10.174054] table : *
  8343. [2022-06-17 08:45:10.175553] db_rec : NULL
  8344. [2022-06-17 08:45:10.177287] local_id : 0xe48c8acd (3834415821)
  8345. [2022-06-17 08:45:10.178945] global : *
  8346. [2022-06-17 08:45:10.180587] global: struct smbXsrv_tcon_global0
  8347. [2022-06-17 08:45:10.182231] db_rec : NULL
  8348. [2022-06-17 08:45:10.183912] tcon_global_id : 0xe48c8acd (3834415821)
  8349. [2022-06-17 08:45:10.185563] tcon_wire_id : 0xe48c8acd (3834415821)
  8350. [2022-06-17 08:45:10.187226] server_id: struct server_id
  8351. [2022-06-17 08:45:10.188872] pid : 0x0000000000002574 (9588)
  8352. [2022-06-17 08:45:10.190537] task_id : 0x00000000 (0)
  8353. [2022-06-17 08:45:10.192189] vnn : 0xffffffff (4294967295)
  8354. [2022-06-17 08:45:10.193886] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8355. [2022-06-17 08:45:10.195555] creation_time : Fri Jun 17 08:45:08 2022 UTC
  8356. [2022-06-17 08:45:10.197200] share_name : NULL
  8357. [2022-06-17 08:45:10.198846] encryption_flags : 0x00 (0)
  8358. [2022-06-17 08:45:10.200490] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8359. [2022-06-17 08:45:10.202139] 0: SMBXSRV_ENCRYPTION_DESIRED
  8360. [2022-06-17 08:45:10.203821] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8361. [2022-06-17 08:45:10.205475] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8362. [2022-06-17 08:45:10.207134] session_global_id : 0x00000000 (0)
  8363. [2022-06-17 08:45:10.208778] signing_flags : 0x00 (0)
  8364. [2022-06-17 08:45:10.210412] 0: SMBXSRV_SIGNING_REQUIRED
  8365. [2022-06-17 08:45:10.212057] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8366. [2022-06-17 08:45:10.213756] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8367. [2022-06-17 08:45:10.215427] status : NT_STATUS_INTERNAL_ERROR
  8368. [2022-06-17 08:45:10.217230] idle_time : Fri Jun 17 08:45:08 2022 UTC
  8369. [2022-06-17 08:45:10.218916] compat : NULL
  8370. [2022-06-17 08:45:10.220565] Allowed connection from 192.168.1.10 (192.168.1.10)
  8371. [2022-06-17 08:45:10.222201] string_to_sid: SID root is not in a valid format
  8372. [2022-06-17 08:45:10.223899] lookup_name: ZALUPA\root => domain=[ZALUPA], name=[root]
  8373. [2022-06-17 08:45:10.225558] lookup_name: flags = 0x073
  8374. [2022-06-17 08:45:10.227186] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8375. [2022-06-17 08:45:10.228813] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8376. [2022-06-17 08:45:10.230435] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8377. [2022-06-17 08:45:10.232059] Security token: (NULL)
  8378. [2022-06-17 08:45:10.233734] UNIX token of user 0
  8379. [2022-06-17 08:45:10.235250] Primary group is 0 and contains 0 supplementary groups
  8380. [2022-06-17 08:45:10.236760] getsampwnam (smbpasswd): search by name: root
  8381. [2022-06-17 08:45:10.238248] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  8382. [2022-06-17 08:45:10.239739] getsmbfilepwent: skipping comment or blank line
  8383. [2022-06-17 08:45:10.241226] getsmbfilepwent: LM password for user nobody invalidated
  8384. [2022-06-17 08:45:10.242719] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  8385. [2022-06-17 08:45:10.244534] getsmbfilepwent: LM password for user useruser invalidated
  8386. [2022-06-17 08:45:10.246194] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  8387. [2022-06-17 08:45:10.247846] getsmbfilepwent: end of file reached.
  8388. [2022-06-17 08:45:10.249365] endsmbfilepwent_internal: closed password file.
  8389. [2022-06-17 08:45:10.250864] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8390. [2022-06-17 08:45:10.252356] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8391. [2022-06-17 08:45:10.253949] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8392. [2022-06-17 08:45:10.255646] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8393. [2022-06-17 08:45:10.257405] Security token: (NULL)
  8394. [2022-06-17 08:45:10.259031] UNIX token of user 0
  8395. [2022-06-17 08:45:10.260545] Primary group is 0 and contains 0 supplementary groups
  8396. [2022-06-17 08:45:10.262256] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8397. [2022-06-17 08:45:10.263949] lookup_name: Unix User\root => domain=[Unix User], name=[root]
  8398. [2022-06-17 08:45:10.265597] lookup_name: flags = 0x073
  8399. [2022-06-17 08:45:10.267217] Finding user root
  8400. [2022-06-17 08:45:10.268829] Trying _Get_Pwnam(), username as lowercase is root
  8401. [2022-06-17 08:45:10.270462] Get_Pwnam_internals did find user [root]!
  8402. [2022-06-17 08:45:10.272100] user_ok_token: share shr is ok for unix user useruser
  8403. [2022-06-17 08:45:10.273801] set_conn_connectpath: service shr, connectpath = /mnt/share
  8404. [2022-06-17 08:45:10.275449] make_connection_snum: Connect path is '/mnt/share/' for service [shr]
  8405. [2022-06-17 08:45:10.277101] string_to_sid: SID root is not in a valid format
  8406. [2022-06-17 08:45:10.278730] lookup_name: ZALUPA\root => domain=[ZALUPA], name=[root]
  8407. [2022-06-17 08:45:10.280358] lookup_name: flags = 0x073
  8408. [2022-06-17 08:45:10.281967] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8409. [2022-06-17 08:45:10.283656] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8410. [2022-06-17 08:45:10.285303] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8411. [2022-06-17 08:45:10.286957] Security token: (NULL)
  8412. [2022-06-17 08:45:10.288568] UNIX token of user 0
  8413. [2022-06-17 08:45:10.290184] Primary group is 0 and contains 0 supplementary groups
  8414. [2022-06-17 08:45:10.291811] getsampwnam (smbpasswd): search by name: root
  8415. [2022-06-17 08:45:10.293380] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  8416. [2022-06-17 08:45:10.295009] getsmbfilepwent: skipping comment or blank line
  8417. [2022-06-17 08:45:10.296667] getsmbfilepwent: LM password for user nobody invalidated
  8418. [2022-06-17 08:45:10.298309] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  8419. [2022-06-17 08:45:10.299935] getsmbfilepwent: LM password for user useruser invalidated
  8420. [2022-06-17 08:45:10.301567] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  8421. [2022-06-17 08:45:10.303268] getsmbfilepwent: end of file reached.
  8422. [2022-06-17 08:45:10.304924] endsmbfilepwent_internal: closed password file.
  8423. [2022-06-17 08:45:10.306572] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8424. [2022-06-17 08:45:10.308220] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8425. [2022-06-17 08:45:10.309854] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8426. [2022-06-17 08:45:10.311485] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8427. [2022-06-17 08:45:10.313170] Security token: (NULL)
  8428. [2022-06-17 08:45:10.314802] UNIX token of user 0
  8429. [2022-06-17 08:45:10.316427] Primary group is 0 and contains 0 supplementary groups
  8430. [2022-06-17 08:45:10.318063] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8431. [2022-06-17 08:45:10.319709] lookup_name: Unix User\root => domain=[Unix User], name=[root]
  8432. [2022-06-17 08:45:10.321362] lookup_name: flags = 0x073
  8433. [2022-06-17 08:45:10.323029] Finding user root
  8434. [2022-06-17 08:45:10.324630] Trying _Get_Pwnam(), username as lowercase is root
  8435. [2022-06-17 08:45:10.326162] Get_Pwnam_internals did find user [root]!
  8436. [2022-06-17 08:45:10.327659] user_ok_token: share shr is ok for unix user useruser
  8437. [2022-06-17 08:45:10.329163] is_share_read_only_for_user: share shr is read-write for unix user useruser
  8438. [2022-06-17 08:45:10.330672] se_file_access_check: MAX desired = 0x2000000 mapped to 0x1f01ff
  8439. [2022-06-17 08:45:10.332171] Initialising default vfs hooks
  8440. [2022-06-17 08:45:10.333734] Initialising custom vfs hooks from [/[Default VFS]/]
  8441. [2022-06-17 08:45:10.335238] vfs_find_backend_entry called for /[Default VFS]/
  8442. [2022-06-17 08:45:10.336734] Successfully loaded vfs module [/[Default VFS]/] with the new modules system
  8443. [2022-06-17 08:45:10.338392] Initialising custom vfs hooks from [io_uring]
  8444. [2022-06-17 08:45:10.339940] vfs_find_backend_entry called for io_uring
  8445. [2022-06-17 08:45:10.341451] vfs module [io_uring] not loaded - trying to load...
  8446. [2022-06-17 08:45:10.342992] load_module_absolute_path: Loading module '/usr/lib/samba/vfs/io_uring.so'
  8447. [2022-06-17 08:45:10.344518] load_module_absolute_path: Module '/usr/lib/samba/vfs/io_uring.so' loaded
  8448. [2022-06-17 08:45:10.346033] vfs_find_backend_entry called for io_uring
  8449. [2022-06-17 08:45:10.347527] Successfully added vfs backend 'io_uring'
  8450. [2022-06-17 08:45:10.349003] vfs_find_backend_entry called for io_uring
  8451. [2022-06-17 08:45:10.350491] Successfully loaded vfs module [io_uring] with the new modules system
  8452. [2022-06-17 08:45:10.351987] notify_init: notifyd=9560
  8453. [2022-06-17 08:45:10.353712] Registering messaging pointer for type 784 - private_data=0xb5bd9db0
  8454. [2022-06-17 08:45:10.355266] Registering messaging pointer for type 793 - private_data=0xb5829e80
  8455. [2022-06-17 08:45:10.356781] Registering messaging pointer for type 799 - private_data=0xb5829e80
  8456. [2022-06-17 08:45:10.358278] set_conn_connectpath: service shr, connectpath = /mnt/share
  8457. [2022-06-17 08:45:10.359766] string_to_sid: SID root is not in a valid format
  8458. [2022-06-17 08:45:10.361393] lookup_name: ZALUPA\root => domain=[ZALUPA], name=[root]
  8459. [2022-06-17 08:45:10.363436] lookup_name: flags = 0x073
  8460. [2022-06-17 08:45:10.364965] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8461. [2022-06-17 08:45:10.366471] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8462. [2022-06-17 08:45:10.368820] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8463. [2022-06-17 08:45:10.370588] Security token: (NULL)
  8464. [2022-06-17 08:45:10.372217] UNIX token of user 0
  8465. [2022-06-17 08:45:10.373895] Primary group is 0 and contains 0 supplementary groups
  8466. [2022-06-17 08:45:10.375539] getsampwnam (smbpasswd): search by name: root
  8467. [2022-06-17 08:45:10.377184] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  8468. [2022-06-17 08:45:10.378841] getsmbfilepwent: skipping comment or blank line
  8469. [2022-06-17 08:45:10.380497] getsmbfilepwent: LM password for user nobody invalidated
  8470. [2022-06-17 08:45:10.382131] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  8471. [2022-06-17 08:45:10.383841] getsmbfilepwent: LM password for user useruser invalidated
  8472. [2022-06-17 08:45:10.385486] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  8473. [2022-06-17 08:45:10.387145] getsmbfilepwent: end of file reached.
  8474. [2022-06-17 08:45:10.388780] endsmbfilepwent_internal: closed password file.
  8475. [2022-06-17 08:45:10.390433] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8476. [2022-06-17 08:45:10.392068] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
  8477. [2022-06-17 08:45:10.393762] push_conn_ctx(0) : conn_ctx_stack_ndx = 0
  8478. [2022-06-17 08:45:10.395404] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8479. [2022-06-17 08:45:10.397045] Security token: (NULL)
  8480. [2022-06-17 08:45:10.398665] UNIX token of user 0
  8481. [2022-06-17 08:45:10.400295] Primary group is 0 and contains 0 supplementary groups
  8482. [2022-06-17 08:45:10.401934] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
  8483. [2022-06-17 08:45:10.403624] lookup_name: Unix User\root => domain=[Unix User], name=[root]
  8484. [2022-06-17 08:45:10.405285] lookup_name: flags = 0x073
  8485. [2022-06-17 08:45:10.406905] Finding user root
  8486. [2022-06-17 08:45:10.408512] Trying _Get_Pwnam(), username as lowercase is root
  8487. [2022-06-17 08:45:10.410150] Get_Pwnam_internals did find user [root]!
  8488. [2022-06-17 08:45:10.411780] user_ok_token: share shr is ok for unix user useruser
  8489. [2022-06-17 08:45:10.413511] is_share_read_only_for_user: share shr is read-write for unix user useruser
  8490. [2022-06-17 08:45:10.415199] se_file_access_check: MAX desired = 0x2000000 mapped to 0x1f01ff
  8491. [2022-06-17 08:45:10.416868] setting sec ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  8492. [2022-06-17 08:45:10.418513] Security token SIDs (7):
  8493. [2022-06-17 08:45:10.420127] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-132066
  8494. [2022-06-17 08:45:10.421757] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-513
  8495. [2022-06-17 08:45:10.423447] SID[ 2]: S-1-22-2-65534
  8496. [2022-06-17 08:45:10.425076] SID[ 3]: S-1-1-0
  8497. [2022-06-17 08:45:10.426698] SID[ 4]: S-1-5-2
  8498. [2022-06-17 08:45:10.428319] SID[ 5]: S-1-5-11
  8499. [2022-06-17 08:45:10.429936] SID[ 6]: S-1-22-1-65533
  8500. [2022-06-17 08:45:10.431545] Privileges (0x 0):
  8501. [2022-06-17 08:45:10.433233] Rights (0x 0):
  8502. [2022-06-17 08:45:10.434879] UNIX token of user 65533
  8503. [2022-06-17 08:45:10.436506] Primary group is 65534 and contains 1 supplementary groups
  8504. [2022-06-17 08:45:10.438140] Group[ 0]: 65534
  8505. [2022-06-17 08:45:10.439758] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/]
  8506. [2022-06-17 08:45:10.441412] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  8507. [2022-06-17 08:45:10.443113] Security token: (NULL)
  8508. [2022-06-17 08:45:10.444743] UNIX token of user 0
  8509. [2022-06-17 08:45:10.446358] Primary group is 0 and contains 0 supplementary groups
  8510. [2022-06-17 08:45:10.447984] change_to_root_user: now uid=(0,0) gid=(0,0)
  8511. [2022-06-17 08:45:10.449627] set_conn_connectpath: service shr, connectpath = /mnt/share
  8512. [2022-06-17 08:45:10.451278] linups (ipv4:192.168.1.10:33730) connect to service shr initially as user useruser (uid=65533, gid=65534) (pid 9588)
  8513. [2022-06-17 08:45:10.453007] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8514. [2022-06-17 08:45:10.454686] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  8515. [2022-06-17 08:45:10.456343] db_tdb_log_key: Locking key E48C8ACD
  8516. [2022-06-17 08:45:10.457967] db_tdb_fetch_locked_internal: Allocated locked data 0xb56bbeb0
  8517. [2022-06-17 08:45:10.459628] smbXsrv_tcon_global_store: key 'E48C8ACD' stored
  8518. [2022-06-17 08:45:10.461264] &global_blob: struct smbXsrv_tcon_globalB
  8519. [2022-06-17 08:45:10.462987] version : SMBXSRV_VERSION_0 (0)
  8520. [2022-06-17 08:45:10.464718] seqnum : 0x00000002 (2)
  8521. [2022-06-17 08:45:10.466376] info : union smbXsrv_tcon_globalU(case 0)
  8522. [2022-06-17 08:45:10.468026] info0 : *
  8523. [2022-06-17 08:45:10.469661] info0: struct smbXsrv_tcon_global0
  8524. [2022-06-17 08:45:10.471300] db_rec : *
  8525. [2022-06-17 08:45:10.472988] tcon_global_id : 0xe48c8acd (3834415821)
  8526. [2022-06-17 08:45:10.474661] tcon_wire_id : 0xe48c8acd (3834415821)
  8527. [2022-06-17 08:45:10.476325] server_id: struct server_id
  8528. [2022-06-17 08:45:10.477968] pid : 0x0000000000002574 (9588)
  8529. [2022-06-17 08:45:10.479608] task_id : 0x00000000 (0)
  8530. [2022-06-17 08:45:10.481246] vnn : 0xffffffff (4294967295)
  8531. [2022-06-17 08:45:10.482922] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8532. [2022-06-17 08:45:10.484605] creation_time : Fri Jun 17 08:45:08 2022 UTC
  8533. [2022-06-17 08:45:10.486268] share_name : 'shr'
  8534. [2022-06-17 08:45:10.487925] encryption_flags : 0x00 (0)
  8535. [2022-06-17 08:45:10.489576] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8536. [2022-06-17 08:45:10.491208] 0: SMBXSRV_ENCRYPTION_DESIRED
  8537. [2022-06-17 08:45:10.492844] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8538. [2022-06-17 08:45:10.494542] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8539. [2022-06-17 08:45:10.496198] session_global_id : 0x6f1a4b46 (1863994182)
  8540. [2022-06-17 08:45:10.497842] signing_flags : 0x00 (0)
  8541. [2022-06-17 08:45:10.499506] 0: SMBXSRV_SIGNING_REQUIRED
  8542. [2022-06-17 08:45:10.501144] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8543. [2022-06-17 08:45:10.502799] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8544. [2022-06-17 08:45:10.504504] db_tdb_log_key: Unlocking key E48C8ACD
  8545. [2022-06-17 08:45:10.506142] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8546. [2022-06-17 08:45:10.507786] smbXsrv_tcon_update: global_id (0xe48c8acd) stored
  8547. [2022-06-17 08:45:10.509428] &tcon_blob: struct smbXsrv_tconB
  8548. [2022-06-17 08:45:10.511054] version : SMBXSRV_VERSION_0 (0)
  8549. [2022-06-17 08:45:10.512711] reserved : 0x00000000 (0)
  8550. [2022-06-17 08:45:10.514432] info : union smbXsrv_tconU(case 0)
  8551. [2022-06-17 08:45:10.516086] info0 : *
  8552. [2022-06-17 08:45:10.517710] info0: struct smbXsrv_tcon
  8553. [2022-06-17 08:45:10.519330] table : *
  8554. [2022-06-17 08:45:10.520963] db_rec : NULL
  8555. [2022-06-17 08:45:10.522607] local_id : 0xe48c8acd (3834415821)
  8556. [2022-06-17 08:45:10.524352] global : *
  8557. [2022-06-17 08:45:10.526003] global: struct smbXsrv_tcon_global0
  8558. [2022-06-17 08:45:10.527655] db_rec : NULL
  8559. [2022-06-17 08:45:10.529306] tcon_global_id : 0xe48c8acd (3834415821)
  8560. [2022-06-17 08:45:10.530957] tcon_wire_id : 0xe48c8acd (3834415821)
  8561. [2022-06-17 08:45:10.532612] server_id: struct server_id
  8562. [2022-06-17 08:45:10.534332] pid : 0x0000000000002574 (9588)
  8563. [2022-06-17 08:45:10.536008] task_id : 0x00000000 (0)
  8564. [2022-06-17 08:45:10.537647] vnn : 0xffffffff (4294967295)
  8565. [2022-06-17 08:45:10.539302] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8566. [2022-06-17 08:45:10.540976] creation_time : Fri Jun 17 08:45:08 2022 UTC
  8567. [2022-06-17 08:45:10.542635] share_name : 'shr'
  8568. [2022-06-17 08:45:10.544360] encryption_flags : 0x00 (0)
  8569. [2022-06-17 08:45:10.546018] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8570. [2022-06-17 08:45:10.547673] 0: SMBXSRV_ENCRYPTION_DESIRED
  8571. [2022-06-17 08:45:10.549329] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8572. [2022-06-17 08:45:10.550970] 0: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8573. [2022-06-17 08:45:10.552605] session_global_id : 0x6f1a4b46 (1863994182)
  8574. [2022-06-17 08:45:10.554338] signing_flags : 0x00 (0)
  8575. [2022-06-17 08:45:10.556008] 0: SMBXSRV_SIGNING_REQUIRED
  8576. [2022-06-17 08:45:10.557656] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8577. [2022-06-17 08:45:10.559316] 0: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8578. [2022-06-17 08:45:10.560972] status : NT_STATUS_OK
  8579. [2022-06-17 08:45:10.562626] idle_time : Fri Jun 17 08:45:08 2022 UTC
  8580. [2022-06-17 08:45:10.564353] compat : *
  8581. [2022-06-17 08:45:10.566002] smbd_smb2_request_done_ex: mid [6] idx[1] status[NT_STATUS_OK] body[16] dyn[no:0] at ../../source3/smbd/smb2_tcon.c:186
  8582. [2022-06-17 08:45:10.567774] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/7/8192
  8583. [2022-06-17 08:45:10.569516] signed SMB2 message
  8584. [2022-06-17 08:45:10.571150] smbd_smb2_request idx[1] of 5 vectors
  8585. [2022-06-17 08:45:10.572914] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 7 (position 7) from bitmap
  8586. [2022-06-17 08:45:10.574638] smbd_smb2_request_dispatch: opcode[SMB2_OP_CREATE] mid = 7
  8587. [2022-06-17 08:45:10.576304] setting sec ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  8588. [2022-06-17 08:45:10.577946] Security token SIDs (7):
  8589. [2022-06-17 08:45:10.579557] SID[ 0]: S-1-5-21-3939785350-4027435424-1589595352-132066
  8590. [2022-06-17 08:45:10.581200] SID[ 1]: S-1-5-21-3939785350-4027435424-1589595352-513
  8591. [2022-06-17 08:45:10.582837] SID[ 2]: S-1-22-2-65534
  8592. [2022-06-17 08:45:10.584546] SID[ 3]: S-1-1-0
  8593. [2022-06-17 08:45:10.586176] SID[ 4]: S-1-5-2
  8594. [2022-06-17 08:45:10.587794] SID[ 5]: S-1-5-11
  8595. [2022-06-17 08:45:10.589406] SID[ 6]: S-1-22-1-65533
  8596. [2022-06-17 08:45:10.591010] Privileges (0x 0):
  8597. [2022-06-17 08:45:10.592646] Rights (0x 0):
  8598. [2022-06-17 08:45:10.594359] UNIX token of user 65533
  8599. [2022-06-17 08:45:10.595982] Primary group is 65534 and contains 1 supplementary groups
  8600. [2022-06-17 08:45:10.597634] Group[ 0]: 65534
  8601. [2022-06-17 08:45:10.599263] vfs_ChDir to /mnt/share
  8602. [2022-06-17 08:45:10.600767] vfs_ChDir: vfs_ChDir got /mnt/share
  8603. [2022-06-17 08:45:10.602260] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  8604. [2022-06-17 08:45:10.604110] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8605. [2022-06-17 08:45:10.605774] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  8606. [2022-06-17 08:45:10.607419] db_tdb_log_key: Locking key E48C8ACD
  8607. [2022-06-17 08:45:10.609065] db_tdb_fetch_locked_internal: Allocated locked data 0xb54a5e80
  8608. [2022-06-17 08:45:10.610711] smbXsrv_tcon_global_store: key 'E48C8ACD' stored
  8609. [2022-06-17 08:45:10.612350] &global_blob: struct smbXsrv_tcon_globalB
  8610. [2022-06-17 08:45:10.614081] version : SMBXSRV_VERSION_0 (0)
  8611. [2022-06-17 08:45:10.615712] seqnum : 0x00000003 (3)
  8612. [2022-06-17 08:45:10.617333] info : union smbXsrv_tcon_globalU(case 0)
  8613. [2022-06-17 08:45:10.618981] info0 : *
  8614. [2022-06-17 08:45:10.620624] info0: struct smbXsrv_tcon_global0
  8615. [2022-06-17 08:45:10.622271] db_rec : *
  8616. [2022-06-17 08:45:10.624037] tcon_global_id : 0xe48c8acd (3834415821)
  8617. [2022-06-17 08:45:10.625691] tcon_wire_id : 0xe48c8acd (3834415821)
  8618. [2022-06-17 08:45:10.627346] server_id: struct server_id
  8619. [2022-06-17 08:45:10.628988] pid : 0x0000000000002574 (9588)
  8620. [2022-06-17 08:45:10.630631] task_id : 0x00000000 (0)
  8621. [2022-06-17 08:45:10.632276] vnn : 0xffffffff (4294967295)
  8622. [2022-06-17 08:45:10.633992] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8623. [2022-06-17 08:45:10.635665] creation_time : Fri Jun 17 08:45:08 2022 UTC
  8624. [2022-06-17 08:45:10.637318] share_name : 'shr'
  8625. [2022-06-17 08:45:10.638960] encryption_flags : 0x08 (8)
  8626. [2022-06-17 08:45:10.640595] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8627. [2022-06-17 08:45:10.642243] 0: SMBXSRV_ENCRYPTION_DESIRED
  8628. [2022-06-17 08:45:10.643803] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8629. [2022-06-17 08:45:10.645546] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8630. [2022-06-17 08:45:10.647202] session_global_id : 0x6f1a4b46 (1863994182)
  8631. [2022-06-17 08:45:10.648837] signing_flags : 0x04 (4)
  8632. [2022-06-17 08:45:10.650461] 0: SMBXSRV_SIGNING_REQUIRED
  8633. [2022-06-17 08:45:10.652095] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8634. [2022-06-17 08:45:10.653797] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8635. [2022-06-17 08:45:10.655455] db_tdb_log_key: Unlocking key E48C8ACD
  8636. [2022-06-17 08:45:10.657088] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  8637. [2022-06-17 08:45:10.658755] smbXsrv_tcon_update: global_id (0xe48c8acd) stored
  8638. [2022-06-17 08:45:10.660393] &tcon_blob: struct smbXsrv_tconB
  8639. [2022-06-17 08:45:10.662022] version : SMBXSRV_VERSION_0 (0)
  8640. [2022-06-17 08:45:10.663708] reserved : 0x00000000 (0)
  8641. [2022-06-17 08:45:10.665357] info : union smbXsrv_tconU(case 0)
  8642. [2022-06-17 08:45:10.667002] info0 : *
  8643. [2022-06-17 08:45:10.668648] info0: struct smbXsrv_tcon
  8644. [2022-06-17 08:45:10.670290] table : *
  8645. [2022-06-17 08:45:10.671937] db_rec : NULL
  8646. [2022-06-17 08:45:10.673631] local_id : 0xe48c8acd (3834415821)
  8647. [2022-06-17 08:45:10.675279] global : *
  8648. [2022-06-17 08:45:10.676911] global: struct smbXsrv_tcon_global0
  8649. [2022-06-17 08:45:10.678544] db_rec : NULL
  8650. [2022-06-17 08:45:10.680172] tcon_global_id : 0xe48c8acd (3834415821)
  8651. [2022-06-17 08:45:10.681822] tcon_wire_id : 0xe48c8acd (3834415821)
  8652. [2022-06-17 08:45:10.683516] server_id: struct server_id
  8653. [2022-06-17 08:45:10.685171] pid : 0x0000000000002574 (9588)
  8654. [2022-06-17 08:45:10.686821] task_id : 0x00000000 (0)
  8655. [2022-06-17 08:45:10.688468] vnn : 0xffffffff (4294967295)
  8656. [2022-06-17 08:45:10.690120] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8657. [2022-06-17 08:45:10.691783] creation_time : Fri Jun 17 08:45:08 2022 UTC
  8658. [2022-06-17 08:45:10.693500] share_name : 'shr'
  8659. [2022-06-17 08:45:10.695287] encryption_flags : 0x08 (8)
  8660. [2022-06-17 08:45:10.696937] 0: SMBXSRV_ENCRYPTION_REQUIRED
  8661. [2022-06-17 08:45:10.698600] 0: SMBXSRV_ENCRYPTION_DESIRED
  8662. [2022-06-17 08:45:10.700251] 0: SMBXSRV_PROCESSED_ENCRYPTED_PACKET
  8663. [2022-06-17 08:45:10.701896] 1: SMBXSRV_PROCESSED_UNENCRYPTED_PACKET
  8664. [2022-06-17 08:45:10.703588] session_global_id : 0x6f1a4b46 (1863994182)
  8665. [2022-06-17 08:45:10.705253] signing_flags : 0x04 (4)
  8666. [2022-06-17 08:45:10.706892] 0: SMBXSRV_SIGNING_REQUIRED
  8667. [2022-06-17 08:45:10.708541] 0: SMBXSRV_PROCESSED_SIGNED_PACKET
  8668. [2022-06-17 08:45:10.710186] 1: SMBXSRV_PROCESSED_UNSIGNED_PACKET
  8669. [2022-06-17 08:45:10.711836] status : NT_STATUS_OK
  8670. [2022-06-17 08:45:10.713516] idle_time : Fri Jun 17 08:45:09 2022 UTC
  8671. [2022-06-17 08:45:10.715172] compat : *
  8672. [2022-06-17 08:45:10.716815] smbd_smb2_create_send: name []
  8673. [2022-06-17 08:45:10.718460] smbd_smb2_create_send: open execution phase
  8674. [2022-06-17 08:45:10.720091] unix_convert: Called on file []
  8675. [2022-06-17 08:45:10.721719] unix_convert: conversion finished [] -> [.]
  8676. [2022-06-17 08:45:10.723402] unix_convert: Conversion finished [] -> [.]
  8677. [2022-06-17 08:45:10.725044] is_in_path: .
  8678. [2022-06-17 08:45:10.726645] is_in_path: match not found
  8679. [2022-06-17 08:45:10.728256] check_reduced_name: check_reduced_name [.] [/mnt/share]
  8680. [2022-06-17 08:45:10.729896] check_reduced_name realpath [.] -> [/mnt/share]
  8681. [2022-06-17 08:45:10.731546] check_reduced_name: . reduced to /mnt/share
  8682. [2022-06-17 08:45:10.733231] openat_pathref_fsp: smb_fname [.]
  8683. [2022-06-17 08:45:10.734880] fsp_new: allocated files structure (1 used)
  8684. [2022-06-17 08:45:10.736508] file_name_hash: /mnt/share/. hash 0x7a8d2120
  8685. [2022-06-17 08:45:10.738131] check_reduced_name: check_reduced_name [.] [/mnt/share]
  8686. [2022-06-17 08:45:10.739776] check_reduced_name realpath [.] -> [/mnt/share]
  8687. [2022-06-17 08:45:10.741418] check_reduced_name: . reduced to /mnt/share
  8688. [2022-06-17 08:45:10.743100] fd_openat: name ., flags = 040000 mode = 00, fd = 39
  8689. [2022-06-17 08:45:10.744751] openat_pathref_fsp: fsp [.]: OK
  8690. [2022-06-17 08:45:10.746376] create_file_default: create_file: access_mask = 0x80 file_attributes = 0x10, share_access = 0x7, create_disposition = 0x1 create_options = 0x1 oplock_request = 0x0 private_flags = 0x0 ea_list = 0, sd = 0, fname = .
  8691. [2022-06-17 08:45:10.748093] create_file_unixpath: create_file_unixpath: access_mask = 0x80 file_attributes = 0x10, share_access = 0x7, create_disposition = 0x1 create_options = 0x1 oplock_request = 0x0 private_flags = 0x0 ea_list = 0, sd = 0, fname = .
  8692. [2022-06-17 08:45:10.749843] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_open_global.tdb
  8693. [2022-06-17 08:45:10.751509] lock order: 1:/var/lock/smbXsrv_open_global.tdb 2:<none> 3:<none> 4:<none>
  8694. [2022-06-17 08:45:10.753224] db_tdb_log_key: Locking key 3C9AF004
  8695. [2022-06-17 08:45:10.754893] db_tdb_fetch_locked_internal: Allocated locked data 0xb5896d90
  8696. [2022-06-17 08:45:10.756534] smbXsrv_open_global_verify_record: empty value
  8697. [2022-06-17 08:45:10.758178] smbXsrv_open_global_store: key '3C9AF004' stored
  8698. [2022-06-17 08:45:10.759810] &global_blob: struct smbXsrv_open_globalB
  8699. [2022-06-17 08:45:10.761441] version : SMBXSRV_VERSION_0 (0)
  8700. [2022-06-17 08:45:10.763114] seqnum : 0x00000001 (1)
  8701. [2022-06-17 08:45:10.764758] info : union smbXsrv_open_globalU(case 0)
  8702. [2022-06-17 08:45:10.766416] info0 : *
  8703. [2022-06-17 08:45:10.768060] info0: struct smbXsrv_open_global0
  8704. [2022-06-17 08:45:10.769699] db_rec : *
  8705. [2022-06-17 08:45:10.771329] server_id: struct server_id
  8706. [2022-06-17 08:45:10.772992] pid : 0x0000000000002574 (9588)
  8707. [2022-06-17 08:45:10.774660] task_id : 0x00000000 (0)
  8708. [2022-06-17 08:45:10.776308] vnn : 0xffffffff (4294967295)
  8709. [2022-06-17 08:45:10.777961] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8710. [2022-06-17 08:45:10.779614] open_global_id : 0x3c9af004 (1016786948)
  8711. [2022-06-17 08:45:10.781249] open_persistent_id : 0x000000003c9af004 (1016786948)
  8712. [2022-06-17 08:45:10.782944] open_volatile_id : 0x000000002b604d9e (727731614)
  8713. [2022-06-17 08:45:10.784613] open_owner : S-1-5-21-3939785350-4027435424-1589595352-132066
  8714. [2022-06-17 08:45:10.786267] open_time : Fri Jun 17 08:45:09 2022 UTC
  8715. [2022-06-17 08:45:10.787929] create_guid : 00000000-0000-0000-0000-000000000000
  8716. [2022-06-17 08:45:10.789580] client_guid : 81388492-5b34-419d-9462-792b3b27d8b4
  8717. [2022-06-17 08:45:10.791235] app_instance_id : 00000000-0000-0000-0000-000000000000
  8718. [2022-06-17 08:45:10.792930] disconnect_time : NTTIME(0)
  8719. [2022-06-17 08:45:10.794592] durable_timeout_msec : 0x00000000 (0)
  8720. [2022-06-17 08:45:10.796229] durable : 0x00 (0)
  8721. [2022-06-17 08:45:10.797867] backend_cookie : DATA_BLOB length=0
  8722. [2022-06-17 08:45:10.799517] channel_sequence : 0x0000 (0)
  8723. [2022-06-17 08:45:10.801140] channel_generation : 0x0000000000000000 (0)
  8724. [2022-06-17 08:45:10.802782] lock_sequence_array: ARRAY(64)
  8725. [2022-06-17 08:45:10.804488] [0000] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8726. [2022-06-17 08:45:10.806227] [0010] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8727. [2022-06-17 08:45:10.807904] [0020] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8728. [2022-06-17 08:45:10.809564] [0030] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8729. [2022-06-17 08:45:10.811228] db_tdb_log_key: Unlocking key 3C9AF004
  8730. [2022-06-17 08:45:10.812850] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_open_global.tdb
  8731. [2022-06-17 08:45:10.814567] smbXsrv_open_create: global_id (0x3c9af004) stored
  8732. [2022-06-17 08:45:10.816219] &open_blob: struct smbXsrv_openB
  8733. [2022-06-17 08:45:10.817855] version : SMBXSRV_VERSION_0 (0)
  8734. [2022-06-17 08:45:10.819479] reserved : 0x00000000 (0)
  8735. [2022-06-17 08:45:10.821115] info : union smbXsrv_openU(case 0)
  8736. [2022-06-17 08:45:10.822746] info0 : *
  8737. [2022-06-17 08:45:10.824442] info0: struct smbXsrv_open
  8738. [2022-06-17 08:45:10.826079] table : *
  8739. [2022-06-17 08:45:10.827722] db_rec : NULL
  8740. [2022-06-17 08:45:10.829368] local_id : 0x2b604d9e (727731614)
  8741. [2022-06-17 08:45:10.831019] global : *
  8742. [2022-06-17 08:45:10.832655] global: struct smbXsrv_open_global0
  8743. [2022-06-17 08:45:10.834354] db_rec : NULL
  8744. [2022-06-17 08:45:10.836001] server_id: struct server_id
  8745. [2022-06-17 08:45:10.837632] pid : 0x0000000000002574 (9588)
  8746. [2022-06-17 08:45:10.839303] task_id : 0x00000000 (0)
  8747. [2022-06-17 08:45:10.840955] vnn : 0xffffffff (4294967295)
  8748. [2022-06-17 08:45:10.842610] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8749. [2022-06-17 08:45:10.844346] open_global_id : 0x3c9af004 (1016786948)
  8750. [2022-06-17 08:45:10.845999] open_persistent_id : 0x000000003c9af004 (1016786948)
  8751. [2022-06-17 08:45:10.847654] open_volatile_id : 0x000000002b604d9e (727731614)
  8752. [2022-06-17 08:45:10.849279] open_owner : S-1-5-21-3939785350-4027435424-1589595352-132066
  8753. [2022-06-17 08:45:10.850949] open_time : Fri Jun 17 08:45:09 2022 UTC
  8754. [2022-06-17 08:45:10.852618] create_guid : 00000000-0000-0000-0000-000000000000
  8755. [2022-06-17 08:45:10.854359] client_guid : 81388492-5b34-419d-9462-792b3b27d8b4
  8756. [2022-06-17 08:45:10.856025] app_instance_id : 00000000-0000-0000-0000-000000000000
  8757. [2022-06-17 08:45:10.857683] disconnect_time : NTTIME(0)
  8758. [2022-06-17 08:45:10.859324] durable_timeout_msec : 0x00000000 (0)
  8759. [2022-06-17 08:45:10.860975] durable : 0x00 (0)
  8760. [2022-06-17 08:45:10.862612] backend_cookie : DATA_BLOB length=0
  8761. [2022-06-17 08:45:10.864337] channel_sequence : 0x0000 (0)
  8762. [2022-06-17 08:45:10.865993] channel_generation : 0x0000000000000000 (0)
  8763. [2022-06-17 08:45:10.867668] lock_sequence_array: ARRAY(64)
  8764. [2022-06-17 08:45:10.869305] [0000] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8765. [2022-06-17 08:45:10.870948] [0010] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8766. [2022-06-17 08:45:10.872588] [0020] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8767. [2022-06-17 08:45:10.874328] [0030] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  8768. [2022-06-17 08:45:10.875995] status : NT_STATUS_OK
  8769. [2022-06-17 08:45:10.877526] idle_time : Fri Jun 17 08:45:09 2022 UTC
  8770. [2022-06-17 08:45:10.879299] compat : NULL
  8771. [2022-06-17 08:45:10.880941] flags : 0x00 (0)
  8772. [2022-06-17 08:45:10.882570] 0: SMBXSRV_OPEN_NEED_REPLAY_CACHE
  8773. [2022-06-17 08:45:10.884278] 0: SMBXSRV_OPEN_HAVE_REPLAY_CACHE
  8774. [2022-06-17 08:45:10.885930] create_action : 0x00000000 (0)
  8775. [2022-06-17 08:45:10.887574] request_count : 0x0000000000000000 (0)
  8776. [2022-06-17 08:45:10.889228] pre_request_count : 0x0000000000000000 (0)
  8777. [2022-06-17 08:45:10.890868] fsp_bind_smb: fsp [.] mid [7]
  8778. [2022-06-17 08:45:10.892501] open_directory: opening directory ., access_mask = 0x80, share_access = 0x7 create_options = 0x1, create_disposition = 0x1, file_attributes = 0x10
  8779. [2022-06-17 08:45:10.894273] posix_get_nt_acl: called for file .
  8780. [2022-06-17 08:45:10.895783] push_sec_ctx(65533, 65534) : sec_ctx_stack_ndx = 1
  8781. [2022-06-17 08:45:10.897557] push_conn_ctx(1863994182) : conn_ctx_stack_ndx = 0
  8782. [2022-06-17 08:45:10.899192] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8783. [2022-06-17 08:45:10.900844] Security token: (NULL)
  8784. [2022-06-17 08:45:10.902471] UNIX token of user 0
  8785. [2022-06-17 08:45:10.904148] Primary group is 0 and contains 0 supplementary groups
  8786. [2022-06-17 08:45:10.905778] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  8787. [2022-06-17 08:45:10.907417] push_conn_ctx(1863994182) : conn_ctx_stack_ndx = 1
  8788. [2022-06-17 08:45:10.908924] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  8789. [2022-06-17 08:45:10.910423] Security token: (NULL)
  8790. [2022-06-17 08:45:10.912058] UNIX token of user 0
  8791. [2022-06-17 08:45:10.913852] Primary group is 0 and contains 0 supplementary groups
  8792. [2022-06-17 08:45:10.915512] getsampwnam (smbpasswd): search by name: root
  8793. [2022-06-17 08:45:10.917142] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  8794. [2022-06-17 08:45:10.918769] getsmbfilepwent: skipping comment or blank line
  8795. [2022-06-17 08:45:10.920421] getsmbfilepwent: LM password for user nobody invalidated
  8796. [2022-06-17 08:45:10.922062] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  8797. [2022-06-17 08:45:10.923796] getsmbfilepwent: LM password for user useruser invalidated
  8798. [2022-06-17 08:45:10.925480] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  8799. [2022-06-17 08:45:10.927158] getsmbfilepwent: end of file reached.
  8800. [2022-06-17 08:45:10.928809] endsmbfilepwent_internal: closed password file.
  8801. [2022-06-17 08:45:10.930460] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  8802. [2022-06-17 08:45:10.932080] pdb_default_uid_to_sid: Did not find user root (0)
  8803. [2022-06-17 08:45:10.933779] pop_sec_ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  8804. [2022-06-17 08:45:10.935433] xid_to_sid: UID 0 -> S-1-22-1-0 fallback
  8805. [2022-06-17 08:45:10.937087] push_sec_ctx(65533, 65534) : sec_ctx_stack_ndx = 1
  8806. [2022-06-17 08:45:10.938733] push_conn_ctx(1863994182) : conn_ctx_stack_ndx = 0
  8807. [2022-06-17 08:45:10.940381] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  8808. [2022-06-17 08:45:10.942010] Security token: (NULL)
  8809. [2022-06-17 08:45:10.943555] UNIX token of user 0
  8810. [2022-06-17 08:45:10.945255] Primary group is 0 and contains 0 supplementary groups
  8811. [2022-06-17 08:45:10.946896] pop_sec_ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  8812. [2022-06-17 08:45:10.948532] xid_to_sid: GID 0 -> S-1-22-2-0 fallback
  8813. [2022-06-17 08:45:10.950172] canonicalise_acl: Access ace entries before arrange :
  8814. [2022-06-17 08:45:10.951807] canon_ace index 0. Type = allow SID = S-1-1-0 other SMB_ACL_OTHER ace_flags = 0x0 perms r-x
  8815. [2022-06-17 08:45:10.953521] canon_ace index 1. Type = allow SID = S-1-22-2-0 gid 0 SMB_ACL_GROUP_OBJ ace_flags = 0x0 perms r-x
  8816. [2022-06-17 08:45:10.955198] canon_ace index 2. Type = allow SID = S-1-22-1-0 uid 0 SMB_ACL_USER_OBJ ace_flags = 0x0 perms rwx
  8817. [2022-06-17 08:45:10.956875] print_canon_ace_list: canonicalise_acl: ace entries after arrange
  8818. [2022-06-17 08:45:10.958523] canon_ace index 0. Type = allow SID = S-1-22-1-0 uid 0 SMB_ACL_USER_OBJ ace_flags = 0x0 perms rwx
  8819. [2022-06-17 08:45:10.960195] canon_ace index 1. Type = allow SID = S-1-22-2-0 gid 0 SMB_ACL_GROUP_OBJ ace_flags = 0x0 perms r-x
  8820. [2022-06-17 08:45:10.961875] canon_ace index 2. Type = allow SID = S-1-1-0 other SMB_ACL_OTHER ace_flags = 0x0 perms r-x
  8821. [2022-06-17 08:45:10.963595] map_canon_ace_perms: Mapped (UNIX) 1c0 to (NT) 1f01ff
  8822. [2022-06-17 08:45:10.965251] map_canon_ace_perms: Mapped (UNIX) 140 to (NT) 1200a9
  8823. [2022-06-17 08:45:10.966905] map_canon_ace_perms: Mapped (UNIX) 140 to (NT) 1200a9
  8824. [2022-06-17 08:45:10.968544] smbd_check_access_rights_sd: File [.] requesting [0x80] returning [0x0] (NT_STATUS_OK)
  8825. [2022-06-17 08:45:10.970196] delete_lock_ref_count for file .
  8826. [2022-06-17 08:45:10.971826] dbwrap_watched_subrec_wakeup_fn: No watchers
  8827. [2022-06-17 08:45:10.973519] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  8828. [2022-06-17 08:45:10.975188] dbwrap_lock_order_lock: check lock order 1 for /var/lock/locking.tdb
  8829. [2022-06-17 08:45:10.976844] lock order: 1:/var/lock/locking.tdb 2:<none> 3:<none> 4:<none>
  8830. [2022-06-17 08:45:10.978479] find_delete_on_close_token: name_hash = 0x7a8d2120
  8831. [2022-06-17 08:45:10.980115] set_share_mode: num_share_modes=0
  8832. [2022-06-17 08:45:10.981756] share_mode_entry_put: share_mode_entry:
  8833. [2022-06-17 08:45:10.983437] discard_const_p(void, e): struct share_mode_entry
  8834. [2022-06-17 08:45:10.985096] pid: struct server_id
  8835. [2022-06-17 08:45:10.986750] pid : 0x0000000000002574 (9588)
  8836. [2022-06-17 08:45:10.988394] task_id : 0x00000000 (0)
  8837. [2022-06-17 08:45:10.990037] vnn : 0xffffffff (4294967295)
  8838. [2022-06-17 08:45:10.991677] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8839. [2022-06-17 08:45:10.993370] op_mid : 0x0000000000000007 (7)
  8840. [2022-06-17 08:45:10.995029] op_type : 0x0000 (0)
  8841. [2022-06-17 08:45:10.996678] client_guid : 00000000-0000-0000-0000-000000000000
  8842. [2022-06-17 08:45:10.998339] lease_key: struct smb2_lease_key
  8843. [2022-06-17 08:45:10.999993] data: ARRAY(2)
  8844. [2022-06-17 08:45:11.001626] data : 0x0000000000000000 (0)
  8845. [2022-06-17 08:45:11.003340] data : 0x0000000000000000 (0)
  8846. [2022-06-17 08:45:11.005002] access_mask : 0x00000080 (128)
  8847. [2022-06-17 08:45:11.006650] share_access : 0x00000007 (7)
  8848. [2022-06-17 08:45:11.008286] private_options : 0x00000000 (0)
  8849. [2022-06-17 08:45:11.009952] time : Fri Jun 17 08:45:08 2022 UTC.757865
  8850. [2022-06-17 08:45:11.011605] share_file_id : 0x0000000000000002 (2)
  8851. [2022-06-17 08:45:11.013300] uid : 0x0000fffd (65533)
  8852. [2022-06-17 08:45:11.014942] flags : 0x0000 (0)
  8853. [2022-06-17 08:45:11.016466] name_hash : 0x7a8d2120 (2056069408)
  8854. [2022-06-17 08:45:11.017959] stale : 0x00 (0)
  8855. [2022-06-17 08:45:11.019675] set_share_mode: idx=0, found=0
  8856. [2022-06-17 08:45:11.021299] set_share_mode: dbufs[0]=(0xbed70290, 132)
  8857. [2022-06-17 08:45:11.022972] dbwrap_watched_subrec_wakeup_fn: No watchers
  8858. [2022-06-17 08:45:11.024633] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  8859. [2022-06-17 08:45:11.026293] share_mode_data_store:
  8860. [2022-06-17 08:45:11.027783] d: struct share_mode_data
  8861. [2022-06-17 08:45:11.029488] unique_content_epoch : 0x18806ab16114c443 (1765528363999740995)
  8862. [2022-06-17 08:45:11.031143] flags : 0x01c0 (448)
  8863. [2022-06-17 08:45:11.032665] 1: SHARE_MODE_SHARE_DELETE
  8864. [2022-06-17 08:45:11.034225] 1: SHARE_MODE_SHARE_WRITE
  8865. [2022-06-17 08:45:11.035738] 1: SHARE_MODE_SHARE_READ
  8866. [2022-06-17 08:45:11.037228] 0: SHARE_MODE_ACCESS_DELETE
  8867. [2022-06-17 08:45:11.038800] 0: SHARE_MODE_ACCESS_WRITE
  8868. [2022-06-17 08:45:11.040314] 0: SHARE_MODE_ACCESS_READ
  8869. [2022-06-17 08:45:11.041810] 0: SHARE_MODE_LEASE_HANDLE
  8870. [2022-06-17 08:45:11.043597] 0: SHARE_MODE_LEASE_WRITE
  8871. [2022-06-17 08:45:11.045278] 0: SHARE_MODE_LEASE_READ
  8872. [2022-06-17 08:45:11.046813] servicepath : *
  8873. [2022-06-17 08:45:11.048476] servicepath : '/mnt/share'
  8874. [2022-06-17 08:45:11.050131] base_name : *
  8875. [2022-06-17 08:45:11.051891] base_name : '.'
  8876. [2022-06-17 08:45:11.053578] stream_name : NULL
  8877. [2022-06-17 08:45:11.055106] num_delete_tokens : 0x00000000 (0)
  8878. [2022-06-17 08:45:11.056844] delete_tokens: ARRAY(0)
  8879. [2022-06-17 08:45:11.058370] old_write_time : NTTIME(0)
  8880. [2022-06-17 08:45:11.060127] changed_write_time : NTTIME(0)
  8881. [2022-06-17 08:45:11.061644] fresh : 0x01 (1)
  8882. [2022-06-17 08:45:11.063187] modified : 0x01 (1)
  8883. [2022-06-17 08:45:11.064691] id: struct file_id
  8884. [2022-06-17 08:45:11.066410] devid : 0x0000000000000012 (18)
  8885. [2022-06-17 08:45:11.068078] inode : 0x0000000000000045 (69)
  8886. [2022-06-17 08:45:11.069731] extid : 0x0000000000000000 (0)
  8887. [2022-06-17 08:45:11.071380] dbwrap_watched_subrec_wakeup_fn: No watchers
  8888. [2022-06-17 08:45:11.073067] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  8889. [2022-06-17 08:45:11.074736] dbwrap_watched_subrec_wakeup_fn: No watchers
  8890. [2022-06-17 08:45:11.076524] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  8891. [2022-06-17 08:45:11.078193] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/locking.tdb
  8892. [2022-06-17 08:45:11.079845] share_mode_memcache_store: stored entry for file . epoch 18806ab16114c445 key 18:69:0
  8893. [2022-06-17 08:45:11.081498] create_file_unixpath: info=1
  8894. [2022-06-17 08:45:11.083185] create_file: info=1
  8895. [2022-06-17 08:45:11.084821] smbd_smb2_create_send: response construction phase
  8896. [2022-06-17 08:45:11.086462] fdos_mode: .
  8897. [2022-06-17 08:45:11.088075] fget_ea_dos_attribute: Cannot get attribute from EA on file .: Error = No data available
  8898. [2022-06-17 08:45:11.089726] dos_mode_debug_print: fdos_mode returning (0x10): "d"
  8899. [2022-06-17 08:45:11.091368] smbd_smb2_create_finish: . - fnum 727731614
  8900. [2022-06-17 08:45:11.093049] smbd_smb2_request_done_ex: mid [7] idx[1] status[NT_STATUS_OK] body[88] dyn[yes:0] at ../../source3/smbd/smb2_create.c:405
  8901. [2022-06-17 08:45:11.094748] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/8/8192
  8902. [2022-06-17 08:45:11.096472] smbd_smb2_request idx[1] of 5 vectors
  8903. [2022-06-17 08:45:11.098111] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 8 (position 8) from bitmap
  8904. [2022-06-17 08:45:11.099770] smbd_smb2_request_dispatch: opcode[SMB2_OP_GETINFO] mid = 8
  8905. [2022-06-17 08:45:11.101402] change_to_user_impersonate: Skipping user change - already user
  8906. [2022-06-17 08:45:11.103104] vfs_ChDir to /mnt/share
  8907. [2022-06-17 08:45:11.104773] vfs_ChDir: vfs_ChDir got /mnt/share
  8908. [2022-06-17 08:45:11.106425] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  8909. [2022-06-17 08:45:11.108092] smbd_smb2_request_verify_creditcharge: mid 8, CreditCharge: 1, NeededCharge: 1
  8910. [2022-06-17 08:45:11.109752] smbd_smb2_getinfo_send: . - fnum 727731614
  8911. [2022-06-17 08:45:11.111387] smbd_do_qfsinfo: level = 1005
  8912. [2022-06-17 08:45:11.113059] smbd_smb2_request_done_ex: mid [8] idx[1] status[NT_STATUS_OK] body[8] dyn[yes:20] at ../../source3/smbd/smb2_getinfo.c:206
  8913. [2022-06-17 08:45:11.114752] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/9/8192
  8914. [2022-06-17 08:45:11.116468] smbd_smb2_request idx[1] of 5 vectors
  8915. [2022-06-17 08:45:11.118125] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 9 (position 9) from bitmap
  8916. [2022-06-17 08:45:11.119799] smbd_smb2_request_dispatch: opcode[SMB2_OP_CLOSE] mid = 9
  8917. [2022-06-17 08:45:11.121444] change_to_user_impersonate: Skipping user change - already user
  8918. [2022-06-17 08:45:11.123137] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  8919. [2022-06-17 08:45:11.124821] smbd_smb2_close: . - fnum 727731614
  8920. [2022-06-17 08:45:11.126463] dbwrap_watched_subrec_wakeup_fn: No watchers
  8921. [2022-06-17 08:45:11.128094] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  8922. [2022-06-17 08:45:11.129747] dbwrap_lock_order_lock: check lock order 1 for /var/lock/locking.tdb
  8923. [2022-06-17 08:45:11.131402] lock order: 1:/var/lock/locking.tdb 2:<none> 3:<none> 4:<none>
  8924. [2022-06-17 08:45:11.133117] share_mode_memcache_fetch: fetched entry for file . epoch 18806ab16114c445 key 18:69:0
  8925. [2022-06-17 08:45:11.134786] find_delete_on_close_token: name_hash = 0x7a8d2120
  8926. [2022-06-17 08:45:11.136420] share_mode_entry_do: num_share_modes=1
  8927. [2022-06-17 08:45:11.138056] share_mode_entry_find: left=0, right=0, middle=0, middle_ptr=0xb5165e62
  8928. [2022-06-17 08:45:11.139700] share_mode_entry_do: entry[0]:
  8929. [2022-06-17 08:45:11.141335] &e: struct share_mode_entry
  8930. [2022-06-17 08:45:11.143013] pid: struct server_id
  8931. [2022-06-17 08:45:11.144665] pid : 0x0000000000002574 (9588)
  8932. [2022-06-17 08:45:11.146321] task_id : 0x00000000 (0)
  8933. [2022-06-17 08:45:11.147968] vnn : 0xffffffff (4294967295)
  8934. [2022-06-17 08:45:11.149626] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8935. [2022-06-17 08:45:11.151268] op_mid : 0x0000000000000007 (7)
  8936. [2022-06-17 08:45:11.152939] op_type : 0x0000 (0)
  8937. [2022-06-17 08:45:11.154597] client_guid : 00000000-0000-0000-0000-000000000000
  8938. [2022-06-17 08:45:11.156241] lease_key: struct smb2_lease_key
  8939. [2022-06-17 08:45:11.157890] data: ARRAY(2)
  8940. [2022-06-17 08:45:11.159500] data : 0x0000000000000000 (0)
  8941. [2022-06-17 08:45:11.161140] data : 0x0000000000000000 (0)
  8942. [2022-06-17 08:45:11.162773] access_mask : 0x00000080 (128)
  8943. [2022-06-17 08:45:11.164475] share_access : 0x00000007 (7)
  8944. [2022-06-17 08:45:11.166136] private_options : 0x00000000 (0)
  8945. [2022-06-17 08:45:11.167781] time : Fri Jun 17 08:45:08 2022 UTC.757865
  8946. [2022-06-17 08:45:11.169417] share_file_id : 0x0000000000000002 (2)
  8947. [2022-06-17 08:45:11.171050] uid : 0x0000fffd (65533)
  8948. [2022-06-17 08:45:11.172677] flags : 0x0000 (0)
  8949. [2022-06-17 08:45:11.174369] name_hash : 0x7a8d2120 (2056069408)
  8950. [2022-06-17 08:45:11.176020] stale : 0x00 (0)
  8951. [2022-06-17 08:45:11.177655] share_mode_entry_do: entry[0]: modified=0, e.stale=1
  8952. [2022-06-17 08:45:11.179299] share_mode_entry_do: share_mode_entry:
  8953. [2022-06-17 08:45:11.180928] &e: struct share_mode_entry
  8954. [2022-06-17 08:45:11.182563] pid: struct server_id
  8955. [2022-06-17 08:45:11.184290] pid : 0x0000000000002574 (9588)
  8956. [2022-06-17 08:45:11.185946] task_id : 0x00000000 (0)
  8957. [2022-06-17 08:45:11.187595] vnn : 0xffffffff (4294967295)
  8958. [2022-06-17 08:45:11.189243] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  8959. [2022-06-17 08:45:11.190904] op_mid : 0x0000000000000007 (7)
  8960. [2022-06-17 08:45:11.192547] op_type : 0x0000 (0)
  8961. [2022-06-17 08:45:11.194268] client_guid : 00000000-0000-0000-0000-000000000000
  8962. [2022-06-17 08:45:11.195920] lease_key: struct smb2_lease_key
  8963. [2022-06-17 08:45:11.197553] data: ARRAY(2)
  8964. [2022-06-17 08:45:11.199164] data : 0x0000000000000000 (0)
  8965. [2022-06-17 08:45:11.200794] data : 0x0000000000000000 (0)
  8966. [2022-06-17 08:45:11.202435] access_mask : 0x00000080 (128)
  8967. [2022-06-17 08:45:11.204172] share_access : 0x00000007 (7)
  8968. [2022-06-17 08:45:11.205818] private_options : 0x00000000 (0)
  8969. [2022-06-17 08:45:11.207336] time : Fri Jun 17 08:45:08 2022 UTC.757865
  8970. [2022-06-17 08:45:11.208835] share_file_id : 0x0000000000000002 (2)
  8971. [2022-06-17 08:45:11.210557] uid : 0x0000fffd (65533)
  8972. [2022-06-17 08:45:11.212186] flags : 0x0000 (0)
  8973. [2022-06-17 08:45:11.213870] name_hash : 0x7a8d2120 (2056069408)
  8974. [2022-06-17 08:45:11.215522] stale : 0x01 (1)
  8975. [2022-06-17 08:45:11.217163] dbwrap_watched_subrec_wakeup_fn: No watchers
  8976. [2022-06-17 08:45:11.218824] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  8977. [2022-06-17 08:45:11.220478] share_mode_data_store:
  8978. [2022-06-17 08:45:11.222087] d: struct share_mode_data
  8979. [2022-06-17 08:45:11.223768] unique_content_epoch : 0x18806ab16114c445 (1765528363999740997)
  8980. [2022-06-17 08:45:11.225429] flags : 0x01c0 (448)
  8981. [2022-06-17 08:45:11.227247] 1: SHARE_MODE_SHARE_DELETE
  8982. [2022-06-17 08:45:11.228936] 1: SHARE_MODE_SHARE_WRITE
  8983. [2022-06-17 08:45:11.230593] 1: SHARE_MODE_SHARE_READ
  8984. [2022-06-17 08:45:11.232219] 0: SHARE_MODE_ACCESS_DELETE
  8985. [2022-06-17 08:45:11.233888] 0: SHARE_MODE_ACCESS_WRITE
  8986. [2022-06-17 08:45:11.235522] 0: SHARE_MODE_ACCESS_READ
  8987. [2022-06-17 08:45:11.237157] 0: SHARE_MODE_LEASE_HANDLE
  8988. [2022-06-17 08:45:11.238803] 0: SHARE_MODE_LEASE_WRITE
  8989. [2022-06-17 08:45:11.240446] 0: SHARE_MODE_LEASE_READ
  8990. [2022-06-17 08:45:11.242078] servicepath : *
  8991. [2022-06-17 08:45:11.243766] servicepath : '/mnt/share'
  8992. [2022-06-17 08:45:11.245431] base_name : *
  8993. [2022-06-17 08:45:11.247079] base_name : '.'
  8994. [2022-06-17 08:45:11.248702] stream_name : NULL
  8995. [2022-06-17 08:45:11.250342] num_delete_tokens : 0x00000000 (0)
  8996. [2022-06-17 08:45:11.251984] delete_tokens: ARRAY(0)
  8997. [2022-06-17 08:45:11.253673] old_write_time : NTTIME(0)
  8998. [2022-06-17 08:45:11.255327] changed_write_time : NTTIME(0)
  8999. [2022-06-17 08:45:11.256962] fresh : 0x00 (0)
  9000. [2022-06-17 08:45:11.258604] modified : 0x01 (1)
  9001. [2022-06-17 08:45:11.260120] id: struct file_id
  9002. [2022-06-17 08:45:11.261599] devid : 0x0000000000000012 (18)
  9003. [2022-06-17 08:45:11.263163] inode : 0x0000000000000045 (69)
  9004. [2022-06-17 08:45:11.264679] extid : 0x0000000000000000 (0)
  9005. [2022-06-17 08:45:11.266181] dbwrap_watched_subrec_wakeup_fn: No watchers
  9006. [2022-06-17 08:45:11.267664] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9007. [2022-06-17 08:45:11.269165] dbwrap_watched_subrec_wakeup_fn: No watchers
  9008. [2022-06-17 08:45:11.270648] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9009. [2022-06-17 08:45:11.272147] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/locking.tdb
  9010. [2022-06-17 08:45:11.274162] delete_lock_ref_count for file .
  9011. [2022-06-17 08:45:11.275814] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_open_global.tdb
  9012. [2022-06-17 08:45:11.277474] lock order: 1:/var/lock/smbXsrv_open_global.tdb 2:<none> 3:<none> 4:<none>
  9013. [2022-06-17 08:45:11.279123] db_tdb_log_key: Locking key 3C9AF004
  9014. [2022-06-17 08:45:11.280749] db_tdb_fetch_locked_internal: Allocated locked data 0xb691fca0
  9015. [2022-06-17 08:45:11.282384] db_tdb_log_key: Unlocking key 3C9AF004
  9016. [2022-06-17 08:45:11.284176] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_open_global.tdb
  9017. [2022-06-17 08:45:11.285877] freed files structure 727731614 (0 used)
  9018. [2022-06-17 08:45:11.288230] smbd_smb2_request_done_ex: mid [9] idx[1] status[NT_STATUS_OK] body[60] dyn[no:0] at ../../source3/smbd/smb2_close.c:146
  9019. [2022-06-17 08:45:11.289916] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/10/8192
  9020. [2022-06-17 08:45:11.291634] smbd_smb2_request idx[1] of 5 vectors
  9021. [2022-06-17 08:45:11.293321] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 10 (position 10) from bitmap
  9022. [2022-06-17 08:45:11.295022] smbd_smb2_request_dispatch: opcode[SMB2_OP_CREATE] mid = 10
  9023. [2022-06-17 08:45:11.296667] change_to_user_impersonate: Skipping user change - already user
  9024. [2022-06-17 08:45:11.298312] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  9025. [2022-06-17 08:45:11.299984] smbd_smb2_create_send: name [qwe]
  9026. [2022-06-17 08:45:11.301615] smbd_smb2_create_send: open execution phase
  9027. [2022-06-17 08:45:11.303298] unix_convert: Called on file [qwe]
  9028. [2022-06-17 08:45:11.304935] stat_cache_lookup: lookup failed for name [0000000000000000@QWE]
  9029. [2022-06-17 08:45:11.306453] unix_convert: Begin: name [qwe] dirpath [.] name [qwe]
  9030. [2022-06-17 08:45:11.307955] stat_cache_add: Added entry (b52c73a0:size 14) 0000000000000000@QWE -> 0000000000000000@qwe
  9031. [2022-06-17 08:45:11.309725] unix_convert: Conversion of base_name finished [qwe] -> [qwe]
  9032. [2022-06-17 08:45:11.311389] unix_convert: Conversion finished [qwe] -> [qwe]
  9033. [2022-06-17 08:45:11.313067] is_in_path: qwe
  9034. [2022-06-17 08:45:11.314700] is_in_path: match not found
  9035. [2022-06-17 08:45:11.316324] check_reduced_name: check_reduced_name [qwe] [/mnt/share]
  9036. [2022-06-17 08:45:11.317949] check_reduced_name realpath [qwe] -> [/mnt/share/qwe]
  9037. [2022-06-17 08:45:11.319580] check_reduced_name: qwe reduced to /mnt/share/qwe
  9038. [2022-06-17 08:45:11.321213] openat_pathref_fsp: smb_fname [qwe]
  9039. [2022-06-17 08:45:11.322842] fsp_new: allocated files structure (1 used)
  9040. [2022-06-17 08:45:11.324549] file_name_hash: /mnt/share/qwe hash 0x7d430cc4
  9041. [2022-06-17 08:45:11.326195] check_reduced_name: check_reduced_name [qwe] [/mnt/share]
  9042. [2022-06-17 08:45:11.327831] check_reduced_name realpath [qwe] -> [/mnt/share/qwe]
  9043. [2022-06-17 08:45:11.329463] check_reduced_name: qwe reduced to /mnt/share/qwe
  9044. [2022-06-17 08:45:11.331091] fd_openat: name qwe, flags = 00 mode = 00, fd = 39
  9045. [2022-06-17 08:45:11.332730] openat_pathref_fsp: fsp [qwe]: OK
  9046. [2022-06-17 08:45:11.334439] create_file_default: create_file: access_mask = 0x120089 file_attributes = 0x0, share_access = 0x3, create_disposition = 0x1 create_options = 0x40 oplock_request = 0x0 private_flags = 0x0 ea_list = 0, sd = 0, fname = qwe
  9047. [2022-06-17 08:45:11.336195] create_file_unixpath: create_file_unixpath: access_mask = 0x120089 file_attributes = 0x0, share_access = 0x3, create_disposition = 0x1 create_options = 0x40 oplock_request = 0x0 private_flags = 0x0 ea_list = 0, sd = 0, fname = qwe
  9048. [2022-06-17 08:45:11.337944] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_open_global.tdb
  9049. [2022-06-17 08:45:11.339616] lock order: 1:/var/lock/smbXsrv_open_global.tdb 2:<none> 3:<none> 4:<none>
  9050. [2022-06-17 08:45:11.341272] db_tdb_log_key: Locking key C61EC380
  9051. [2022-06-17 08:45:11.342940] db_tdb_fetch_locked_internal: Allocated locked data 0xb5896d30
  9052. [2022-06-17 08:45:11.344604] smbXsrv_open_global_verify_record: empty value
  9053. [2022-06-17 08:45:11.346235] smbXsrv_open_global_store: key 'C61EC380' stored
  9054. [2022-06-17 08:45:11.347885] &global_blob: struct smbXsrv_open_globalB
  9055. [2022-06-17 08:45:11.349529] version : SMBXSRV_VERSION_0 (0)
  9056. [2022-06-17 08:45:11.351165] seqnum : 0x00000001 (1)
  9057. [2022-06-17 08:45:11.352794] info : union smbXsrv_open_globalU(case 0)
  9058. [2022-06-17 08:45:11.354491] info0 : *
  9059. [2022-06-17 08:45:11.356122] info0: struct smbXsrv_open_global0
  9060. [2022-06-17 08:45:11.357752] db_rec : *
  9061. [2022-06-17 08:45:11.359382] server_id: struct server_id
  9062. [2022-06-17 08:45:11.361017] pid : 0x0000000000002574 (9588)
  9063. [2022-06-17 08:45:11.362655] task_id : 0x00000000 (0)
  9064. [2022-06-17 08:45:11.364356] vnn : 0xffffffff (4294967295)
  9065. [2022-06-17 08:45:11.365881] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  9066. [2022-06-17 08:45:11.367666] open_global_id : 0xc61ec380 (3323904896)
  9067. [2022-06-17 08:45:11.369208] open_persistent_id : 0x00000000c61ec380 (3323904896)
  9068. [2022-06-17 08:45:11.370708] open_volatile_id : 0x000000003a146f1a (974417690)
  9069. [2022-06-17 08:45:11.372212] open_owner : S-1-5-21-3939785350-4027435424-1589595352-132066
  9070. [2022-06-17 08:45:11.374119] open_time : Fri Jun 17 08:45:09 2022 UTC
  9071. [2022-06-17 08:45:11.375792] create_guid : 00000000-0000-0000-0000-000000000000
  9072. [2022-06-17 08:45:11.377452] client_guid : 81388492-5b34-419d-9462-792b3b27d8b4
  9073. [2022-06-17 08:45:11.379107] app_instance_id : 00000000-0000-0000-0000-000000000000
  9074. [2022-06-17 08:45:11.380761] disconnect_time : NTTIME(0)
  9075. [2022-06-17 08:45:11.382397] durable_timeout_msec : 0x00000000 (0)
  9076. [2022-06-17 08:45:11.384134] durable : 0x00 (0)
  9077. [2022-06-17 08:45:11.385801] backend_cookie : DATA_BLOB length=0
  9078. [2022-06-17 08:45:11.387466] channel_sequence : 0x0000 (0)
  9079. [2022-06-17 08:45:11.389113] channel_generation : 0x0000000000000000 (0)
  9080. [2022-06-17 08:45:11.390742] lock_sequence_array: ARRAY(64)
  9081. [2022-06-17 08:45:11.392260] [0000] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9082. [2022-06-17 08:45:11.394092] [0010] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9083. [2022-06-17 08:45:11.395758] [0020] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9084. [2022-06-17 08:45:11.397426] [0030] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9085. [2022-06-17 08:45:11.399094] db_tdb_log_key: Unlocking key C61EC380
  9086. [2022-06-17 08:45:11.400732] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_open_global.tdb
  9087. [2022-06-17 08:45:11.402378] smbXsrv_open_create: global_id (0xc61ec380) stored
  9088. [2022-06-17 08:45:11.404101] &open_blob: struct smbXsrv_openB
  9089. [2022-06-17 08:45:11.405740] version : SMBXSRV_VERSION_0 (0)
  9090. [2022-06-17 08:45:11.407367] reserved : 0x00000000 (0)
  9091. [2022-06-17 08:45:11.409006] info : union smbXsrv_openU(case 0)
  9092. [2022-06-17 08:45:11.410641] info0 : *
  9093. [2022-06-17 08:45:11.412272] info0: struct smbXsrv_open
  9094. [2022-06-17 08:45:11.413949] table : *
  9095. [2022-06-17 08:45:11.415581] db_rec : NULL
  9096. [2022-06-17 08:45:11.417207] local_id : 0x3a146f1a (974417690)
  9097. [2022-06-17 08:45:11.418845] global : *
  9098. [2022-06-17 08:45:11.420498] global: struct smbXsrv_open_global0
  9099. [2022-06-17 08:45:11.422155] db_rec : NULL
  9100. [2022-06-17 08:45:11.423847] server_id: struct server_id
  9101. [2022-06-17 08:45:11.425489] pid : 0x0000000000002574 (9588)
  9102. [2022-06-17 08:45:11.427144] task_id : 0x00000000 (0)
  9103. [2022-06-17 08:45:11.428796] vnn : 0xffffffff (4294967295)
  9104. [2022-06-17 08:45:11.430450] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  9105. [2022-06-17 08:45:11.432125] open_global_id : 0xc61ec380 (3323904896)
  9106. [2022-06-17 08:45:11.433868] open_persistent_id : 0x00000000c61ec380 (3323904896)
  9107. [2022-06-17 08:45:11.435559] open_volatile_id : 0x000000003a146f1a (974417690)
  9108. [2022-06-17 08:45:11.437222] open_owner : S-1-5-21-3939785350-4027435424-1589595352-132066
  9109. [2022-06-17 08:45:11.438892] open_time : Fri Jun 17 08:45:09 2022 UTC
  9110. [2022-06-17 08:45:11.440546] create_guid : 00000000-0000-0000-0000-000000000000
  9111. [2022-06-17 08:45:11.442205] client_guid : 81388492-5b34-419d-9462-792b3b27d8b4
  9112. [2022-06-17 08:45:11.443891] app_instance_id : 00000000-0000-0000-0000-000000000000
  9113. [2022-06-17 08:45:11.445558] disconnect_time : NTTIME(0)
  9114. [2022-06-17 08:45:11.447197] durable_timeout_msec : 0x00000000 (0)
  9115. [2022-06-17 08:45:11.448832] durable : 0x00 (0)
  9116. [2022-06-17 08:45:11.450463] backend_cookie : DATA_BLOB length=0
  9117. [2022-06-17 08:45:11.452090] channel_sequence : 0x0000 (0)
  9118. [2022-06-17 08:45:11.453806] channel_generation : 0x0000000000000000 (0)
  9119. [2022-06-17 08:45:11.455480] lock_sequence_array: ARRAY(64)
  9120. [2022-06-17 08:45:11.457142] [0000] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9121. [2022-06-17 08:45:11.458806] [0010] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9122. [2022-06-17 08:45:11.460455] [0020] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9123. [2022-06-17 08:45:11.462102] [0030] FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF ........ ........
  9124. [2022-06-17 08:45:11.463812] status : NT_STATUS_OK
  9125. [2022-06-17 08:45:11.465459] idle_time : Fri Jun 17 08:45:09 2022 UTC
  9126. [2022-06-17 08:45:11.467100] compat : NULL
  9127. [2022-06-17 08:45:11.468743] flags : 0x00 (0)
  9128. [2022-06-17 08:45:11.470395] 0: SMBXSRV_OPEN_NEED_REPLAY_CACHE
  9129. [2022-06-17 08:45:11.472039] 0: SMBXSRV_OPEN_HAVE_REPLAY_CACHE
  9130. [2022-06-17 08:45:11.473731] create_action : 0x00000000 (0)
  9131. [2022-06-17 08:45:11.475377] request_count : 0x0000000000000000 (0)
  9132. [2022-06-17 08:45:11.477024] pre_request_count : 0x0000000000000000 (0)
  9133. [2022-06-17 08:45:11.478658] fsp_bind_smb: fsp [qwe] mid [10]
  9134. [2022-06-17 08:45:11.480275] unix_mode: unix_mode(qwe) returning 0666
  9135. [2022-06-17 08:45:11.481908] open_file_ntcreate: fname=qwe, dos_attrs=0x0 access_mask=0x120089 share_access=0x3 create_disposition = 0x1 create_options=0x40 unix mode=0666 oplock_request=0 private_flags = 0x0
  9136. [2022-06-17 08:45:11.483684] fget_ea_dos_attribute: Cannot get attribute from EA on file qwe: Error = No data available
  9137. [2022-06-17 08:45:11.485363] open_file_ntcreate: fname=qwe, after mapping access_mask=0x120089
  9138. [2022-06-17 08:45:11.487087] calling open_file with flags=0x0 flags2=0x800 mode=0666, access_mask = 0x120089, open_access_mask = 0x120089
  9139. [2022-06-17 08:45:11.488792] posix_get_nt_acl: called for file qwe
  9140. [2022-06-17 08:45:11.490435] push_sec_ctx(65533, 65534) : sec_ctx_stack_ndx = 1
  9141. [2022-06-17 08:45:11.492079] push_conn_ctx(1863994182) : conn_ctx_stack_ndx = 0
  9142. [2022-06-17 08:45:11.493775] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  9143. [2022-06-17 08:45:11.495435] Security token: (NULL)
  9144. [2022-06-17 08:45:11.497064] UNIX token of user 0
  9145. [2022-06-17 08:45:11.498677] Primary group is 0 and contains 0 supplementary groups
  9146. [2022-06-17 08:45:11.500304] push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
  9147. [2022-06-17 08:45:11.501816] push_conn_ctx(1863994182) : conn_ctx_stack_ndx = 1
  9148. [2022-06-17 08:45:11.503444] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
  9149. [2022-06-17 08:45:11.505200] Security token: (NULL)
  9150. [2022-06-17 08:45:11.506836] UNIX token of user 0
  9151. [2022-06-17 08:45:11.508467] Primary group is 0 and contains 0 supplementary groups
  9152. [2022-06-17 08:45:11.509990] getsampwnam (smbpasswd): search by name: root
  9153. [2022-06-17 08:45:11.511503] startsmbfilepwent_internal: opening file /etc/samba/smbpasswd
  9154. [2022-06-17 08:45:11.513314] getsmbfilepwent: skipping comment or blank line
  9155. [2022-06-17 08:45:11.514969] getsmbfilepwent: LM password for user nobody invalidated
  9156. [2022-06-17 08:45:11.516620] getsmbfilepwent: returning passwd entry for user nobody, uid 0
  9157. [2022-06-17 08:45:11.518278] getsmbfilepwent: LM password for user useruser invalidated
  9158. [2022-06-17 08:45:11.519914] getsmbfilepwent: returning passwd entry for user useruser, uid 65533
  9159. [2022-06-17 08:45:11.521549] getsmbfilepwent: end of file reached.
  9160. [2022-06-17 08:45:11.523211] endsmbfilepwent_internal: closed password file.
  9161. [2022-06-17 08:45:11.524860] pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
  9162. [2022-06-17 08:45:11.526489] pdb_default_uid_to_sid: Did not find user root (0)
  9163. [2022-06-17 08:45:11.528133] pop_sec_ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  9164. [2022-06-17 08:45:11.529776] xid_to_sid: UID 0 -> S-1-22-1-0 fallback
  9165. [2022-06-17 08:45:11.531396] push_sec_ctx(65533, 65534) : sec_ctx_stack_ndx = 1
  9166. [2022-06-17 08:45:11.533073] push_conn_ctx(1863994182) : conn_ctx_stack_ndx = 0
  9167. [2022-06-17 08:45:11.534718] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
  9168. [2022-06-17 08:45:11.536358] Security token: (NULL)
  9169. [2022-06-17 08:45:11.537970] UNIX token of user 0
  9170. [2022-06-17 08:45:11.539583] Primary group is 0 and contains 0 supplementary groups
  9171. [2022-06-17 08:45:11.541220] pop_sec_ctx (65533, 65534) - sec_ctx_stack_ndx = 0
  9172. [2022-06-17 08:45:11.542920] xid_to_sid: GID 0 -> S-1-22-2-0 fallback
  9173. [2022-06-17 08:45:11.544585] canonicalise_acl: Access ace entries before arrange :
  9174. [2022-06-17 08:45:11.546114] canon_ace index 0. Type = allow SID = S-1-1-0 other SMB_ACL_OTHER ace_flags = 0x0 perms r--
  9175. [2022-06-17 08:45:11.547628] canon_ace index 1. Type = allow SID = S-1-22-2-0 gid 0 SMB_ACL_GROUP_OBJ ace_flags = 0x0 perms r--
  9176. [2022-06-17 08:45:11.549136] canon_ace index 2. Type = allow SID = S-1-22-1-0 uid 0 SMB_ACL_USER_OBJ ace_flags = 0x0 perms rw-
  9177. [2022-06-17 08:45:11.550657] print_canon_ace_list: canonicalise_acl: ace entries after arrange
  9178. [2022-06-17 08:45:11.552394] canon_ace index 0. Type = allow SID = S-1-22-1-0 uid 0 SMB_ACL_USER_OBJ ace_flags = 0x0 perms rw-
  9179. [2022-06-17 08:45:11.554168] canon_ace index 1. Type = allow SID = S-1-22-2-0 gid 0 SMB_ACL_GROUP_OBJ ace_flags = 0x0 perms r--
  9180. [2022-06-17 08:45:11.555855] canon_ace index 2. Type = allow SID = S-1-1-0 other SMB_ACL_OTHER ace_flags = 0x0 perms r--
  9181. [2022-06-17 08:45:11.557519] map_canon_ace_perms: Mapped (UNIX) 180 to (NT) 12019f
  9182. [2022-06-17 08:45:11.559135] map_canon_ace_perms: Mapped (UNIX) 100 to (NT) 120089
  9183. [2022-06-17 08:45:11.560643] map_canon_ace_perms: Mapped (UNIX) 100 to (NT) 120089
  9184. [2022-06-17 08:45:11.562416] smbd_check_access_rights_sd: File [qwe] requesting [0x120089] returning [0x120009] (NT_STATUS_OK)
  9185. [2022-06-17 08:45:11.564189] delete_lock_ref_count for file qwe
  9186. [2022-06-17 08:45:11.565839] useruser opened file qwe read=Yes write=No (numopen=1)
  9187. [2022-06-17 08:45:11.567363] dbwrap_watched_subrec_wakeup_fn: No watchers
  9188. [2022-06-17 08:45:11.568963] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9189. [2022-06-17 08:45:11.570712] dbwrap_lock_order_lock: check lock order 1 for /var/lock/locking.tdb
  9190. [2022-06-17 08:45:11.572366] lock order: 1:/var/lock/locking.tdb 2:<none> 3:<none> 4:<none>
  9191. [2022-06-17 08:45:11.574106] share_mode_forall_entries: num_share_modes=0
  9192. [2022-06-17 08:45:11.575748] share_mode_forall_entries: num_share_entries=0, writeback=0
  9193. [2022-06-17 08:45:11.577422] find_delete_on_close_token: name_hash = 0x7d430cc4
  9194. [2022-06-17 08:45:11.579064] share_conflict: existing access_mask = 0x0, existing share access = 0x7, access_mask = 0x120089, share_access = 0x3
  9195. [2022-06-17 08:45:11.580748] share_conflict: No conflict due to existing access_mask = 0x0
  9196. [2022-06-17 08:45:11.582392] open_mode_check: No conflict due to share_mode_flags access
  9197. [2022-06-17 08:45:11.584173] share_mode_forall_entries: num_share_modes=0
  9198. [2022-06-17 08:45:11.585829] share_mode_forall_entries: num_share_entries=0, writeback=0
  9199. [2022-06-17 08:45:11.587474] seqnum=0, fsp->brlock_seqnum=0
  9200. [2022-06-17 08:45:11.589107] set_file_oplock: granted oplock on file qwe, 19:193:0/3, tv_sec = 62ac3f15, tv_usec = 4bdbb
  9201. [2022-06-17 08:45:11.590651] delay_for_oplock: oplock type 0x0 on file qwe
  9202. [2022-06-17 08:45:11.592151] set_share_mode: num_share_modes=0
  9203. [2022-06-17 08:45:11.593692] share_mode_entry_put: share_mode_entry:
  9204. [2022-06-17 08:45:11.595188] discard_const_p(void, e): struct share_mode_entry
  9205. [2022-06-17 08:45:11.596683] pid: struct server_id
  9206. [2022-06-17 08:45:11.598169] pid : 0x0000000000002574 (9588)
  9207. [2022-06-17 08:45:11.599668] task_id : 0x00000000 (0)
  9208. [2022-06-17 08:45:11.601161] vnn : 0xffffffff (4294967295)
  9209. [2022-06-17 08:45:11.602665] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  9210. [2022-06-17 08:45:11.604240] op_mid : 0x000000000000000a (10)
  9211. [2022-06-17 08:45:11.605935] op_type : 0x0000 (0)
  9212. [2022-06-17 08:45:11.607467] client_guid : 00000000-0000-0000-0000-000000000000
  9213. [2022-06-17 08:45:11.608968] lease_key: struct smb2_lease_key
  9214. [2022-06-17 08:45:11.610448] data: ARRAY(2)
  9215. [2022-06-17 08:45:11.611924] data : 0x0000000000000000 (0)
  9216. [2022-06-17 08:45:11.613482] data : 0x0000000000000000 (0)
  9217. [2022-06-17 08:45:11.615005] access_mask : 0x00120089 (1179785)
  9218. [2022-06-17 08:45:11.616499] share_access : 0x00000003 (3)
  9219. [2022-06-17 08:45:11.617992] private_options : 0x00000000 (0)
  9220. [2022-06-17 08:45:11.619492] time : Fri Jun 17 08:45:09 2022 UTC.310715
  9221. [2022-06-17 08:45:11.621211] share_file_id : 0x0000000000000003 (3)
  9222. [2022-06-17 08:45:11.622725] uid : 0x0000fffd (65533)
  9223. [2022-06-17 08:45:11.624290] flags : 0x0000 (0)
  9224. [2022-06-17 08:45:11.626269] name_hash : 0x7d430cc4 (2101546180)
  9225. [2022-06-17 08:45:11.627939] stale : 0x00 (0)
  9226. [2022-06-17 08:45:11.629579] set_share_mode: idx=0, found=0
  9227. [2022-06-17 08:45:11.631215] set_share_mode: dbufs[0]=(0xbed70020, 132)
  9228. [2022-06-17 08:45:11.632908] dbwrap_watched_subrec_wakeup_fn: No watchers
  9229. [2022-06-17 08:45:11.634559] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9230. [2022-06-17 08:45:11.636213] share_mode_data_store:
  9231. [2022-06-17 08:45:11.637836] d: struct share_mode_data
  9232. [2022-06-17 08:45:11.639468] unique_content_epoch : 0x18806ab16114c44b (1765528363999741003)
  9233. [2022-06-17 08:45:11.641110] flags : 0x00c8 (200)
  9234. [2022-06-17 08:45:11.642731] 0: SHARE_MODE_SHARE_DELETE
  9235. [2022-06-17 08:45:11.644420] 1: SHARE_MODE_SHARE_WRITE
  9236. [2022-06-17 08:45:11.646063] 1: SHARE_MODE_SHARE_READ
  9237. [2022-06-17 08:45:11.647695] 0: SHARE_MODE_ACCESS_DELETE
  9238. [2022-06-17 08:45:11.649332] 0: SHARE_MODE_ACCESS_WRITE
  9239. [2022-06-17 08:45:11.650968] 1: SHARE_MODE_ACCESS_READ
  9240. [2022-06-17 08:45:11.652604] 0: SHARE_MODE_LEASE_HANDLE
  9241. [2022-06-17 08:45:11.654311] 0: SHARE_MODE_LEASE_WRITE
  9242. [2022-06-17 08:45:11.655948] 0: SHARE_MODE_LEASE_READ
  9243. [2022-06-17 08:45:11.657573] servicepath : *
  9244. [2022-06-17 08:45:11.659201] servicepath : '/mnt/share'
  9245. [2022-06-17 08:45:11.660860] base_name : *
  9246. [2022-06-17 08:45:11.662498] base_name : 'qwe'
  9247. [2022-06-17 08:45:11.664256] stream_name : NULL
  9248. [2022-06-17 08:45:11.665898] num_delete_tokens : 0x00000000 (0)
  9249. [2022-06-17 08:45:11.667529] delete_tokens: ARRAY(0)
  9250. [2022-06-17 08:45:11.669158] old_write_time : Fri Jun 17 06:10:26 2022 UTC
  9251. [2022-06-17 08:45:11.670800] changed_write_time : NTTIME(0)
  9252. [2022-06-17 08:45:11.672448] fresh : 0x01 (1)
  9253. [2022-06-17 08:45:11.674176] modified : 0x01 (1)
  9254. [2022-06-17 08:45:11.675830] id: struct file_id
  9255. [2022-06-17 08:45:11.677452] devid : 0x0000000000000013 (19)
  9256. [2022-06-17 08:45:11.678974] inode : 0x00000000000000c1 (193)
  9257. [2022-06-17 08:45:11.680470] extid : 0x0000000000000000 (0)
  9258. [2022-06-17 08:45:11.682126] dbwrap_watched_subrec_wakeup_fn: No watchers
  9259. [2022-06-17 08:45:11.683967] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9260. [2022-06-17 08:45:11.685647] dbwrap_watched_subrec_wakeup_fn: No watchers
  9261. [2022-06-17 08:45:11.687305] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9262. [2022-06-17 08:45:11.688959] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/locking.tdb
  9263. [2022-06-17 08:45:11.690616] share_mode_memcache_store: stored entry for file qwe epoch 18806ab16114c44d key 19:193:0
  9264. [2022-06-17 08:45:11.692273] create_file_unixpath: info=1
  9265. [2022-06-17 08:45:11.693969] create_file: info=1
  9266. [2022-06-17 08:45:11.695684] smbd_smb2_create_send: response construction phase
  9267. [2022-06-17 08:45:11.697351] fdos_mode: qwe
  9268. [2022-06-17 08:45:11.698974] fget_ea_dos_attribute: Cannot get attribute from EA on file qwe: Error = No data available
  9269. [2022-06-17 08:45:11.700631] dos_mode_debug_print: fdos_mode returning (0x80): ""
  9270. [2022-06-17 08:45:11.702272] smbd_smb2_create_finish: qwe - fnum 974417690
  9271. [2022-06-17 08:45:11.703972] smbd_smb2_request_done_ex: mid [10] idx[1] status[NT_STATUS_OK] body[88] dyn[yes:0] at ../../source3/smbd/smb2_create.c:405
  9272. [2022-06-17 08:45:11.705663] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/11/8192
  9273. [2022-06-17 08:45:11.707372] smbd_smb2_request idx[1] of 5 vectors
  9274. [2022-06-17 08:45:11.709026] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 11 (position 11) from bitmap
  9275. [2022-06-17 08:45:11.710702] smbd_smb2_request_dispatch: opcode[SMB2_OP_GETINFO] mid = 11
  9276. [2022-06-17 08:45:11.712228] change_to_user_impersonate: Skipping user change - already user
  9277. [2022-06-17 08:45:11.713776] vfs_ChDir to /mnt/share
  9278. [2022-06-17 08:45:11.715251] vfs_ChDir: vfs_ChDir got /mnt/share
  9279. [2022-06-17 08:45:11.716735] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  9280. [2022-06-17 08:45:11.718256] smbd_smb2_request_verify_creditcharge: mid 11, CreditCharge: 1, NeededCharge: 1
  9281. [2022-06-17 08:45:11.719759] smbd_smb2_getinfo_send: qwe - fnum 974417690
  9282. [2022-06-17 08:45:11.721257] share_mode_memcache_fetch: fetched entry for file qwe epoch 18806ab16114c44d key 19:193:0
  9283. [2022-06-17 08:45:11.722759] find_delete_on_close_token: name_hash = 0x7d430cc4
  9284. [2022-06-17 08:45:11.724310] smbd_do_qfilepathinfo: qwe (fnum 974417690) level=65298 max_data=65535
  9285. [2022-06-17 08:45:11.726161] fdos_mode: qwe
  9286. [2022-06-17 08:45:11.727800] fget_ea_dos_attribute: Cannot get attribute from EA on file qwe: Error = No data available
  9287. [2022-06-17 08:45:11.729469] dos_mode_debug_print: fdos_mode returning (0x80): ""
  9288. [2022-06-17 08:45:11.731159] get_ea_names_from_file: ea_namelist size = 0
  9289. [2022-06-17 08:45:11.732830] fill_ea_chained_buffer: data_size = 0
  9290. [2022-06-17 08:45:11.734529] smbd_do_qfilepathinfo: SMB2_FILE_ALL_INFORMATION
  9291. [2022-06-17 08:45:11.736182] smbd_smb2_request_done_ex: mid [11] idx[1] status[NT_STATUS_OK] body[8] dyn[yes:108] at ../../source3/smbd/smb2_getinfo.c:206
  9292. [2022-06-17 08:45:11.737862] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/12/8192
  9293. [2022-06-17 08:45:11.739572] smbd_smb2_request idx[1] of 5 vectors
  9294. [2022-06-17 08:45:11.741200] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 12 (position 12) from bitmap
  9295. [2022-06-17 08:45:11.742915] smbd_smb2_request_dispatch: opcode[SMB2_OP_READ] mid = 12
  9296. [2022-06-17 08:45:11.744592] change_to_user_impersonate: Skipping user change - already user
  9297. [2022-06-17 08:45:11.746252] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  9298. [2022-06-17 08:45:11.747915] smbd_smb2_request_verify_creditcharge: mid 12, CreditCharge: 1, NeededCharge: 1
  9299. [2022-06-17 08:45:11.749561] smbd_smb2_read: qwe - fnum 974417690
  9300. [2022-06-17 08:45:11.751192] seqnum=0, fsp->brlock_seqnum=0
  9301. [2022-06-17 08:45:11.752829] is_posix_locked: File qwe, offset = 0, count = 64000, type = READ
  9302. [2022-06-17 08:45:11.754534] posix_lock_in_range: offset_out = 0, count_out = 64000
  9303. [2022-06-17 08:45:11.756197] posix_fcntl_getlock 40 0 64000 0
  9304. [2022-06-17 08:45:11.757851] fcntl_getlock fd=40 op=12 offset=0 count=64000 type=0
  9305. [2022-06-17 08:45:11.759501] fcntl_getlock: fd 40 is returned info 2 pid 0
  9306. [2022-06-17 08:45:11.761126] posix_fcntl_getlock: Lock query call successful
  9307. [2022-06-17 08:45:11.762763] brl_locktest: posix start=0 len=64000 unlocked for fnum 974417690 file qwe
  9308. [2022-06-17 08:45:11.764467] strict_lock_default: flavour = WINDOWS_LOCK brl start=0 len=64000 unlocked for fnum 974417690 file qwe
  9309. [2022-06-17 08:45:11.766144] smb2: scheduled aio_read for file qwe, offset 0, len = 64000 (mid = 12)
  9310. [2022-06-17 08:45:11.767797] smbd_smb2_request_pending_queue: req->current_idx = 1
  9311. [2022-06-17 08:45:11.769447] req->in.vector[0].iov_len = 0
  9312. [2022-06-17 08:45:11.771081] req->in.vector[1].iov_len = 0
  9313. [2022-06-17 08:45:11.772711] req->in.vector[2].iov_len = 64
  9314. [2022-06-17 08:45:11.774391] req->in.vector[3].iov_len = 48
  9315. [2022-06-17 08:45:11.776022] req->in.vector[4].iov_len = 1
  9316. [2022-06-17 08:45:11.777526] req->out.vector[0].iov_len = 4
  9317. [2022-06-17 08:45:11.779279] req->out.vector[1].iov_len = 0
  9318. [2022-06-17 08:45:11.780922] req->out.vector[2].iov_len = 64
  9319. [2022-06-17 08:45:11.782562] req->out.vector[3].iov_len = 8
  9320. [2022-06-17 08:45:11.784282] req->out.vector[4].iov_len = 0
  9321. [2022-06-17 08:45:11.785910] smbd_smb2_request_pending_queue: opcode[SMB2_OP_READ] mid 12 going async
  9322. [2022-06-17 08:45:11.787555] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/13/8192
  9323. [2022-06-17 08:45:11.789272] state->vector[0/5].iov_len = 4
  9324. [2022-06-17 08:45:11.790906] state->vector[1/5].iov_len = 0
  9325. [2022-06-17 08:45:11.792528] state->vector[2/5].iov_len = 64
  9326. [2022-06-17 08:45:11.794139] state->vector[3/5].iov_len = 8
  9327. [2022-06-17 08:45:11.795647] state->vector[4/5].iov_len = 1
  9328. [2022-06-17 08:45:29.841629] smbd_smb2_request idx[1] of 5 vectors
  9329. [2022-06-17 08:45:29.842611] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 13 (position 13) from bitmap
  9330. [2022-06-17 08:45:29.845676] smbd_smb2_request_dispatch: opcode[SMB2_OP_CLOSE] mid = 13
  9331. [2022-06-17 08:45:29.847389] change_to_user_impersonate: Skipping user change - already user
  9332. [2022-06-17 08:45:29.849063] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  9333. [2022-06-17 08:45:29.850755] smbd_smb2_request_pending_queue: req->current_idx = 1
  9334. [2022-06-17 08:45:29.852407] req->in.vector[0].iov_len = 0
  9335. [2022-06-17 08:45:29.854143] req->in.vector[1].iov_len = 0
  9336. [2022-06-17 08:45:29.855775] req->in.vector[2].iov_len = 64
  9337. [2022-06-17 08:45:29.857407] req->in.vector[3].iov_len = 24
  9338. [2022-06-17 08:45:29.859032] req->in.vector[4].iov_len = 0
  9339. [2022-06-17 08:45:29.860657] req->out.vector[0].iov_len = 4
  9340. [2022-06-17 08:45:29.862292] req->out.vector[1].iov_len = 0
  9341. [2022-06-17 08:45:29.864014] req->out.vector[2].iov_len = 64
  9342. [2022-06-17 08:45:29.865654] req->out.vector[3].iov_len = 8
  9343. [2022-06-17 08:45:29.867287] req->out.vector[4].iov_len = 0
  9344. [2022-06-17 08:45:29.868964] smbd_smb2_request_pending_queue: opcode[SMB2_OP_CLOSE] mid 13 going async
  9345. [2022-06-17 08:45:29.870642] smb2_set_operation_credit: smb2_set_operation_credit: requested 1, charge 1, granted 1, current possible/max 1/8192, total granted/max/low/range 8192/8192/14/8192
  9346. [2022-06-17 08:45:29.872353] state->vector[0/5].iov_len = 4
  9347. [2022-06-17 08:45:29.874081] state->vector[1/5].iov_len = 0
  9348. [2022-06-17 08:45:29.875728] state->vector[2/5].iov_len = 64
  9349. [2022-06-17 08:45:29.877364] state->vector[3/5].iov_len = 8
  9350. [2022-06-17 08:45:29.878995] state->vector[4/5].iov_len = 1
  9351. [2022-06-17 08:45:49.876361] smbd_smb2_request idx[1] of 5 vectors
  9352. [2022-06-17 08:45:49.878179] smb2_validate_sequence_number: smb2_validate_sequence_number: clearing id 14 (position 14) from bitmap
  9353. [2022-06-17 08:45:49.879953] smbd_smb2_request_dispatch: opcode[SMB2_OP_TDIS] mid = 14
  9354. [2022-06-17 08:45:49.881644] change_to_user_impersonate: Skipping user change - already user
  9355. [2022-06-17 08:45:49.883477] print_impersonation_info: Impersonated user: uid=(65533,65533), gid=(0,65534), cwd=[/mnt/share]
  9356. [2022-06-17 08:45:49.885048] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9357. [2022-06-17 08:45:49.886691] Security token: (NULL)
  9358. [2022-06-17 08:45:49.888389] UNIX token of user 0
  9359. [2022-06-17 08:45:49.889876] Primary group is 0 and contains 0 supplementary groups
  9360. [2022-06-17 08:45:49.891519] change_to_root_user: now uid=(0,0) gid=(0,0)
  9361. [2022-06-17 08:46:05.073933] smbd_idle_event_handler: idle_evt(deadtime) 0 called
  9362. [2022-06-17 08:46:05.074910] smbd_idle_event_handler: idle_evt(deadtime) 0 rescheduled
  9363. [2022-06-17 08:46:05.075648] smbd_idle_event_handler: idle_evt(housekeeping) 0 called
  9364. [2022-06-17 08:46:05.076341] housekeeping
  9365. [2022-06-17 08:46:05.077015] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9366. [2022-06-17 08:46:05.077690] Security token: (NULL)
  9367. [2022-06-17 08:46:05.078366] UNIX token of user 0
  9368. [2022-06-17 08:46:05.079029] Primary group is 0 and contains 0 supplementary groups
  9369. [2022-06-17 08:46:05.079695] change_to_root_user: now uid=(0,0) gid=(0,0)
  9370. [2022-06-17 08:46:05.080365] smbd_idle_event_handler: idle_evt(housekeeping) 0 rescheduled
  9371. [2022-06-17 08:46:09.913069] smbd_server_connection_terminate_ex: conn[ipv4:192.168.1.10:33730] num_ok[0] reason[NT_STATUS_END_OF_FILE] at ../../source3/smbd/smb2_server.c:4940
  9372. [2022-06-17 08:46:09.914886] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9373. [2022-06-17 08:46:09.923814] Security token: (NULL)
  9374. [2022-06-17 08:46:09.925627] UNIX token of user 0
  9375. [2022-06-17 08:46:09.927192] Primary group is 0 and contains 0 supplementary groups
  9376. [2022-06-17 08:46:09.928862] change_to_root_user: now uid=(0,0) gid=(0,0)
  9377. [2022-06-17 08:46:09.930648] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9378. [2022-06-17 08:46:09.932286] Security token: (NULL)
  9379. [2022-06-17 08:46:09.945268] UNIX token of user 0
  9380. [2022-06-17 08:46:09.947203] Primary group is 0 and contains 0 supplementary groups
  9381. [2022-06-17 08:46:09.948922] change_to_root_user: now uid=(0,0) gid=(0,0)
  9382. [2022-06-17 08:46:09.950583] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9383. [2022-06-17 08:46:09.952229] Security token: (NULL)
  9384. [2022-06-17 08:46:09.953789] UNIX token of user 0
  9385. [2022-06-17 08:46:09.955431] Primary group is 0 and contains 0 supplementary groups
  9386. [2022-06-17 08:46:09.957082] change_to_root_user: now uid=(0,0) gid=(0,0)
  9387. [2022-06-17 08:46:09.958726] dbwrap_watched_subrec_wakeup_fn: No watchers
  9388. [2022-06-17 08:46:09.960224] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9389. [2022-06-17 08:46:09.961859] dbwrap_lock_order_lock: check lock order 1 for /var/lock/locking.tdb
  9390. [2022-06-17 08:46:09.963559] lock order: 1:/var/lock/locking.tdb 2:<none> 3:<none> 4:<none>
  9391. [2022-06-17 08:46:09.965239] share_mode_memcache_fetch: failed to find entry for key 19:193:0
  9392. [2022-06-17 08:46:09.966897] parse_share_modes:
  9393. [2022-06-17 08:46:09.968518] d: struct share_mode_data
  9394. [2022-06-17 08:46:09.970166] unique_content_epoch : 0x18806ab16114c44d (1765528363999741005)
  9395. [2022-06-17 08:46:09.971924] flags : 0x00c8 (200)
  9396. [2022-06-17 08:46:09.973492] 0: SHARE_MODE_SHARE_DELETE
  9397. [2022-06-17 08:46:09.975245] 1: SHARE_MODE_SHARE_WRITE
  9398. [2022-06-17 08:46:09.976878] 1: SHARE_MODE_SHARE_READ
  9399. [2022-06-17 08:46:09.978401] 0: SHARE_MODE_ACCESS_DELETE
  9400. [2022-06-17 08:46:09.980046] 0: SHARE_MODE_ACCESS_WRITE
  9401. [2022-06-17 08:46:09.981673] 1: SHARE_MODE_ACCESS_READ
  9402. [2022-06-17 08:46:09.983363] 0: SHARE_MODE_LEASE_HANDLE
  9403. [2022-06-17 08:46:09.985017] 0: SHARE_MODE_LEASE_WRITE
  9404. [2022-06-17 08:46:09.986663] 0: SHARE_MODE_LEASE_READ
  9405. [2022-06-17 08:46:09.988281] servicepath : *
  9406. [2022-06-17 08:46:09.990026] servicepath : '/mnt/share'
  9407. [2022-06-17 08:46:09.991557] base_name : *
  9408. [2022-06-17 08:46:09.993106] base_name : 'qwe'
  9409. [2022-06-17 08:46:09.994779] stream_name : NULL
  9410. [2022-06-17 08:46:09.996395] num_delete_tokens : 0x00000000 (0)
  9411. [2022-06-17 08:46:09.998032] delete_tokens: ARRAY(0)
  9412. [2022-06-17 08:46:09.999659] old_write_time : Fri Jun 17 06:10:26 2022 UTC
  9413. [2022-06-17 08:46:10.001310] changed_write_time : NTTIME(0)
  9414. [2022-06-17 08:46:10.002996] fresh : 0x00 (0)
  9415. [2022-06-17 08:46:10.004648] modified : 0x00 (0)
  9416. [2022-06-17 08:46:10.006276] id: struct file_id
  9417. [2022-06-17 08:46:10.007987] devid : 0x0000000000000013 (19)
  9418. [2022-06-17 08:46:10.009515] inode : 0x00000000000000c1 (193)
  9419. [2022-06-17 08:46:10.011159] extid : 0x0000000000000000 (0)
  9420. [2022-06-17 08:46:10.012807] find_delete_on_close_token: name_hash = 0x7d430cc4
  9421. [2022-06-17 08:46:10.014503] share_mode_entry_do: num_share_modes=1
  9422. [2022-06-17 08:46:10.016257] share_mode_entry_find: left=0, right=0, middle=0, middle_ptr=0xb5147554
  9423. [2022-06-17 08:46:10.017901] share_mode_entry_do: entry[0]:
  9424. [2022-06-17 08:46:10.019420] &e: struct share_mode_entry
  9425. [2022-06-17 08:46:10.021147] pid: struct server_id
  9426. [2022-06-17 08:46:10.022760] pid : 0x0000000000002574 (9588)
  9427. [2022-06-17 08:46:10.024459] task_id : 0x00000000 (0)
  9428. [2022-06-17 08:46:10.025994] vnn : 0xffffffff (4294967295)
  9429. [2022-06-17 08:46:10.028060] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  9430. [2022-06-17 08:46:10.029742] op_mid : 0x000000000000000a (10)
  9431. [2022-06-17 08:46:10.031373] op_type : 0x0000 (0)
  9432. [2022-06-17 08:46:10.033031] client_guid : 00000000-0000-0000-0000-000000000000
  9433. [2022-06-17 08:46:10.034570] lease_key: struct smb2_lease_key
  9434. [2022-06-17 08:46:10.036209] data: ARRAY(2)
  9435. [2022-06-17 08:46:10.037837] data : 0x0000000000000000 (0)
  9436. [2022-06-17 08:46:10.039472] data : 0x0000000000000000 (0)
  9437. [2022-06-17 08:46:10.041132] access_mask : 0x00120089 (1179785)
  9438. [2022-06-17 08:46:10.042774] share_access : 0x00000003 (3)
  9439. [2022-06-17 08:46:10.044491] private_options : 0x00000000 (0)
  9440. [2022-06-17 08:46:10.046235] time : Fri Jun 17 08:45:09 2022 UTC.310715
  9441. [2022-06-17 08:46:10.047869] share_file_id : 0x0000000000000003 (3)
  9442. [2022-06-17 08:46:10.049390] uid : 0x0000fffd (65533)
  9443. [2022-06-17 08:46:10.051060] flags : 0x0000 (0)
  9444. [2022-06-17 08:46:10.052800] name_hash : 0x7d430cc4 (2101546180)
  9445. [2022-06-17 08:46:10.054494] stale : 0x00 (0)
  9446. [2022-06-17 08:46:10.056031] share_mode_entry_do: entry[0]: modified=0, e.stale=1
  9447. [2022-06-17 08:46:10.057674] share_mode_entry_do: share_mode_entry:
  9448. [2022-06-17 08:46:10.059398] &e: struct share_mode_entry
  9449. [2022-06-17 08:46:10.060911] pid: struct server_id
  9450. [2022-06-17 08:46:10.062633] pid : 0x0000000000002574 (9588)
  9451. [2022-06-17 08:46:10.064353] task_id : 0x00000000 (0)
  9452. [2022-06-17 08:46:10.065886] vnn : 0xffffffff (4294967295)
  9453. [2022-06-17 08:46:10.067520] unique_id : 0x1f1c5a526b61e095 (2241766024559059093)
  9454. [2022-06-17 08:46:10.069170] op_mid : 0x000000000000000a (10)
  9455. [2022-06-17 08:46:10.070909] op_type : 0x0000 (0)
  9456. [2022-06-17 08:46:10.072530] client_guid : 00000000-0000-0000-0000-000000000000
  9457. [2022-06-17 08:46:10.074147] lease_key: struct smb2_lease_key
  9458. [2022-06-17 08:46:10.075892] data: ARRAY(2)
  9459. [2022-06-17 08:46:10.077483] data : 0x0000000000000000 (0)
  9460. [2022-06-17 08:46:10.079141] data : 0x0000000000000000 (0)
  9461. [2022-06-17 08:46:10.080899] access_mask : 0x00120089 (1179785)
  9462. [2022-06-17 08:46:10.082428] share_access : 0x00000003 (3)
  9463. [2022-06-17 08:46:10.084289] private_options : 0x00000000 (0)
  9464. [2022-06-17 08:46:10.085823] time : Fri Jun 17 08:45:09 2022 UTC.310715
  9465. [2022-06-17 08:46:10.087461] share_file_id : 0x0000000000000003 (3)
  9466. [2022-06-17 08:46:10.089107] uid : 0x0000fffd (65533)
  9467. [2022-06-17 08:46:10.090753] flags : 0x0000 (0)
  9468. [2022-06-17 08:46:10.092488] name_hash : 0x7d430cc4 (2101546180)
  9469. [2022-06-17 08:46:10.094078] stale : 0x01 (1)
  9470. [2022-06-17 08:46:10.095728] dbwrap_watched_subrec_wakeup_fn: No watchers
  9471. [2022-06-17 08:46:10.097352] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9472. [2022-06-17 08:46:10.098996] share_mode_data_store:
  9473. [2022-06-17 08:46:10.100614] d: struct share_mode_data
  9474. [2022-06-17 08:46:10.102341] unique_content_epoch : 0x18806ab16114c44d (1765528363999741005)
  9475. [2022-06-17 08:46:10.104053] flags : 0x00c8 (200)
  9476. [2022-06-17 08:46:10.105566] 0: SHARE_MODE_SHARE_DELETE
  9477. [2022-06-17 08:46:10.107189] 1: SHARE_MODE_SHARE_WRITE
  9478. [2022-06-17 08:46:10.108929] 1: SHARE_MODE_SHARE_READ
  9479. [2022-06-17 08:46:10.110450] 0: SHARE_MODE_ACCESS_DELETE
  9480. [2022-06-17 08:46:10.112079] 0: SHARE_MODE_ACCESS_WRITE
  9481. [2022-06-17 08:46:10.113739] 1: SHARE_MODE_ACCESS_READ
  9482. [2022-06-17 08:46:10.115380] 0: SHARE_MODE_LEASE_HANDLE
  9483. [2022-06-17 08:46:10.117012] 0: SHARE_MODE_LEASE_WRITE
  9484. [2022-06-17 08:46:10.118632] 0: SHARE_MODE_LEASE_READ
  9485. [2022-06-17 08:46:10.120420] servicepath : *
  9486. [2022-06-17 08:46:10.121961] servicepath : '/mnt/share'
  9487. [2022-06-17 08:46:10.123674] base_name : *
  9488. [2022-06-17 08:46:10.125428] base_name : 'qwe'
  9489. [2022-06-17 08:46:10.126957] stream_name : NULL
  9490. [2022-06-17 08:46:10.128680] num_delete_tokens : 0x00000000 (0)
  9491. [2022-06-17 08:46:10.130201] delete_tokens: ARRAY(0)
  9492. [2022-06-17 08:46:10.131912] old_write_time : Fri Jun 17 06:10:26 2022 UTC
  9493. [2022-06-17 08:46:10.133485] changed_write_time : NTTIME(0)
  9494. [2022-06-17 08:46:10.135145] fresh : 0x00 (0)
  9495. [2022-06-17 08:46:10.136909] modified : 0x01 (1)
  9496. [2022-06-17 08:46:10.138443] id: struct file_id
  9497. [2022-06-17 08:46:10.139917] devid : 0x0000000000000013 (19)
  9498. [2022-06-17 08:46:10.141410] inode : 0x00000000000000c1 (193)
  9499. [2022-06-17 08:46:10.143246] extid : 0x0000000000000000 (0)
  9500. [2022-06-17 08:46:10.144906] dbwrap_watched_subrec_wakeup_fn: No watchers
  9501. [2022-06-17 08:46:10.146447] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9502. [2022-06-17 08:46:10.147975] dbwrap_watched_subrec_wakeup_fn: No watchers
  9503. [2022-06-17 08:46:10.149473] dbwrap_watched_do_locked: dbwrap_watched_do_locked_fn returned NT_STATUS_OK
  9504. [2022-06-17 08:46:10.151142] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/locking.tdb
  9505. [2022-06-17 08:46:10.152967] delete_lock_ref_count for file qwe
  9506. [2022-06-17 08:46:10.154499] useruser closed file qwe (numopen=0) NT_STATUS_OK
  9507. [2022-06-17 08:46:10.156251] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_open_global.tdb
  9508. [2022-06-17 08:46:10.157786] lock order: 1:/var/lock/smbXsrv_open_global.tdb 2:<none> 3:<none> 4:<none>
  9509. [2022-06-17 08:46:10.159441] db_tdb_log_key: Locking key C61EC380
  9510. [2022-06-17 08:46:10.161074] db_tdb_fetch_locked_internal: Allocated locked data 0xb5ef4cf0
  9511. [2022-06-17 08:46:10.162705] db_tdb_log_key: Unlocking key C61EC380
  9512. [2022-06-17 08:46:10.164485] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_open_global.tdb
  9513. [2022-06-17 08:46:10.166027] freed files structure 974417690 (0 used)
  9514. [2022-06-17 08:46:10.167528] vfs_ChDir to /mnt/share
  9515. [2022-06-17 08:46:10.169001] vfs_ChDir: vfs_ChDir got /mnt/share
  9516. [2022-06-17 08:46:10.170655] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9517. [2022-06-17 08:46:10.172298] Security token: (NULL)
  9518. [2022-06-17 08:46:10.174113] UNIX token of user 0
  9519. [2022-06-17 08:46:10.175623] Primary group is 0 and contains 0 supplementary groups
  9520. [2022-06-17 08:46:10.177119] change_to_root_user: now uid=(0,0) gid=(0,0)
  9521. [2022-06-17 08:46:10.178777] linups (ipv4:192.168.1.10:33730) closed connection to service shr
  9522. [2022-06-17 08:46:10.180521] vfs_ChDir to /
  9523. [2022-06-17 08:46:10.182025] vfs_ChDir: vfs_ChDir got /
  9524. [2022-06-17 08:46:10.183719] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9525. [2022-06-17 08:46:10.185356] Security token: (NULL)
  9526. [2022-06-17 08:46:10.186974] UNIX token of user 0
  9527. [2022-06-17 08:46:10.188610] Primary group is 0 and contains 0 supplementary groups
  9528. [2022-06-17 08:46:10.190337] change_to_root_user: now uid=(0,0) gid=(0,0)
  9529. [2022-06-17 08:46:10.191964] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  9530. [2022-06-17 08:46:10.193551] lock order: 1:/var/lock/smbXsrv_tcon_global.tdb 2:<none> 3:<none> 4:<none>
  9531. [2022-06-17 08:46:10.195232] db_tdb_log_key: Locking key E48C8ACD
  9532. [2022-06-17 08:46:10.196876] db_tdb_fetch_locked_internal: Allocated locked data 0xb5444e90
  9533. [2022-06-17 08:46:10.198523] db_tdb_log_key: Unlocking key E48C8ACD
  9534. [2022-06-17 08:46:10.200013] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_tcon_global.tdb
  9535. [2022-06-17 08:46:10.201515] dbwrap_lock_order_lock: check lock order 1 for /var/lock/smbXsrv_session_global.tdb
  9536. [2022-06-17 08:46:10.203355] lock order: 1:/var/lock/smbXsrv_session_global.tdb 2:<none> 3:<none> 4:<none>
  9537. [2022-06-17 08:46:10.204918] db_tdb_log_key: Locking key 6F1A4B46
  9538. [2022-06-17 08:46:10.206557] db_tdb_fetch_locked_internal: Allocated locked data 0xb5160b30
  9539. [2022-06-17 08:46:10.208221] dbwrap_watched_subrec_wakeup_fn: No watchers
  9540. [2022-06-17 08:46:10.209877] dbwrap_lock_order_unlock: release lock order 1 for /var/lock/smbXsrv_session_global.tdb
  9541. [2022-06-17 08:46:10.211440] db_tdb_log_key: Unlocking key 6F1A4B46
  9542. [2022-06-17 08:46:10.212969] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9543. [2022-06-17 08:46:10.214609] Security token: (NULL)
  9544. [2022-06-17 08:46:10.216307] UNIX token of user 0
  9545. [2022-06-17 08:46:10.217925] Primary group is 0 and contains 0 supplementary groups
  9546. [2022-06-17 08:46:10.219455] change_to_root_user: now uid=(0,0) gid=(0,0)
  9547. [2022-06-17 08:46:10.221114] setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
  9548. [2022-06-17 08:46:10.222757] Security token: (NULL)
  9549. [2022-06-17 08:46:10.224414] UNIX token of user 0
  9550. [2022-06-17 08:46:10.226039] Primary group is 0 and contains 0 supplementary groups
  9551. [2022-06-17 08:46:10.227546] change_to_root_user: now uid=(0,0) gid=(0,0)
  9552. [2022-06-17 08:46:10.229036] Deregistering messaging pointer for type 784 - private_data=0xb5bd9db0
  9553. [2022-06-17 08:46:10.230554] msg_dgm_ref_destructor: refs=0
  9554. [2022-06-17 08:46:10.232320] Server exit (NT_STATUS_END_OF_FILE)
  9555. [2022-06-17 08:46:10.233921] messaging_dgm_send: Sending message to 9561
  9556. [2022-06-17 08:46:10.235557] messaging_recv_cb: Received message 0x314 len 0 (num_fds:0) from 9557
  9557. [2022-06-17 08:46:10.237203] smbd_cleanupd_process_exited: cleaned up pid 9588