Re: Replicable problem with later versions of npcap
Daniel Miller <[email protected]> Thu, 11 Apr 2019 13:23:22 -0500
| Newsgroups | gmane.comp.security.nmap.devel |
|---|---|
| Message-ID | <CABmvJnOLfg=sWPDRZTtkX8LrKnHZpqXevbspc1iq9C=R81TorA@mail.gmail.com> |
--===============3198082497050563717== Content-Type: multipart/alternative; boundary="000000000000aaeecb0586454804" --000000000000aaeecb0586454804 Content-Type: text/plain; charset="UTF-8" Kurt, We've done some initial investigation into this issue, but we haven't identified a cause yet. We'll be doing our own testing with VMware soon, but if you can provide a bit more information, it would be very helpful. First, we need the output of DiagReport for your system ( https://nmap.org/npcap/guide/npcap-issues.html#npcap-issues-diagreport). Next, we'd like to see if we can leverage built-in Windows diagnostic tools to force a bugcheck (BSoD) which would point directly to the problem. This is preferable to differential diagnosis based on behavior which can take a long time. To do this, we need you to run Driver Verifier and create default settings for npcap.sys and/or npf.sys. Here is the information about Driver Verifier: https://docs.microsoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier Thanks! Dan On Thu, Apr 4, 2019 at 12:09 PM Daniel Miller <[email protected]> wrote: > Kurt, > > Thanks for reporting this. We'll look into it, and will be tracking the > issue at http://issues.nmap.org/1541 > > Dan > > On Wed, Mar 27, 2019 at 1:58 PM Kurt Buff - GSEC, GCIH < > [email protected]> wrote: > >> All, >> >> Found a problem with npcap .0.99-r8 (and possibly r7, but I'm not sure >> of that) up to and including 0.992, with suspended VMs under VMware >> Workstation Pro. >> >> Configuration: >> -Lenovo T460p, 32gb RAM with Intel Dual Band Wireless AC 8260 adapter >> (I do not use the wired adapter, but it is, for completeness sake, an >> Intel 1219-LM), all current drivers (per the Lenovo update utility) >> -Win10 1709, fully patched except for this month's patches, coming soon. >> - VMWare Workstation Pro, 14.1.6 build-12368378 >> - A VM running Win10 1709 (I have a couple of other VMs, but have not >> tested them, as I use them infrequently) in bridged mode. >> - I normally access the VM via RDP from the host. >> >> On the laptop host OS, I upgraded Wireshark to 3.0.0 yesterday (bear >> with me) and accepted the upgrade of npcap to 0.99-r8, and all seemed >> well. However, per my normal practice, I suspended the VM, then >> hibernated the laptop and found upon arriving home that evening that >> my Win10 1709 VM could not touch the network. The VM was unchanged, no >> upgrades (it has npcap 0.99-r8, but I don't believe it's involved). >> Once home, I woke up the laptop and unsuspended the VM, and I could >> not ping the VM from the laptop, nor could the VM see the network when >> I logged into the console via VMware. >> >> I then uninstalled Wireshark and npcap, and the VM saw the network >> immediately. I was then able to install npcap, and the VM still >> functioned. I didn't install either Wireshark or nmap, just npcap. At >> the end of the evening, I suspended the VM again, and hibernated the >> laptop. >> >> I then tried again, suspending/unsuspending the VM and again npcap >> prevented the newly unsuspended VM from seeing the network, and >> uninstalling npcap gave immediate access to the network for the VM. >> >> I was able to replicate the problem again today, as I fired up the >> laptop from hibernation, then unsuspended the VM, and the VM wasn't >> able to connect to the network. Again, as soon as I removed npcap >> 0.992, the VM was on the network. >> >> In all cases, the host OS had no problems with networking, other than >> not being able to see the VM, and the VM not being able to see its >> network. >> >> If any more info is needed, please let me know, as i'd like to help >> resolve this problem. >> >> Thanks, >> >> Kurt >> _______________________________________________ >> Sent through the dev mailing list >> https://nmap.org/mailman/listinfo/dev >> Archived at http://seclists.org/nmap-dev/ >> > --000000000000aaeecb0586454804 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div>Kurt,</div><div><br= ></div><div>We've done some initial investigation into this issue, but = we haven't identified a cause yet. We'll be doing our own testing w= ith VMware soon, but if you can provide a bit more information, it would be= very helpful. First, we need the output of DiagReport for your system (<a = href=3D"https://nmap.org/npcap/guide/npcap-issues.html#npcap-issues-diagrep= ort">https://nmap.org/npcap/guide/npcap-issues.html#npcap-issues-diagreport= </a>).</div><div><br></div><div>Next, we'd like to see if we can levera= ge built-in Windows diagnostic tools to force a bugcheck (BSoD) which would= point directly to the problem. This is preferable to differential diagnosi= s based on behavior which can take a long time. To do this, we need you to = run Driver Verifier and create default settings for npcap.sys and/or npf.sy= s. Here is the information about Driver Verifier: <a href=3D"https://docs.m= icrosoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier">https:= //docs.microsoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier= </a></div><div><br></div><div>Thanks!</div><div>Dan<br></div></div></div></= div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On= Thu, Apr 4, 2019 at 12:09 PM Daniel Miller <<a href=3D"mailto:bonsaivik= [email protected]">[email protected]</a>> wrote:<br></div><blockquote c= lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli= d rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>Kurt,</div><div>= <br></div><div>Thanks for reporting this. We'll look into it, and will = be tracking the issue at <a href=3D"http://issues.nmap.org/1541" target=3D"= _blank">http://issues.nmap.org/1541</a></div><div><br></div><div>Dan<br></d= iv></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_att= r">On Wed, Mar 27, 2019 at 1:58 PM Kurt Buff - GSEC, GCIH <<a href=3D"ma= ilto:[email protected]" target=3D"_blank">[email protected]</a>> wro= te:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px = 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">All,<br> <br> Found a problem with npcap .0.99-r8 (and possibly r7, but I'm not sure<= br> of that) up to and including 0.992, with suspended VMs under VMware<br> Workstation Pro.<br> <br> Configuration:<br> -Lenovo T460p, 32gb RAM with Intel Dual Band Wireless AC 8260 adapter<br> (I do not use the wired adapter, but it is, for completeness sake, an<br> Intel 1219-LM), all current drivers (per the Lenovo update utility)<br> -Win10 1709, fully patched except for this month's patches, coming soon= .<br> - VMWare Workstation Pro, 14.1.6 build-12368378<br> - A VM running Win10 1709 (I have a couple of other VMs, but have not<br> tested them, as I use them infrequently) in bridged mode.<br> - I normally access the VM via RDP from the host.<br> <br> On the laptop host OS, I upgraded Wireshark to 3.0.0 yesterday (bear<br> with me) and accepted the upgrade of npcap to 0.99-r8, and all seemed<br> well. However, per my normal practice, I suspended the VM, then<br> hibernated the laptop and found upon arriving home that evening that<br> my Win10 1709 VM could not touch the network. The VM was unchanged, no<br> upgrades (it has npcap 0.99-r8, but I don't believe it's involved).= <br> Once home, I woke up the laptop and unsuspended the VM, and I could<br> not ping the VM from the laptop, nor could the VM see the network when<br> I logged into the console via VMware.<br> <br> I then uninstalled Wireshark and npcap, and the VM saw the network<br> immediately. I was then able to install npcap, and the VM still<br> functioned. I didn't install either Wireshark or nmap, just npcap. At<b= r> the end of the evening, I suspended the VM again, and hibernated the<br> laptop.<br> <br> I then tried again, suspending/unsuspending the VM and again npcap<br> prevented the newly unsuspended VM from seeing the network, and<br> uninstalling npcap gave immediate access to the network for the VM.<br> <br> I was able to replicate the problem again today, as I fired up the<br> laptop from hibernation, then unsuspended the VM, and the VM wasn't<br> able to connect to the network. Again, as soon as I removed npcap<br> 0.992, the VM was on the network.<br> <br> In all cases, the host OS had no problems with networking, other than<br> not being able to see the VM, and the VM not being able to see its<br> network.<br> <br> If any more info is needed, please let me know, as i'd like to help<br> resolve this problem.<br> <br> Thanks,<br> <br> Kurt<br> _______________________________________________<br> Sent through the dev mailing list<br> <a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer" target= =3D"_blank">https://nmap.org/mailman/listinfo/dev</a><br> Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer" ta= rget=3D"_blank">http://seclists.org/nmap-dev/</a><br> </blockquote></div> </blockquote></div> --000000000000aaeecb0586454804-- --===============3198082497050563717== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Sent through the dev mailing list https://nmap.org/mailman/listinfo/dev Archived at http://seclists.org/nmap-dev/ --===============3198082497050563717==--