Closed glennbarrett closed 6 years ago
Forgot to note that I had run the update.sh script before trying this.
I just tried again with a fresh VM before the update, and it is working properly. After running the update.sh script, the functionality is broken again.
I noticed as part of the apt upgrade process in the update.sh, the following error is thrown:
Errors were encountered while processing: /var/cache/apt/archives/artifacts-data_20170909-1ppa1\~xenial_all.deb /var/cache/apt/archives/plaso-data_20170930-1ppa1\~xenial_all.deb E: Sub-process /usr/bin/dpkg returned an error code (1) Reading package lists... Done Building dependency tree Reading state information... Done You might want to run 'apt-get -f install' to correct these. The following packages have unmet dependencies: python-artifacts : Depends: artifacts-data but it is not installed python-plaso : Depends: plaso-data but it is not installed E: Unmet dependencies. Try using -f.
I ran an apt-get -f install and it did install more packages successfully, but still did not resolve the broken functionality.
Glenn,
Thanks for bringing this up. I'm not able to test for the next couple of days but I will later this week. My guess is that something happened with with plaso apt-get repo and that they are in the process of updating it therefore all of the dependencies aren't aligning at this time. I recommend rolling back to a snapshot of the VM before the update script was run or redeploying the OVF and not running the update.sh script until the Plaso repository is fixed (usually takes a couple to a few days).
Checking the Plaso git it looks like they are in the middle of updating the Linux repo's. https://github.com/log2timeline/plaso/issues/1421
The work around for now is to comment out the following lines of the update.sh script
echo "Updating OS" sudo apt-get -y update sudo apt-get -y dist-upgrade sudo apt-get -y autoremove
Filed an issue with Plaso Github for upgrading: https://github.com/log2timeline/plaso/issues/1484
This is not officially supported yet in CDQR but that support is coming (you can check it out now in the Branch PR002
sudo add-apt-repository -y universe
sudo add-apt-repository -y ppa:gift/stable
sudo apt -y purge python-artifacts python3-artifacts plaso plaso-data plaso-tools python-plaso forensics-all
sudo rm -rf /usr/lib/python2.7/dist-packages/plaso
sudo apt -y -f install
sudo apt -y autoremove
sudo apt -y autoclean
sudo -H pip uninstall PyYAML
sudo -H pip uninstall artifacts
sudo apt -y update;sudo apt-get -y dist-upgrade
sudo apt -y install python-plaso plaso-tools
sudo shutdown -r "now"
On a fresh install of CCF_VM 2.2, I am getting an error that there is no such file or directory for log2timeline.py when running the standard cdqr.py command to process a windows zip from CyLR. It looks like the new TimeSketch options aren't part of the documentation, so maybe this command or process has changed somehow but isn't documented?