Merge remote-tracking branch 'origin/816-port-cmdscan-and-console-plugins-from-vol2-to-vol3-please' into blackhat_2024

This commit is contained in:
Dave Lassalle
2024-08-03 14:27:57 -07:00
2 changed files with 17 additions and 7 deletions
@@ -619,7 +619,8 @@ class Consoles(interfaces.plugins.PluginInterface):
bucket_cmd,
) in command_history.get_commands():
try:
console_properties.append({
console_properties.append(
{
"level": 3,
"name": f"_CONSOLE_INFORMATION.HistoryList.CommandHistory_{index}_Command_{cmd_index}",
"address": bucket_cmd.vol.offset,
@@ -23,9 +23,9 @@ class ROW(objects.StructType):
0x50,
0x60,
0x80,
0xa8,
0xc0,
0xc8,
0xA8,
0xC0,
0xC8,
0x98,
0xF8,
0xF0,
@@ -226,7 +226,12 @@ class COMMAND(objects.StructType):
"""A Command Structure"""
def is_valid(self):
if self.Length < 1 or self.Allocated < 1 or self.Length > 1024 or self.Allocated > 1024:
if (
self.Length < 1
or self.Allocated < 1
or self.Length > 1024
or self.Allocated > 1024
):
return False
return True
@@ -256,7 +261,7 @@ class COMMAND_HISTORY(objects.StructType):
@property
def ProcessHandle(self):
""" Allow ProcessHandle to be referenced regardless of OS version """
"""Allow ProcessHandle to be referenced regardless of OS version"""
return self.ConsoleProcessHandle.ProcessHandle
def is_valid(self, max_history=50):
@@ -269,7 +274,11 @@ class COMMAND_HISTORY(objects.StructType):
return False
# Process handle must be a valid pid
if self.ProcessHandle <= 0 or self.ProcessHandle > 0xFFFF or self.ProcessHandle % 4 != 0:
if (
self.ProcessHandle <= 0
or self.ProcessHandle > 0xFFFF
or self.ProcessHandle % 4 != 0
):
return False
return True