mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-10-01 05:54:58 +02:00
Merge pull request #1018 from volatilityfoundation/1017-printkey-breaks-when-encountering-invalid-root-node
issue #1017 - check for valid root node type
This commit is contained in:
@@ -171,7 +171,15 @@ class RegistryHive(linear.LinearlyMappedLayer):
|
||||
node (default) or a list of nodes from root to the current node
|
||||
(if return_list is true).
|
||||
"""
|
||||
node_key = [self.get_node(self.root_cell_offset)]
|
||||
root_node = self.get_node(self.root_cell_offset)
|
||||
if not root_node.vol.type_name.endswith(constants.BANG + "_CM_KEY_NODE"):
|
||||
raise RegistryFormatException(
|
||||
self.name,
|
||||
"Encountered {} instead of _CM_KEY_NODE".format(
|
||||
root_node.vol.type_name
|
||||
),
|
||||
)
|
||||
node_key = [root_node]
|
||||
if key.endswith("\\"):
|
||||
key = key[:-1]
|
||||
key_array = key.split("\\")
|
||||
|
||||
Reference in New Issue
Block a user