This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello,

I did a packet capture of a computer that boots and logs in on a corporate network. The client is Windows 7 and I think that the servers are Windows 2008. There are a few lines that I do not understand. See the screenshot:

http://postimg.org/image/zfqzmva0r/

Packet 978 is an Ioctl Request for a file on a server. Why does the server name have only one backslash? Should it not say \ \ before the servername instead of \?

Packet 979 gives Error: STATUS NOT FOUND. What does that mean? It looks to me as if it's working as supposed to anyway, looking at the packets right after the error.

Does anyone have an explanation?

asked 08 Mar '15, 15:44

Farid's gravatar image

Farid
6112
accept rate: 0%

Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×27
×1

question asked: 08 Mar '15, 15:44

question was seen: 2,410 times

last updated: 08 Mar '15, 15:44

p​o​w​e​r​e​d by O​S​Q​A