From 164079c203f44eac655ad213aea8693f2ae69b7b Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Tue, 23 Jul 2019 00:46:09 +0100 Subject: [PATCH] Casting will use the original object's symbol_table if none is provided. --- volatility/framework/plugins/windows/handles.py | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/volatility/framework/plugins/windows/handles.py b/volatility/framework/plugins/windows/handles.py index a8588dc8e..3ffe2e291 100644 --- a/volatility/framework/plugins/windows/handles.py +++ b/volatility/framework/plugins/windows/handles.py @@ -81,8 +81,8 @@ class Handles(interfaces_plugins.PluginInterface): # before windows 7 if not self.context.layers[virtual].is_valid(handle_table_entry.Object): return None - fast_ref = handle_table_entry.Object.cast(self.config["nt_symbols"] + constants.BANG + "_EX_FAST_REF") - object_header = fast_ref.dereference().cast(self.config["nt_symbols"] + constants.BANG + "_OBJECT_HEADER") + fast_ref = handle_table_entry.Object.cast("_EX_FAST_REF") + object_header = fast_ref.dereference().cast("_OBJECT_HEADER") object_header.GrantedAccess = handle_table_entry.GrantedAccess except AttributeError: # starting with windows 8 @@ -284,16 +284,16 @@ class Handles(interfaces_plugins.PluginInterface): continue if obj_type == "File": - item = entry.Body.cast(self.config["nt_symbols"] + constants.BANG + "_FILE_OBJECT") + item = entry.Body.cast("_FILE_OBJECT") obj_name = item.file_name_with_device() elif obj_type == "Process": - item = entry.Body.cast(self.config["nt_symbols"] + constants.BANG + "_EPROCESS") + item = entry.Body.cast("_EPROCESS") obj_name = "{} Pid {}".format(utility.array_to_string(proc.ImageFileName), item.UniqueProcessId) elif obj_type == "Thread": - item = entry.Body.cast(self.config["nt_symbols"] + constants.BANG + "_ETHREAD") + item = entry.Body.cast("_ETHREAD") obj_name = "Tid {} Pid {}".format(item.Cid.UniqueThread, item.Cid.UniqueProcess) elif obj_type == "Key": - item = entry.Body.cast(self.config["nt_symbols"] + constants.BANG + "_CM_KEY_BODY") + item = entry.Body.cast("_CM_KEY_BODY") obj_name = item.get_full_key_name() else: try: