Open frakman1 opened 2 years ago
pymongo.errors.AutoReconnect: localhost:27018: [Errno 104] Connection reset by peer
That error suggests that your database stopped at some point. You will probably need to restart your container (you could also try to exec into the container and only start the DB but I'm not sure if that will work). The worker processes should generally restart in case of errors. In rare cases this could fail, though (here too restarting FACT helps).
ERROR: Could not connect to clamd on LocalSocket /var/run/clamav/clamd.ctl: No such file or directory
There seem to be some problems with FACT docker in combination with the OMS plugin / ClamAV. Did it work for you at some point?
[2021-10-30 16:16:20][docker][WARNING]: [source_code_analysis]: encountered process error while processing
This could mean that call to the "linguist" docker container did not work. Did it produce any results at all? Could be another mounting path problem.
I have not used ClamAV or linguist before and not sure which category they fall in. They may never have worked and I didn't notice.
I am guessing ClamAV relates to the "malware scanner" tab and linguist is for the "source code analysis" tab?
ClamAV is an open source Linux anti-malware scanner and should be used to scan the file when you run the "malware scanner" plugin
linguist is a tool that is used internally for the "source code analysis" plugin for determining the (programming) language
What I meant was: were there any results for the respective plugins?
Since I have always only run firmware analysis (not source code) I have never looked at the source code analysis tab. I just checked an older firmware analysis and opened a script file /etc/init.d/firewall
and the source code analysis tab shows an error. The same as the one I opened a ticket for here
Example:
Anytime that I have looked at that, the page returns clean results. Example:
The web server was running fine for days, then I added a zip of some source code (curl) to test the source code static analysis plugin. I selected all plugin checkmarks. When I came back a few hours later, the webpage show the error:
The docker logs showed many errors like this:
for a long time leading up to a more fatal error like this:
The error seems to be related to mongodb. It looks like it stopped working at some point because I don't see port 27018 in the
netstat
output anymore.I also see messages like this in the logs