doomedraven / Tools

Combination of different utilities, have fun!
MIT License
202 stars 96 forks source link

Cuckoo Sandbox Help Request #126

Closed jefazo92 closed 2 years ago

jefazo92 commented 2 years ago

Hi @doomedraven,

I am a university student and I'm using Cuckoo Sandbox (Ubuntu 20.04 LTS host and WIndows 7 Guest VM) as part of my university project. I'd like to ask you for help because the project is being a nightmare. There is no more support for Cuckoo anymore (the GitHub Repo is closed and the Slack group chat is completely dead) and there are no online communities which support Cuckoo nor anyone who knows about it. I already failed my first project attempt and I'm desperate because my university staff doesn't know how to use Cuckoo either (even though they proposed that project). I'm contacting you because I saw you used to be very active in the Cuckoo Repo and helped out someone who, like me, was trying to enable VPN routing but was getting the same error message all the time as soon as he started Cuckoo (please see image attached below). I've followed the instructions in the documentation but I'm being unable to make the VPN routing work. I've also been trying to find the logs for Rooter ([cuckoo.apps.rooter]) but I've only managed to find the Cuckoo debug log (inside ~/.cuckoo/log). Please doomedraven I have nobody else whom to ask. If you want to help me you can reply to me there, to my email (millotcharles92@gmail.com) or discord (DeGent), which I'd prefer more if you don't mind. I look forward to your reply.

image

doomedraven commented 2 years ago

Cuckoo is dead and obsolet, there is no support for cuckoo, neither from me.

jefazo92 commented 2 years ago

@doomedraven I know the project is dead and obsolete but, being ignorant, I selected malware analysis with Cuckoo and couldn't have ever imagined there would be no support at all. I have nobody else to ask, nobody (not even my university lecturers). I know you don't know me but please I'm asking you this as a personal favour because I'm really desperate and don't know how to move on. If I had previously known Cuckoo was dead, I would have never chosen it but now it's too late for me. I hope you can put yourself in my shoes.

doomedraven commented 2 years ago

is dead, python2 is dead, is 4y that i don't use it or even more. so don't waste your time. https://github.com/kevoreilly/CAPEv2/. Read docs, read readme and then you fine to go with alive sandbox

but give regards from me and JRP to M***a L***a

jefazo92 commented 2 years ago

is dead, python2 is dead, is 4y that i don't use it or even more. so don't waste your time. https://github.com/kevoreilly/CAPEv2/. Read docs, read readme and then you fine to go with alive sandbox

but give regards from me and JRP to Ma La

Thank you for letting me know other sandbox @doomedraven but I can't change from Cuckoo now :( Who are JRP and Ma La? I've tried to find their names in Cuckoo Rep's contributors but those names don't appear anywhere. Could the help me out?

doomedraven commented 2 years ago

they are not there. that is cipher text ;) sorry i can't help. that is pure wasting of time

https://cuckoo.readthedocs.io/en/latest/installation/host/routing/#routing-iproute2

jefazo92 commented 2 years ago

@doomedraven

they are not there. that is cipher text ;) sorry i can't help. that is pure wasting of time

https://cuckoo.readthedocs.io/en/latest/installation/host/routing/#routing-iproute2

And how much support does CAPEv2 offer @doomedraven ? It's too late for me to change sandbox but is the documentation up-to-date? And very importantly, do they have active online communities in which students like me can get help for troubleshooting? Are there also any other active sandboxes apart from CAPEv2 that you know of? At least I can let know my lecturers so that future students don't have to go though the nightmare I've been going through.

doomedraven commented 2 years ago

is uniq active open source sandbox. as is open source that means that support is on volunteers. We have pretty updated docs and automated install, but the biggest problems of the people that comes the they don't know wtf they doing as they don't understand the rest of the technology that it uses. If you don't know what it does and how it does, that makes people asking stupid linux question totally not related to project. We have slack but is only for active members. I don't want to have that crap slack as in cuckoo that people ask noob questions having answers in docs for most of the questions from general

jefazo92 commented 2 years ago

is uniq active open source sandbox. as is open source that means that support is on volunteers. We have pretty updated docs and automated install, but the biggest problems of the people that comes the they don't know wtf they doing as they don't understand the rest of the technology that it uses. If you don't know what it does and how it does, that makes people asking stupid linux question totally not related to project. We have slack but is only for active members. I don't want to have that crap slack as in cuckoo that people ask noob questions having answers in docs for most of the questions from general

And what would it take for me to become an active member @doomedraven ? Just creating an account in the CAPEv2 website? And you may not be so tolerant of noob questions but what about the other volunteers? I need to know this before even suggesting the sandbox to my university. I need to make sure I suggest an active sandbox which has an active online community anyone can access and is student/noob friendly so that nobody has to go through what I've been going through ever again. I hope you can understand that.

jefazo92 commented 2 years ago

Also why doesn't CAPEv2 repo have any malware tags? A few months ago, when I tried to look for other Sandbox alternatives in Github (and in Google) CAPE never showed up. Not even once. A few minutes ago, I also tried searching on GitHub, "Malware Sandbox" and CAPEv2 is not listed at all in the results. That should change so that people can become more aware of its existence since, in my case, I didn't know until you mentioned it today.

doomedraven commented 2 years ago

become an active member means become skilled, you wasn't even able to find the answer about your question in cuckoo docs(see my link in one of the answers). The problem of newcomers they don't want to do their home job and learn the tools, they want everything working out of the box and in modern world that is almost imposible. Others ignoring noob questions and normally i just close them due to ignoring documentation or not even google that if that is not project related.

You can see changelog and commits in repo to see how active we are. anyway i have to do my personal stuff so have fun.