work on _POOL_HEADER.get_object()

This commit is contained in:
Michael Ligh
2018-09-15 15:22:38 +01:00
committed by ikelos
parent be6a351a11
commit 5d20faa0a7
2 changed files with 44 additions and 7 deletions
@@ -18,13 +18,42 @@ class _POOL_HEADER(objects.Struct):
def get_object(self, type_name, object_type):
symbol_table_name = self.vol.type_name.split(constants.BANG)[0]
pool_header_size = self._context.symbol_space.get_type(symbol_table_name + constants.BANG + "_POOL_HEADER").size
# if there is no object type, then just instantiate a structure
if object_type is None:
pass
mem_object = self._context.object(symbol_table_name + constants.BANG + type_name,
layer_name = self.vol.layer_name,
offset = self.vol.offset + pool_header_size)
return mem_object
# otherwise we have an executive object in the pool
else:
pass
# this used to be a vol magic but its basically the size of a pool header
alignment = pool_header_size
type_size = self._context.symbol_space.get_type(symbol_table_name + constants.BANG + type_name).size
rounded_size = utility.round(type_size, alignment, up = True)
mem_object = self._context.object(symbol_table_name + constants.BANG + type_name,
layer_name = self.vol.layer_name,
offset = self.vol.offset + self.BlockSize * alignment - rounded_size)
object_header = mem_object.object_header()
## FIXME: this will raise even though we know a valid object exists at this address
#if mem_object.vol.offset == 0x0000000002013ad0:
# print(object_header.NameInfo.Name.String)
try:
object_type_string = object_header.NameInfo.Name.String
if object_type_string == object_type:
return mem_object
else:
return None
except (TypeError, exceptions.InvalidAddressException):
return None
class _KSYSTEM_TIME(objects.Struct):
@@ -422,7 +451,7 @@ class _UNICODE_STRING(objects.Struct):
String = property(get_string)
class _EPROCESS(generic.GenericIntelProcess):
class _EPROCESS(generic.GenericIntelProcess, ExecutiveObject):
def add_process_layer(self,
config_prefix: str = None,
preferred_name: str = None):
+12 -4
View File
@@ -65,15 +65,15 @@ class PoolScanner(plugins.PluginInterface):
]
# a lookup table that associates pool tags with structures and object types
tag_type_map = {
b'AtmT': [
"AtmT": [
"_RTL_ATOM_TABLE", # structure name
None, # _OBJECT_TYPE name (if any)
],
b'Pro\xe3': [
"Pro\xe3": [
"_EPROCESS",
"Process",
],
b'Proc': [
"Proc": [
"_EPROCESS",
"Process",
],
@@ -99,10 +99,18 @@ class PoolScanner(plugins.PluginInterface):
vollog.log(constants.LOGLEVEL_VVV, "Cannot create an instance of {}".format(type_entry[0]))
continue
# generate some type-specific info for sanity checking
if type_entry[1] == "Process":
name = mem_object.ImageFileName.cast("string",
max_length = mem_object.ImageFileName.vol.count,
errors = "replace")
else:
name = ""
yield (0, (tag_string,
format_hints.Hex(header.vol.offset),
header.vol.layer_name,
"Name",
name,
"Path"))
@classmethod