Article ID: 139608
Article Last Modified on 11/1/2006
Node IpAddress: [xxx.57.9.54] Scope Id: []
NetBIOS Local Name Table
Name Type Status
---------------------------------------------
NTWINSCLIENT <00> UNIQUE Registered
NTWINSDOM <00> GROUP Registered
NTWINSCLIENT <03> UNIQUE Registered
NTWINSCLIENT <20> UNIQUE Registered
NTWINSDOM <1E> GROUP Registered
NEWUSER <03> UNIQUE Registered
NBT: NS: Registration req. for NTWINSCLIENT <00>
NBT: NS: Registration (Node Status) resp. for NTWINSCLIENT <00>, Success, Owner Addr. xxx.57.9.54
NBT: NS: Registration req. for NTWINSDOM <00>
NBT: NS: Registration (Node Status) resp. for NTWINSDOM <00>, Success, Owner Addr. xxx.57.9.54
NBT: NS: Query req. for NTWINSDOM <1C>
NBT: NS: Query (Node Status) resp. for NTWINSDOM <1C>, Success
NBT: DS: Type = 17 (DIRECT GROUP) SMB: C transact, File = \MAILSLOT\NET\NTLOGON NETLOGON: SAM LOGON request from client
ARP_RARP: ARP: Request, Target IP: xxx.57.11.179
ARP_RARP: ARP: Reply, Target IP: xxx.57.9.54 Target Hdwr Addr: 00AA0051E2B3
NBT: DS: Type = 17 (DIRECT GROUP) SMB: C transact, File = \MAILSLOT\NET\NTLOGON NETLOGON: SAM LOGON request from client
NBT: DS: Type = 17 (DIRECT GROUP) SMB: C transact, File = \MAILSLOT\NET\NTLOGON NETLOGON: SAM LOGON request from client
NBT: DS: Type = 16 (DIRECT UNIQUE) SMB: C transact, File = \MAILSLOT\NET\GETDC209 NETLOGON: SAM Response to SAM LOGON request
NBT: NS: Query req. for NTWINSPDC
NBT: NS: Query (Node Status) resp. for NTWINSPDC, Success
NBT: SS: Session Request, Dest: NTWINSPDC , Source: NTWINSCLIENT<00>, Len: 68
NBT: SS: Positive Session Response, Len: 0
SMB: C negotiate, Dialect = NT LM 0.12
SMB: R negotiate, Dialect # = 7
SMB: C session setup & X, Username = , and C tree connect & X, Share =\\NTWINSPDC\IPC$
SMB: R session setup & X, and R tree connect & X, Type = IPC
SMB: C NT create & X, File = \lsarpc
SMB: R NT create & X, FID = 0x800
At this point Microsoft RPC traffic over SMBs occurs between the
Windows NT DC and the Windows NT Workstation. This traffic is not
shown because it does not pertain to the subject matter.
SMB: C close file, FID = 0x800
SMB: R close file
SMB: C NT create & X, File = \NETLOGON
SMB: R NT create & X, FID = 0x801
At this point Microsoft RPC traffic over SMBs occurs between the
Windows NT DC and the Windows NT Workstation. This traffic is not
shown because it does not pertain to the subject matter.
NBT: NS: Registration req. for NTWINSCLIENT <03>
NBT: NS: Registration (Node Status) resp. for NTWINSCLIENT <03>, Success, Owner Addr. xxx.57.9.54
NBT: NS: Registration req. for NTWINSCLIENT
NBT: NS: Registration (Node Status) resp. for NTWINSCLIENT,Success, Owner Addr. xxx.57.9.54
NBT: DS: Type = 17 (DIRECT GROUP) SMB: C transact, File = \MAILSLOT\BROWSE BROWSER: Host Announcement [0x01] NTWINSCLIENT
NBT: NS: Registration req. for NTWINSDOM <1E>
NBT: NS: Registration (Node Status) resp. for NTWINSDOM <1E>, Success, Owner Addr. xxx.57.9.54
NBT: DS: Type = 17 (DIRECT GROUP) SMB: C transact, File = \MAILSLOT\BROWSE BROWSER: Announcement Request [0x02]
NBT: DS: Type = 17 (DIRECT GROUP) SMB: C transact, File = \MAILSLOT\BROWSE BROWSER: Host Announcement [0x01] NTWINSCLIENT
NBT: SS: Session Request, Dest: NTWINSPDC , Source: NTWINSCLIENT<00>, Len: 68
NBT: SS: Positive Session Response, Len: 0
SMB: C negotiate, Dialect = NT LM 0.12
SMB: R negotiate, Dialect # = 7
SMB: C session setup & X, Username = , and C tree connect & X, Share =\\NTWINSPDC\IPC$
SMB: R session setup & X, and R tree connect & X, Type = IPC
SMB: C NT create & X, File = \lsarpc
SMB: R NT create & X, FID = 0x804
At this point Microsoft RPC traffic over SMBs occurs between the
Windows NT DC and the Windows NT Workstation. This traffic is not
shown because it does not pertain to the subject matter.
SMB: C close file, FID = 0x804
SMB: R close file
SMB: C NT create & X, File = \lsarpc
SMB: R NT create & X, FID = 0x805
At this point Microsoft RPC traffic over SMBs occurs between the
Windows NT DC and the Windows NT Workstation. This traffic is not
shown because it does not pertain to the subject matter.
SMB: C close file, FID = 0x805
SMB: R close file
SMB: C NT create & X, File = \NETLOGON
SMB: R NT create & X, FID = 0x806
At this point Microsoft RPC traffic over SMBs occurs between the
Windows NT DC and the Windows NT Workstation. This traffic is not
shown because it does not pertain to the subject matter.
NBT: NS: Registration req. for NEWUSER <03>
NBT: NS: WACK (Node Status) resp. for NEWUSER <03>,Success
NBT: NS: Registration (Node Status) resp. for NEWUSER <03>, Success, Owner Addr. xxx.57.9.54
Additional query words: prodnt login bootup sniffer trace
Keywords: kbhowto kbnetwork KB139608