This wiki has been migrated to https://gitlab.com/wireshark/wireshark/-/wikis/home and is now deprecated. Please use that site instead.
Differences between revisions 1 and 2
Revision 1 as of 2005-04-01 12:57:03
Size: 1480
Editor: UlfLamping
Comment: first content
Revision 2 as of 2005-12-05 02:58:58
Size: 1729
Comment: Add Open Questions
Deletions are marked like this. Additions are marked like this.
Line 4: Line 4:
XXX - add a brief RPCNetlogon description here RPCNetlogon provides workstations, member servers and trusted domains with access to the centralised, shared authentication database in WinNT networks. This protocol also includes NT4 level syncrosisation of user accounts between a PDC and BDC, as well as many other services.
Line 20: Line 20:
The RPCNetlogon dissector is (fully functional, partially functional, not existing, ... whatever the current state is). Also add info of additional Ethereal features where appropriate, like special statistics of this protocol. The RPCNetlogon dissector is partially functional. There are still a number of unknown commands and feilds.
Line 42: Line 42:
 * add link to RPCNetlogon specification and where to find additional info on the web about RPCNetlogon  * [http://samba.org/ftp/unpacked/samba4/source/librpc/idl/netlogon.idl Samba4 IDL] for RPCNetlogon
Line 45: Line 45:

== Open Questions ==
We still don't entirely understand this protocol, and we have some of these on the RPCNetlogon/OpenQuestions page.

Microsoft Network Logon (RPCNetlogon)

RPCNetlogon provides workstations, member servers and trusted domains with access to the centralised, shared authentication database in WinNT networks. This protocol also includes NT4 level syncrosisation of user accounts between a PDC and BDC, as well as many other services.

History

XXX - add a brief description of RPCNetlogon history

Protocol dependencies

  • ["DCE/RPC"]: RPCNetlogon uses ["DCE/RPC"] as its transport protocol.

Example traffic

XXX - Add example traffic here (as plain text or Ethereal screenshot).

Ethereal

The RPCNetlogon dissector is partially functional. There are still a number of unknown commands and feilds.

Preference Settings

(XXX add links to preference settings affecting how RPCNetlogon is dissected).

Example capture file

XXX - Add a simple example capture file to the SampleCaptures page and link from here. Keep it short, it's also a good idea to gzip it to make it even smaller, as Ethereal can open gzipped files automatically.

Display Filter

A complete list of RPCNetlogon display filter fields can be found in the [http://www.ethereal.com/docs/dfref/r/rpc_netlogon.html display filter reference]

  • Show only the RPCNetlogon based traffic:

     rpc_netlogon 

Capture Filter

You cannot directly filter RPCNetlogon protocols while capturing.

Discussion

Open Questions

We still don't entirely understand this protocol, and we have some of these on the RPCNetlogon/OpenQuestions page.

RPCNetlogon (last edited 2012-12-17 20:39:34 by SadeqDousti)