Re: Replicable problem with later versions of npcap

Daniel Miller <[email protected]> Thu, 11 Apr 2019 13:23:22 -0500
Newsgroups gmane.comp.security.nmap.devel
Message-ID <CABmvJnOLfg=sWPDRZTtkX8LrKnHZpqXevbspc1iq9C=R81TorA@mail.gmail.com>
--===============3198082497050563717==
Content-Type: multipart/alternative; boundary="000000000000aaeecb0586454804"

--000000000000aaeecb0586454804
Content-Type: text/plain; charset="UTF-8"

Kurt,

We've done some initial investigation into this issue, but we haven't
identified a cause yet. We'll be doing our own testing with VMware soon,
but if you can provide a bit more information, it would be very helpful.
First, we need the output of DiagReport for your system (
https://nmap.org/npcap/guide/npcap-issues.html#npcap-issues-diagreport).

Next, we'd like to see if we can leverage built-in Windows diagnostic tools
to force a bugcheck (BSoD) which would point directly to the problem. This
is preferable to differential diagnosis based on behavior which can take a
long time. To do this, we need you to run Driver Verifier and create
default settings for npcap.sys and/or npf.sys. Here is the information
about Driver Verifier:
https://docs.microsoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier

Thanks!
Dan

On Thu, Apr 4, 2019 at 12:09 PM Daniel Miller <[email protected]>
wrote:

> Kurt,
>
> Thanks for reporting this. We'll look into it, and will be tracking the
> issue at http://issues.nmap.org/1541
>
> Dan
>
> On Wed, Mar 27, 2019 at 1:58 PM Kurt Buff - GSEC, GCIH <
> [email protected]> wrote:
>
>> All,
>>
>> Found a problem with npcap .0.99-r8 (and possibly r7, but I'm not sure
>> of that) up to and including 0.992, with suspended VMs under VMware
>> Workstation Pro.
>>
>> Configuration:
>> -Lenovo T460p, 32gb RAM with Intel Dual Band Wireless AC 8260 adapter
>> (I do not use the wired adapter, but it is, for completeness sake, an
>> Intel 1219-LM), all current drivers (per the Lenovo update utility)
>> -Win10 1709, fully patched except for this month's patches, coming soon.
>> - VMWare Workstation Pro, 14.1.6 build-12368378
>> - A VM running Win10 1709 (I have a couple of other VMs, but have not
>> tested them, as I use them infrequently) in bridged mode.
>> - I normally access the VM via RDP from the host.
>>
>> On the laptop host OS, I upgraded Wireshark to 3.0.0 yesterday (bear
>> with me) and accepted the upgrade of npcap to 0.99-r8, and all seemed
>> well. However, per my normal practice, I suspended the VM, then
>> hibernated the laptop and found upon arriving home that evening that
>> my Win10 1709 VM could not touch the network. The VM was unchanged, no
>> upgrades (it has npcap 0.99-r8, but I don't believe it's involved).
>> Once home, I woke up the laptop and unsuspended the VM, and I could
>> not ping the VM from the laptop, nor could the VM see the network when
>> I logged into the console via VMware.
>>
>> I then uninstalled Wireshark and npcap, and the VM saw the network
>> immediately. I was then able to install npcap, and the VM still
>> functioned. I didn't install either Wireshark or nmap, just npcap. At
>> the end of the evening, I suspended the VM again, and hibernated the
>> laptop.
>>
>> I then tried again, suspending/unsuspending the VM and again npcap
>> prevented the newly unsuspended VM from seeing the network, and
>> uninstalling npcap gave immediate access to the network for the VM.
>>
>> I was able to replicate the problem again today, as I fired up the
>> laptop from hibernation, then unsuspended the VM, and the VM wasn't
>> able to connect to the network. Again, as soon as I removed npcap
>> 0.992, the VM was on the network.
>>
>> In all cases, the host OS had no problems with networking, other than
>> not being able to see the VM, and the VM not being able to see its
>> network.
>>
>> If any more info is needed, please let me know, as i'd like to help
>> resolve this problem.
>>
>> Thanks,
>>
>> Kurt
>> _______________________________________________
>> Sent through the dev mailing list
>> https://nmap.org/mailman/listinfo/dev
>> Archived at http://seclists.org/nmap-dev/
>>
>

--000000000000aaeecb0586454804
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div>Kurt,</div><div><br=
></div><div>We&#39;ve done some initial investigation into this issue, but =
we haven&#39;t identified a cause yet. We&#39;ll be doing our own testing w=
ith VMware soon, but if you can provide a bit more information, it would be=
 very helpful. First, we need the output of DiagReport for your system (<a =
href=3D"https://nmap.org/npcap/guide/npcap-issues.html#npcap-issues-diagrep=
ort">https://nmap.org/npcap/guide/npcap-issues.html#npcap-issues-diagreport=
</a>).</div><div><br></div><div>Next, we&#39;d like to see if we can levera=
ge built-in Windows diagnostic tools to force a bugcheck (BSoD) which would=
 point directly to the problem. This is preferable to differential diagnosi=
s based on behavior which can take a long time. To do this, we need you to =
run Driver Verifier and create default settings for npcap.sys and/or npf.sy=
s. Here is the information about Driver Verifier: <a href=3D"https://docs.m=
icrosoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier">https:=
//docs.microsoft.com/en-us/windows-hardware/drivers/devtest/driver-verifier=
</a></div><div><br></div><div>Thanks!</div><div>Dan<br></div></div></div></=
div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On=
 Thu, Apr 4, 2019 at 12:09 PM Daniel Miller &lt;<a href=3D"mailto:bonsaivik=
[email protected]">[email protected]</a>&gt; wrote:<br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli=
d rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>Kurt,</div><div>=
<br></div><div>Thanks for reporting this. We&#39;ll look into it, and will =
be tracking the issue at <a href=3D"http://issues.nmap.org/1541" target=3D"=
_blank">http://issues.nmap.org/1541</a></div><div><br></div><div>Dan<br></d=
iv></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_att=
r">On Wed, Mar 27, 2019 at 1:58 PM Kurt Buff - GSEC, GCIH &lt;<a href=3D"ma=
ilto:[email protected]" target=3D"_blank">[email protected]</a>&gt; wro=
te:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">All,<br>
<br>
Found a problem with npcap .0.99-r8 (and possibly r7, but I&#39;m not sure<=
br>
of that) up to and including 0.992, with suspended VMs under VMware<br>
Workstation Pro.<br>
<br>
Configuration:<br>
-Lenovo T460p, 32gb RAM with Intel Dual Band Wireless AC 8260 adapter<br>
(I do not use the wired adapter, but it is, for completeness sake, an<br>
Intel 1219-LM), all current drivers (per the Lenovo update utility)<br>
-Win10 1709, fully patched except for this month&#39;s patches, coming soon=
.<br>
- VMWare Workstation Pro, 14.1.6 build-12368378<br>
- A VM running Win10 1709 (I have a couple of other VMs, but have not<br>
tested them, as I use them infrequently) in bridged mode.<br>
- I normally access the VM via RDP from the host.<br>
<br>
On the laptop host OS, I upgraded Wireshark to 3.0.0 yesterday (bear<br>
with me) and accepted the upgrade of npcap to 0.99-r8, and all seemed<br>
well. However, per my normal practice, I suspended the VM, then<br>
hibernated the laptop and found upon arriving home that evening that<br>
my Win10 1709 VM could not touch the network. The VM was unchanged, no<br>
upgrades (it has npcap 0.99-r8, but I don&#39;t believe it&#39;s involved).=
<br>
Once home, I woke up the laptop and unsuspended the VM, and I could<br>
not ping the VM from the laptop, nor could the VM see the network when<br>
I logged into the console via VMware.<br>
<br>
I then uninstalled Wireshark and npcap, and the VM saw the network<br>
immediately. I was then able to install npcap, and the VM still<br>
functioned. I didn&#39;t install either Wireshark or nmap, just npcap. At<b=
r>
the end of the evening, I suspended the VM again, and hibernated the<br>
laptop.<br>
<br>
I then tried again, suspending/unsuspending the VM and again npcap<br>
prevented the newly unsuspended VM from seeing the network, and<br>
uninstalling npcap gave immediate access to the network for the VM.<br>
<br>
I was able to replicate the problem again today, as I fired up the<br>
laptop from hibernation, then unsuspended the VM, and the VM wasn&#39;t<br>
able to connect to the network. Again, as soon as I removed npcap<br>
0.992, the VM was on the network.<br>
<br>
In all cases, the host OS had no problems with networking, other than<br>
not being able to see the VM, and the VM not being able to see its<br>
network.<br>
<br>
If any more info is needed, please let me know, as i&#39;d like to help<br>
resolve this problem.<br>
<br>
Thanks,<br>
<br>
Kurt<br>
_______________________________________________<br>
Sent through the dev mailing list<br>
<a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer" target=
=3D"_blank">https://nmap.org/mailman/listinfo/dev</a><br>
Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer" ta=
rget=3D"_blank">http://seclists.org/nmap-dev/</a><br>
</blockquote></div>
</blockquote></div>

--000000000000aaeecb0586454804--

--===============3198082497050563717==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
--===============3198082497050563717==--