biggiesmallsAG / nightHawkResponse

Incident Response Forensic Framework
599 stars 139 forks source link

103 Browser Issues Mac OSx and Windows #17

Open xeen3d opened 7 years ago

xeen3d commented 7 years ago

Hi iam so sorry but 103 have not same Issues than 102 but have some like i can upload now and looks that is works but after one hour running nothing happens i see the case but get no result my Browsers in OSx are both at over 100 % CPU the vmware self not looks that the Browser Tabs hangs.

In Night Hawk i see openserach state is yellow but no real other work

screenshot 2016-09-11 so 15 25 01 screenshot 2016-09-11 so 15 29 27

Since now i get no results every Browser i test hang after i click one of the results

best

Andre

xeen3d commented 7 years ago

Here a other Picture after closing the Browser hole CPU goes down and my System is normal

screenshot 2016-09-11 so 15 34 53
xeen3d commented 7 years ago

The only Browser i get something was Firefox but i get only a load loop and a broken View like in this Picture best Andre

screenshot 2016-09-11 so 15 38 01
xeen3d commented 7 years ago

Hi, i check the Browser Issue in Windows now with same Problem than with OSx Browsers. A simple Question from me did someone have tested V103 with a Browser ?

Here a Sample from Windows IE Browser looks same than all Other Browsers on OSx and for that test i use the Redline Script from repository here. For now 103 is not usable for me i can´t get any Browser working with it.

best Andre

screenshot 2016-09-11 so 22 55 34
biggiesmallsAG commented 7 years ago

Hi Andre,

This is quite strange, i tested on OSX (Chrome/Firefox) and WIndows (Chrome/Firefox) extensively before this release, no issues at all.

That loop happens when the browser tries to load angular.js libs twice, it will go into an uncontrollable loop.

So this happens when you click on a case OR audit?

Regards,

Dan

xeen3d commented 7 years ago

Hi Dan i can open the Case and i can use Timeline and Search also System Information and User Group is work like design. But if i click on the case and see Treemenu if i click one of that Menu entrees Browser hang, it was not important what one it seems problem is in tee Menu. I try yesterday a Windows 10 IE with same result than all OSx Browsers if browser hang some time later nighthawk process in VM is a Zombie (after a hour ) . I use now for all tests the demo File from repository and the redline script from repository to be absolutely sure that the error not is in my zip files i upload to the server.

Looks like all Works i have only Problems with the tree menu I try a new installation i can see errors in VM when it start i told you if i get different results ok best

Andre

xeen3d commented 7 years ago

Hi Dan i make a clean new VM with exactly right Settings for Centos7 Minimal, give the VM 4 Cores and 80 GB Disk with 4096 Mb Memory. After start i make nothing i use the nighthawk user and upload the sample file from repro in VM Console i see same Error than in my First 103 installation (see Picture) but now i can use the tree menu and get results.

I try now make my own Zip File with Redline Script from Repro maybe that works too (i hope s)

Here the Picture with the error i see in both Installations

screenshot 2016-09-12 mo 23 14 46

best

Andre

xeen3d commented 7 years ago

Hi Dan i wait for analyse of my own zip and take a look at system state the nighthawk process is shown as zombi process is that ok ?

screenshot 2016-09-12 mo 23 21 36

after my zip was analysed i get two zombi nighthawk and i get no result in tree menu same Problem than before it looks first analyse was ok (from the sample in Repro) but a own one brings nighthawk down but i use for the own one the redline script from repro not a own one i try now make all in Windows to see if the problem was again my zip file from OSx

screenshot 2016-09-12 mo 23 30 57

Browser hangs and hole webkit crashes

Sep 12 23:26:02 Andres-MBP com.apple.xpc.launchd1: Service exited with abnormal code: 1 Sep 12 23:26:25 Andres-MBP com.apple.xpc.launchd1: Service exited with abnormal code: 1 Sep 12 23:27:24 Andres-MBP com.apple.xpc.launchd1: Service exited with abnormal code: 1 Sep 12 23:28:29 Andres-MBP com.apple.xpc.launchd1: Service exited due to signal: Killed: 9 sent

Is no Difference a zip from windows bring a third nighthawk zombi process, i do now first a clean restart and try leave all on windows vm hole redline folder and make the zip from repro redline script of my test vm but i feel i will get same results. i tell it here when i have the result.

best

Andre

xeen3d commented 7 years ago

Hi Dan, i do all Checks against a pure Windows VM i create and store and run the Redline Script from within that Windows VM after ready i create also in Windows a Zip File for Upload to Nighthawk.

But and believe me i am very sorry about that with same Result, NH analyse the Zip shows me the Case and the VM name i can search and create a Timeline but if i try click one of the Treemenu Entrees my Browser still hang than.

After go back with a clean page reload and go to System Information i see a nighthawk Zombi process, if i try same procedure a few times i get more Nighthawk Zombis for every try a new one.

State of Elastic Search every time is yellow i think after analysing it must be green or not ?

Let me know if i can do some tests for you or give you other Informations

best

Andre

biggiesmallsAG commented 7 years ago

Hi Andre,

This is very strange, i cannot reproduce on my machine. What is your VM architecture ? Are you on VMWare/Vbox/Parallels?

Dont worry about the zombie processes, this is fine. Its natural for the platform stats to see zombie processes after you upload data to the system and its finished ingesting.

Is there anyway you can test running this on well known VM architecture? As stated, both myself and Roshan have tested this on all major vendors with no drama.

Regards,

Dan

xeen3d commented 7 years ago

Hi Dan

i use VMware Fusion 8.5 Professional on a Mac Book Pro with actually Sierra OS last week i use El Captain OSx In My Eyes VMware Fusion is a well known Hypervisor ;-)

I am absolut sure that you can use my VM and use it without any modification in ESX oe VM Workstation i do same very often at work when i import Images from our ESX Farm.

I give NH good Resources and don´t touch it otherwise, only install give 6 GB Ram give 4 Cores and a 100 GB Hard disk (virtual Disk) I can Upload that VM to my Dropbox Folder (A payed one) so you can use it for a test if you can run all you want the Problem is that i run all on a Mac

If you can send me a Mail i send you the Dropbox Link and shrink before the Disk andre(at)xeen3d.de

best Andre

biggiesmallsAG commented 7 years ago

20

This is the issue, fix on the way.