DevOps Cloud (ADM)
Cybersecurity
IT Operations Cloud
09:35:54 894 LDAP: New cleartext connection 0xda2340 from 10.1.2.1:34769, monitor = 0x0, index = 1
09:35:54 994 LDAP: (10.1.2.1:34769)(0x0001:0x60) DoBind on connection 0xda2340
09:35:54 994 LDAP: (10.1.2.1:34769)(0x0001:0x60) Bind name:cn=admin,ou=system,o=dundee, version:3, authentication:simple
09:35:55 970 LDAP: (10.1.2.1:34769)(0x0002:0x63) DoSearch on connection 0xda2340
09:35:55 970 LDAP: (10.1.2.1:34769)(0x0002:0x63) Search request:
base: "ou=test2,ou=test,o=dundee"
scope:2 dereference:3 sizelimit:0 timelimit:0 attrsonly:0
filter: "(objectclass=inetOrgPerson)"
attribute: "uid"
attribute: "givenname"
attribute: "initials"
attribute: "sn"
attribute: "manager"
attribute: "departmentnumber"
attribute: "telephonenumber"
attribute: "mail"
attribute: "title"
attribute: "homephone"
attribute: "mobile"
attribute: "pager"
09:35:55 970 LDAP: (10.1.2.1:34769)(0x0002:0x63) Sending search result entry "cn=ALSwiffin,ou=test,o=dundee" to connection 0xda2340
...
09:35:55 970 LDAP: (10.1.2.1:34769)(0x0002:0x63) Sending operation result 0:"":"" to connection 0xda2340
09:36:00 8A4 LDAP: (10.1.2.1:34769)(0x0004:0x63) DoSearch on connection 0xda2340
09:36:00 8A4 LDAP: (10.1.2.1:34769)(0x0004:0x63) Search request:
base: "ou=test,o=dundee"
scope:2 dereference:3 sizelimit:0 timelimit:0 attrsonly:0
filter: "(objectclass=inetOrgPerson)"
attribute: "uid"
attribute: "givenname"
attribute: "initials"
attribute: "sn"
attribute: "manager"
attribute: "departmentnumber"
attribute: "telephonenumber"
attribute: "mail"
attribute: "title"
attribute: "homephone"
attribute: "mobile"
attribute: "pager"
attribute: "objectClass"
attribute: "javaSerializedData"
attribute: "javaClassName"
attribute: "javaFactory"
attribute: "javaCodeBase"
attribute: "javaReferenceAddress"
attribute: "javaClassNames"
attribute: "javaRemoteLocation"
09:36:00 8A4 LDAP: (10.1.2.1:34769)(0x0004:0x63) Persistent Search doesn't work when dereferencing aliases under the base
09:36:00 8A4 LDAP: (10.1.2.1:34769)(0x0004:0x63) Sending operation result 80:"":"" to connection 0xda2340
Frame 70 (262 bytes on wire, 262 bytes captured)
Ethernet II, Src: CompaqHp_cb:7d:6a (00:0b:cd:cb:7d:6a), Dst: Vmware_c3:be:17 (00:0c:29:c3:be:17)
Internet Protocol, Src: 10.1.2.1 (10.1.2.1), Dst: 10.1.2.5 (10.1.2.5)
Transmission Control Protocol, Src Port: 54810 (54810), Dst Port: ldap (389), Seq: 47, Ack: 15, Len: 196
Lightweight-Directory-Access-Protocol
LDAPMessage searchRequest(2) "ou=test2,ou=test,o=dundee" wholeSubtree
messageID: 2
protocolOp: searchRequest (3)
searchRequest
baseObject: ou=test2,ou=test,o=dundee
scope: wholeSubtree (2)
derefAliases: derefAlways (3)
sizeLimit: 0
timeLimit: 0
typesOnly: False
Filter: (objectclass=inetOrgPerson)
filter: equalityMatch (3)
equalityMatch
attributes: 12 items
Item: uid
Item: givenname
Item: initials
Item: sn
Item: manager
Item: departmentnumber
Item: telephonenumber
Item: mail
Item: title
Item: homephone
Item: mobile
Item: pager
[Response In: 71]
Frame 76 (443 bytes on wire, 443 bytes captured)
Ethernet II, Src: CompaqHp_cb:7d:6a (00:0b:cd:cb:7d:6a), Dst: Vmware_c3:be:17 (00:0c:29:c3:be:17)
Internet Protocol, Src: 10.1.2.1 (10.1.2.1), Dst: 10.1.2.5 (10.1.2.5)
Transmission Control Protocol, Src Port: 54810 (54810), Dst Port: ldap (389), Seq: 298, Ack: 1344, Len: 377
Lightweight-Directory-Access-Protocol
LDAPMessage searchRequest(4) "ou=test2,ou=test,o=dundee" wholeSubtree
messageID: 4
protocolOp: searchRequest (3)
searchRequest
baseObject: ou=test2,ou=test,o=dundee
scope: wholeSubtree (2)
derefAliases: derefAlways (3)
sizeLimit: 0
timeLimit: 0
typesOnly: False
Filter: (objectclass=inetOrgPerson)
filter: equalityMatch (3)
equalityMatch
attributes: 20 items
Item: uid
Item: givenname
Item: initials
Item: sn
Item: manager
Item: departmentnumber
Item: telephonenumber
Item: mail
Item: title
Item: homephone
Item: mobile
Item: pager
Item: objectClass
Item: javaSerializedData
Item: javaClassName
Item: javaFactory
Item: javaCodeBase
Item: javaReferenceAddress
Item: javaClassNames
Item: javaRemoteLocation
[Response In: 77]
controls: 1 item
Item joint-iso-ccitt.16.840.1.113730.3.4.3
controlType: 2.16.840.1.113730.3.4.3 (joint-iso-ccitt.16.840.1.113730.3.4.3)
criticality: True
controlValue: 300902010F0101FF0101FF
Frame 77 (80 bytes on wire, 80 bytes captured)
Ethernet II, Src: Vmware_c3:be:17 (00:0c:29:c3:be:17), Dst: CompaqHp_cb:7d:6a (00:0b:cd:cb:7d:6a)
Internet Protocol, Src: 10.1.2.5 (10.1.2.5), Dst: 10.1.2.1 (10.1.2.1)
Transmission Control Protocol, Src Port: ldap (389), Dst Port: 54810 (54810), Seq: 1344, Ack: 675, Len: 14
Lightweight-Directory-Access-Protocol
LDAPMessage searchResDone(4) other () [0 results]
messageID: 4
protocolOp: searchResDone (5)
searchResDone
resultCode: other (80)
matchedDN:
errorMessage:
[Response To: 76]
[Time: 0.000477000 seconds]
Frame 79 (73 bytes on wire, 73 bytes captured)
Ethernet II, Src: CompaqHp_cb:7d:6a (00:0b:cd:cb:7d:6a), Dst: Vmware_c3:be:17 (00:0c:29:c3:be:17)
Internet Protocol, Src: 10.1.2.1 (10.1.2.1), Dst: 10.1.2.5 (10.1.2.5)
Transmission Control Protocol, Src Port: 54810 (54810), Dst Port: ldap (389), Seq: 675, Ack: 1358, Len: 7
Lightweight-Directory-Access-Protocol
LDAPMessage unbindRequest(5)
messageID: 5
protocolOp: unbindRequest (2)
unbindRequest
Lightweight-Directory-Access-Protocol
LDAPMessage searchRequest(4) "ou=test2,ou=test,o=dundee" wholeSubtree
messageID: 4
protocolOp: searchRequest (3)
searchRequest
baseObject: ou=test2,ou=test,o=dundee
scope: wholeSubtree (2)
derefAliases: derefAlways (3)
Frame 1068 (355 bytes on wire, 355 bytes captured)
Ethernet II, Src: Vmware_c8:aa:da (00:0c:29:c8:aa:da), Dst: CompaqHp_cb:7d:6a (00:0b:cd:cb:7d:6a)
Internet Protocol, Src: 10.1.2.6 (10.1.2.6), Dst: 10.1.2.1 (10.1.2.1)
Transmission Control Protocol, Src Port: ldap (389), Dst Port: 57086 (57086), Seq: 2217, Ack: 634, Len: 289
Lightweight-Directory-Access-Protocol
LDAPMessage searchResEntry(4) "cn=WThePooh, ou=People,dc=dundee" [8 results]
messageID: 4
protocolOp: searchResEntry (4)
searchResEntry
objectName: cn=WThePooh, ou=People,dc=dundee
attributes: 6 items
Item uid
type: uid
vals: 1 item
WThePooh
Item givenname
type: givenname
vals: 1 item
Winnie
Item sn
type: sn
vals: 1 item
ThePooh
Item departmentnumber
type: departmentnumber
vals: 1 item
Institute for Honey Studies
Item telephonenumber
type: telephonenumber
vals: 1 item
123123
Item objectClass
type: objectClass
vals: 4 items
top
person
inetOrgPerson
organizationalPerson
[Response To: 292]
[Time: 564.484574000 seconds]
controls: 1 item
Item joint-iso-ccitt.16.840.1.113730.3.4.7
controlType: 2.16.840.1.113730.3.4.7 (joint-iso-ccitt.16.840.1.113730.3.4.7)
controlValue: 30030A0104
Frame 53 (1282 bytes on wire, 1282 bytes captured)
...
LDAPMessage searchResEntry(2) "" [1 result]
messageID: 2
protocolOp: searchResEntry (4)
searchResEntry
objectName:
attributes: 37 items
Item subschemaSubentry
Item supportedGroupingTypes
Item namingContexts
Item supportedExtension
Item supportedControl
type: supportedControl
vals: 6 items
OID: 2.16.840.1.113719.1.27.101.6 (joint-iso-ccitt.16.840.1.113719.1.27.101.6)
OID: 2.16.840.1.113719.1.27.101.5 (joint-iso-ccitt.16.840.1.113719.1.27.101.5)
OID: 2.16.840.1.113730.3.4.3 (joint-iso-ccitt.16.840.1.113730.3.4.3)
OID: 2.16.840.1.113730.3.4.7 (joint-iso-ccitt.16.840.1.113730.3.4.7)
OID: 2.16.840.1.113730.3.4.2 (joint-iso-ccitt.16.840.1.113730.3.4.2)
OID: 2.16.840.1.113719.1.27.103.7 (joint-iso-ccitt.16.840.1.113719.1.27.103.7)
Item supportedSASLMechanisms
Item supportedLDAPVersion
Etc etc
Item supportedControl
type: supportedControl
vals: 4 items
OID: 2.16.840.1.113719.1.27.101.6 (joint-iso-ccitt.16.840.1.113719.1.27.101.6)
OID: 2.16.840.1.113719.1.27.101.5 (joint-iso-ccitt.16.840.1.113719.1.27.101.5)
OID: 2.16.840.1.113730.3.4.2 (joint-iso-ccitt.16.840.1.113730.3.4.2)
OID: 2.16.840.1.113719.1.27.103.7 (joint-iso-ccitt.16.840.1.113719.1.27.103.7)