mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-28 04:24:53 +02:00
@@ -87,7 +87,7 @@ class Downloader:
|
||||
output_filename = 'unknown-kernel.json'
|
||||
for named_file in named_files:
|
||||
prefix = '--system-map'
|
||||
if not 'System' in named_files[named_file]:
|
||||
if 'System' not in named_files[named_file]:
|
||||
prefix = '--elf'
|
||||
output_filename = './' + '-'.join((named_file.split('/')[-1]).split('-')[2:])[:-4] + '.json.xz'
|
||||
args += [prefix, named_files[named_file]]
|
||||
|
||||
@@ -543,7 +543,7 @@ class CommandLine:
|
||||
self._file = io.open(fd, mode = 'w+b')
|
||||
CLIFileHandler.__init__(self, filename)
|
||||
for item in dir(self._file):
|
||||
if not item.startswith('_') and not item in ['closed', 'close', 'mode', 'name']:
|
||||
if not item.startswith('_') and item not in ('closed', 'close', 'mode', 'name'):
|
||||
setattr(self, item, getattr(self._file, item))
|
||||
|
||||
def __getattr__(self, item):
|
||||
|
||||
@@ -7,6 +7,7 @@ import json
|
||||
import logging
|
||||
import os
|
||||
import sys
|
||||
import glob
|
||||
|
||||
import volatility3.plugins
|
||||
import volatility3.symbols
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
import logging
|
||||
from typing import Any, Iterable, List, Tuple, Type, Optional, Callable
|
||||
|
||||
from volatility3.framework import interfaces, constants
|
||||
from volatility3.framework import interfaces, constants, layers
|
||||
from volatility3.framework.automagic import symbol_cache
|
||||
from volatility3.framework.configuration import requirements
|
||||
from volatility3.framework.layers import scanners
|
||||
|
||||
@@ -82,7 +82,7 @@ class ResourceAccessor(object):
|
||||
"""Determines whether a URLs contents should be cached"""
|
||||
parsed_url = urllib.parse.urlparse(url)
|
||||
|
||||
return self._enable_cache and not parsed_url.scheme in self._non_cached_schemes()
|
||||
return self._enable_cache and parsed_url.scheme not in self._non_cached_schemes()
|
||||
|
||||
@staticmethod
|
||||
def _non_cached_schemes() -> List[str]:
|
||||
|
||||
@@ -44,7 +44,7 @@ class Check_creds(interfaces.plugins.PluginInterface):
|
||||
|
||||
cred_addr = task.cred.dereference().vol.offset
|
||||
|
||||
if not cred_addr in creds:
|
||||
if cred_addr not in creds:
|
||||
creds[cred_addr] = []
|
||||
|
||||
creds[cred_addr].append(task.pid)
|
||||
|
||||
@@ -152,7 +152,7 @@ class Check_syscall(plugins.PluginInterface):
|
||||
except exceptions.SymbolError:
|
||||
ia32_symbol = None
|
||||
|
||||
if ia32_symbol != None:
|
||||
if ia32_symbol is not None:
|
||||
ia32_info = self._get_table_info(vmlinux, "ia32_sys_call_table", ptr_sz)
|
||||
tables.append(("32bit", ia32_info))
|
||||
|
||||
|
||||
@@ -72,7 +72,7 @@ class List_Files(plugins.PluginInterface):
|
||||
key = vnode.vol.offset
|
||||
added = False
|
||||
|
||||
if not key in loop_vnodes:
|
||||
if key not in loop_vnodes:
|
||||
# We can't do anything with a no-name vnode
|
||||
v_name = cls._vnode_name(vnode)
|
||||
if v_name is None:
|
||||
@@ -108,7 +108,7 @@ class List_Files(plugins.PluginInterface):
|
||||
added = True
|
||||
|
||||
parent = cls._get_parent(context, vnode)
|
||||
while parent and not parent in loop_vnodes:
|
||||
while parent and parent not in loop_vnodes:
|
||||
if not cls._walk_vnode(context, parent, loop_vnodes):
|
||||
break
|
||||
|
||||
|
||||
@@ -84,7 +84,7 @@ class MMVAD_SHORT(objects.StructType):
|
||||
|
||||
if tag in ["VadS", "VadF"]:
|
||||
target = "_MMVAD_SHORT"
|
||||
elif tag != None and tag.startswith("Vad"):
|
||||
elif tag is not None and tag.startswith("Vad"):
|
||||
target = "_MMVAD"
|
||||
elif depth == 0:
|
||||
# the root node at depth 0 is allowed to not have a tag
|
||||
@@ -651,7 +651,10 @@ class EPROCESS(generic.GenericIntelProcess, pool.ExecutiveObject):
|
||||
except AttributeError:
|
||||
return False
|
||||
|
||||
return value != 0 and value != None
|
||||
if value:
|
||||
return True
|
||||
|
||||
return False
|
||||
|
||||
def get_vad_root(self):
|
||||
|
||||
|
||||
Reference in New Issue
Block a user