Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cuckoo pcap and pcap_sorted capture nothing of interest. :( #287

Open
b1g334 opened this issue May 13, 2016 · 0 comments
Open

cuckoo pcap and pcap_sorted capture nothing of interest. :( #287

b1g334 opened this issue May 13, 2016 · 0 comments

Comments

@b1g334
Copy link

b1g334 commented May 13, 2016

Hello,

I have Cuckoo setup and up and running (i think) and I can invoke a vbox image, and perform --URL and analyze a test url... In this case i'm just feeding a test url, http://www.cnn.com.

My problem is that the PCAP files in /storage/analysis/9/dump.pcap do not contain any references to the subject website.

I'm sure I've mucked up somewhere obvious. The "sort_pcap = on" value in cuckoo.conf doesn't actually produce a sorted PCAP!

I'm on a ubuntu14.04LTS box, I have entered the command to allow tcpdump to run as a non root account as well.

sudo chmod +s /usr/sbin/tcpdump
sudo apt-get install libcap2-bin
sudo setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump

I can successfully launch the URL analysis, on windows 7, the agent spawns an ie8 instance and browses to the website. Everything looks normal, just sparse to empty PCAP files.

feliperalmeida pushed a commit to feliperalmeida/cuckoo-modified that referenced this issue Dec 15, 2016
dist.py, fix of empty task_ids response
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant