From 201fc5780aa787484886a37723cd32432c7166d4 Mon Sep 17 00:00:00 2001 From: Dave Lassalle Date: Wed, 6 Jun 2018 16:38:19 -0500 Subject: [PATCH] don't use BaseBlock.Length for maxaddr --- volatility/framework/layers/registry.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/volatility/framework/layers/registry.py b/volatility/framework/layers/registry.py index aad48d108..948dfeee7 100644 --- a/volatility/framework/layers/registry.py +++ b/volatility/framework/layers/registry.py @@ -62,7 +62,9 @@ class RegistryHive(interfaces.layers.TranslationLayerInterface): self._minaddr = 0 # If there's no base_block, we don't know how big the address space is # We also don't know the root_cell_offset, so we use a hardcoded value of 0x20 - self._maxaddr = self._base_block.Length or 0x7fffffff + # FIXME: using BaseBlock.Length runs into issues + # self._maxaddr = self._base_block.Length or 0x7fffffff + self._maxaddr = 0x7fffffff @property def hive_offset(self) -> int: