Coder Social home page Coder Social logo

Can't access Velociraptor about detectionlab HOT 3 OPEN

VicTee avatar VicTee commented on June 2, 2024
Can't access Velociraptor

from detectionlab.

Comments (3)

Matthew2412 avatar Matthew2412 commented on June 2, 2024

[*] Verifying that Velociraptor is reachable...
Error occured on webrequest: Exception calling "DownloadString" with "1" argument(s): "Nem lehet csatlakozni a távoli kiszolgálóhoz." (Cant connect to remote service )
[!] Velociraptor was unreachable and may not have installed correctly.

Could someone have a look at the logger vm ?
Fleet, Splunk , Guacamole is reachable but not velociraptor

I tried to redownload it but the issue persisted

from detectionlab.

Matthew2412 avatar Matthew2412 commented on June 2, 2024
logger: HTTP request sent, awaiting response... 200 OK
logger: Length: 54981288 (52M) [application/octet-stream]
logger: Saving to: ‘/opt/velociraptor/velociraptor-v0.7.0-2-linux-amd64’
logger:

velociraptor-v0.7.0 100%[===================>] 52.43M 4.29MB/s in 12s
logger:
logger: 2023-10-15 16:05:43 (4.31 MB/s) - ‘/opt/velociraptor/velociraptor-v0.7.0-2-linux-amd64’ saved [54981288/54981288]
logger:
logger: [16:05:43]: Velociraptor successfully downloaded!
logger: [16:05:43]: Creating Velociraptor dpkg...
logger: Creating amd64 server package at velociraptor_server_0.7.0.2_amd64.deb
logger: [16:05:46]: Cleanup velociraptor package building leftovers...
logger: [16:05:46]: Installing the dpkg...
logger: dpkg: error: cannot access archive 'velociraptor_*_server.deb': No such file or directory
logger: [16:05:46]: Failed to install the dpkg

from detectionlab.

Skr1ptKid-0x avatar Skr1ptKid-0x commented on June 2, 2024

It's not being managed anymore. :\ not sure where you are running it on. Logger isn't loading splunk or velociraptor either for me right now. I re-ran ansible playbook and got guacamole to load correctly. You may want to re-provision the host. Got splunk up. Otherwise, we probably need to look in the logger_bootstrap.sh for something that's wrong/old. And I found it

I installed in manually, but, I think if you look at this log in the bootstrap script, the wildcards in the wrong place. Its in the wrong place in the Velociraptor documents too. Unless I am messed up?

logger: dpkg: error: cannot access archive 'velociraptor_*_server.deb': No such file or directory

It should be like 'velociraptor_server_*_amd64.deb' https://docs.velociraptor.app/docs/deployment/self-signed/
I wonder about the cert used in the config too, but maybe its still ok and if not would it be easier to just make a new one with their tool or just use previous version of raptor? Not sure

Yes, the cert is expired. There are instructions at https://docs.velociraptor.app/docs/deployment/troubleshooting/

Attached is a new server.config. Remove the .txt extension and place is in your DetectionLab/Vagrant/resources/velociraptor path
server.config.yaml.txt

Attached is an updated logger_bootstrap.sh. Remove the .txt extension and place it in DetectionLab/Vagrant path
logger_bootstrap.sh.txt

from detectionlab.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.