in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Retina can not read registry.

Last post 02-05-2010 12:31 PM by jaws. 4 replies.
Page 1 of 1 (5 items)
Sort Posts: Previous Next
  • 02-03-2010 4:39 PM

    • jaws
    • Top 50 Contributor
    • Joined on 09-01-2009
    • Posts 13

    Retina can not read registry.

     Hi,

    Windows 2003 running retina (latest version download recently).  The issue is no registry access.

    I found a good article here about all the registry settings to check and have done so but no success yet.

    I checked and can access the registry via the connect network registry.

    I have two machines that do not work and many others do work.

    The user is in the administrators group.

     The strange thing is the renamed administrator account does work but another

    user with administrator privlages does not work.

    Help please!  I have spent over 12 hours looking at the registry settings with no luck so far.

    I have less hair today....  Would even pay for a support call !! 

     

    Thanks,

    Jim

  • 02-04-2010 1:03 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: Retina can not read registry.

    Hi Jim,

    Looking at the RetinaScanner log would be helpful to see whats going on. You can search for CreateRegSession to see if your credentials are working or what the error code is... like 1326 (Bad username/password).  You can lookup the error codes for CreateRegSession just by using cmd.  Use the command "net helpmsg <error number>".

    Let me know what you find.

    Thanks,
    Brian

     

  • 02-05-2010 5:03 AM In reply to

    • jaws
    • Top 50 Contributor
    • Joined on 09-01-2009
    • Posts 13

    Re: Retina can not read registry.

    Hi Brian,

    Thanks for your response.  Here is what I found from the RetinaScanner log

    CreateRegSession(IP): Entered user='useradmin'

    CreateRegSession(IP): RetWNetAddConnection2: user='useradmin' err=[1219:0] - Multiple connections to a server or shared resource by the same user, using more than one user name, are not allowed.  Disconnect all previous connections to the server or shared resource and try again.

    CreateRegSession(IP): Finished: user='useradmin' err=[1219:0] - Multiple connections to a server or shared resource by the same user, using more than one user name, are not allowed.  Disconnect all previous connections to the server or shared resource and try again.

    RETCREDS(IP): CreateRegSession failed: user='useradmin' : 1219 : 0

    --- End of section of log.

    The machine being scanned was just rebooted so nothing was accessing except Retina scan.

    Look forward to your response.

    Thanks,

    Jim

  • 02-05-2010 11:12 AM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: Retina can not read registry.

    It sounds like the scanner machine may have already had a connection to it. You can use "net use" via cmd to see what connections are open. You can use the "net use * /delete" to remove all connections.  I would try doing that and re-run a test scan to see if you get better results.

    Hope that helps.

     

  • 02-05-2010 12:31 PM In reply to

    • jaws
    • Top 50 Contributor
    • Joined on 09-01-2009
    • Posts 13

    Re: Retina can not read registry.

     Hi,

      I tried the net use * /delete but it did not fix the issue.

      It seems that retina is establishing two connections - I did not open any connections.

      Is Retina using two connections - one to registry, one to c$ share?

      I log into the computer running retina as user A and run the scan on the target machine as user B.  Both have admin accounts on the target machine.  Maybe Retina is causing the conflict using user A for the c$ share and user B for the registry connection.

      Please advise.

    Thanks,

    Jim

Page 1 of 1 (5 items)
© 1995 - 2009 eEye Incorporated