in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Retina - REMOTE REGISTRY OPEN ACCESS DENIED

Last post 03-18-2009 9:06 AM by Blue1978. 4 replies.
Page 1 of 1 (5 items)
Sort Posts: Previous Next
  • 02-12-2009 11:40 AM

    Retina - REMOTE REGISTRY OPEN ACCESS DENIED

     Nothing has changed in my domain yet all of the sudden Retina is not getting remote access into the registry of some 20+ computers.

    I can access every registry remotely threw regedt32, so thats not the issue. I have installed the newest version today and still no change.

    I have played with the permissions as work around and was able to get a good scan adding EVERYONE with read priveleges, but this is not a good work around as it is causse for vurnalbilites. It should as was working with LOCAL SERVICES with read writes, so again this can't be the issue.

    Another flaky issue; when we go to single scan SOMETIMES, but rare, I can get a good scan. Why is this?

    Is anyone else having similar problems with Retina?

  • 02-12-2009 6:14 PM In reply to

    Re: Retina - REMOTE REGISTRY OPEN ACCESS DENIED

    First check your credentials.  Next verify your firewall settings.  If that doesn't work out, please submit a support request through the client support portal.

  • 02-18-2009 4:08 AM In reply to

    Re: Retina - REMOTE REGISTRY OPEN ACCESS DENIED

    Something has changed. When Retina suddenly starts having registry access issues it's usually a policy or firewall issue.  First thing to do is follow the advice nomuus gave. If you still don't have registry access then do this:

    1) Narrow your scan to one target and one audit that is problematic.

    2) Examine the Retina log file (xxxx_RetinaScanner.log in the Logs directory) and look for lines that have "WNetAddConnection" and  "CreateRegSession". Examine the lines that follow these entries and check if the calls returned an error. If you see error 1326 you have invalid credentials. If you see lots of "err=5", it's a permission thing.

    Your message is not specific so I can only give you a vague response. More details are needed.

    A) What version of Retina?

    B) What do the 20+ computers in question have in common? i.e. On the same subnet? Different domain? Different group policies? etc...

     

  • 03-18-2009 8:03 AM In reply to

    Re: Retina - REMOTE REGISTRY OPEN ACCESS DENIED

    If you're a valid Retina customer you have access to support via the Business Portal

    I think the address is www.eeye.com/clients

    -------------------------------------
    melon cat is not pleased.
    -------------------------------------
  • 03-18-2009 9:06 AM In reply to

    Re: Retina - REMOTE REGISTRY OPEN ACCESS DENIED

     *Passes out laughing at Gamachan's avatar picture*

Page 1 of 1 (5 items)
© 1995 - 2009 eEye Incorporated