Closed spartan782 closed 5 years ago
This appears to be fixed with the new packages however there is another bro issue when it run broctl check
.
warning in /usr/share/bro/policy.protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb' instead"
error in /usr/share/bro/base/bif/plugins/.Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:connection; version:count; record_version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count; comp_methods:vector of count;) and event(c:connection; version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count;))
Confirm, have seen this issue.
sudo systemctl -l status bro.service
● bro.service - Bro Network Intrusion Detection System (NIDS)
Loaded: loaded (/usr/lib/systemd/system/bro.service; enabled; vendor preset: disabled)
Active: failed (Result: exit-code) since Mon 2019-02-18 03:32:04 UTC; 13min ago
Process: 12654 ExecStart=/usr/bin/broctl deploy (code=exited, status=1/FAILURE)
Feb 18 03:32:04 simplerockbuild.simplerock.lan broctl[12654]: proxy-1 scripts failed.
Feb 18 03:32:04 simplerockbuild.simplerock.lan broctl[12654]: warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb' instead"
Feb 18 03:32:04 simplerockbuild.simplerock.lan broctl[12654]: error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:connection; version:count; record_version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count; comp_methods:vector of count;) and event(c:connection; version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count;))
Feb 18 03:32:04 simplerockbuild.simplerock.lan broctl[12654]: ens34-1 scripts failed.
Feb 18 03:32:04 simplerockbuild.simplerock.lan broctl[12654]: warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb' instead"
Feb 18 03:32:04 simplerockbuild.simplerock.lan broctl[12654]: error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:connection; version:count; record_version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count; comp_methods:vector of count;) and event(c:connection; version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count;))
Feb 18 03:32:04 simplerockbuild.simplerock.lan systemd[1]: bro.service: control process exited, code=exited status=1
Feb 18 03:32:04 simplerockbuild.simplerock.lan systemd[1]: Failed to start Bro Network Intrusion Detection System (NIDS).
Feb 18 03:32:04 simplerockbuild.simplerock.lan systemd[1]: Unit bro.service entered failed state.
Feb 18 03:32:04 simplerockbuild.simplerock.lan systemd[1]: bro.service failed.
sudo broctl diag
[logger]
No core file found and gdb is not installed. It is recommended to
install gdb so that BroControl can output a backtrace if Bro crashes.
Bro 2.6.1
Linux 3.10.0-862.14.4.el7.x86_64
Bro plugins:
Apache::Kafka - Writes logs to Kafka (dynamic, version 0.3)
Bro::AF_Packet - Packet acquisition via AF_Packet (dynamic, version 1.4)
==== No reporter.log
==== stderr.log
warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /data/bro/spool/installed-scripts-do-not-touch/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb' instead"
error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /data/bro/spool/installed-scripts-do-not-touch/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:connection; version:count; record_version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count; comp_methods:vector of count;) and event(c:connection; version:count; possible_ts:time; client_random:string; session_id:string; ciphers:vector of count;))
==== stdout.log
max memory size (kbytes, -m) unlimited
data seg size (kbytes, -d) unlimited
virtual memory (kbytes, -v) unlimited
core file size (blocks, -c) unlimited
==== .cmdline
-U .status -p broctl -p broctl-live -p local -p logger local.bro broctl base/frameworks/cluster broctl/auto
==== .env_vars
PATH=/usr/bin:/usr/share/broctl/scripts:/sbin:/bin:/usr/sbin:/usr/bin
BROPATH=/data/bro/spool/installed-scripts-do-not-touch/site::/data/bro/spool/installed-scripts-do-not-touch/auto:/usr/share/bro:/usr/share/bro/policy:/usr/share/bro/site
CLUSTER_NODE=logger
==== .status
TERMINATED [atexit]
==== No prof.log
==== No packet_filter.log
==== No loaded_scripts.log
[manager]
No work dir found
[proxy-1]
No work dir found
[ens34-1]
No work dir found
[ens34-2]
No work dir found
Looks like we need to update JA3/JA3S in the rock-scripts.
https://github.com/salesforce/ja3/commit/202bcaa6995eb554cb8d37c5573050548cbdff50
This issue still appears to be plaguing the nightly release.
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb'
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:con
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: manager scripts failed.
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb'
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:con
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: proxy-1 scripts failed.
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb'
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:con
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: ens34-1 scripts failed.
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: warning in /usr/share/bro/policy/protocols/smb/__load__.bro, line 1: deprecated script loaded from /usr/share/bro/site/scripts/rock/./rock.bro:24 "Use '@load base/protocols/smb'
Feb 20 02:52:33 simplerockbuild.simplerock.lan broctl[5106]: error in /usr/share/bro/base/bif/plugins/./Bro_SSL.events.bif.bro, line 41 and /usr/share/bro/site/scripts/rock/././misc/ja3/./ja3.bro, line 118: incompatible types (event(c:con
Feb 20 02:52:33 simplerockbuild.simplerock.lan systemd[1]: bro.service: control process exited, code=exited status=1
Fixed with ja3 update in rock dashboards
Package errors on nightly
Additional possibly related package fails.