From 640f2584e471e38d003f0e63064298a209ef40ea Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Thu, 24 Sep 2020 01:20:37 +0100 Subject: [PATCH] Windows: Reduce complexity by using built-in inet_ntop --- .../symbols/windows/extensions/network.py | 66 ++----------------- 1 file changed, 7 insertions(+), 59 deletions(-) diff --git a/volatility/framework/symbols/windows/extensions/network.py b/volatility/framework/symbols/windows/extensions/network.py index 4919f3412..c2794367c 100644 --- a/volatility/framework/symbols/windows/extensions/network.py +++ b/volatility/framework/symbols/windows/extensions/network.py @@ -2,71 +2,21 @@ # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # -import enum -import itertools import logging import socket +from typing import Dict, Tuple, List, Union -from volatility.framework import objects, interfaces, exceptions from volatility.framework import exceptions +from volatility.framework import objects, interfaces from volatility.framework.objects import Array from volatility.framework.renderers import conversion -from volatility.framework.symbols.wrappers import Flags -from volatility.framework import renderers -from typing import Dict, Tuple vollog = logging.getLogger(__name__) -def inet_ntop(address_family: int, packed_ip: Array) -> str: - - def inet_ntop4(packed_ip: Array) -> str: - - if not (isinstance(packed_ip, list) or isinstance(packed_ip, Array)): - raise TypeError("must be Array, not {0}".format(type(packed_ip))) - if len(packed_ip) != 4: - raise ValueError("invalid length of packed IP address string") - return "{0}.{1}.{2}.{3}".format(*[x.to_bytes(1, "little")[0] for x in packed_ip]) - - def inet_ntop6(packed_ip) -> str: - if not (isinstance(packed_ip, list) or isinstance(packed_ip, Array)): - raise TypeError("must be Array, not {0}".format(type(packed_ip))) - - if len(packed_ip) != 16: - raise ValueError("invalid length of packed IP address string") - - words = [] - for i in range(0, 16, 2): - words.append((packed_ip[i] << 8) | packed_ip[i + 1]) - - # Replace a run of 0x00s with None - numlen = [(k, len(list(g))) for k, g in itertools.groupby(words)] - max_zero_run = sorted(sorted(numlen, key = lambda x: x[1], reverse = True), key = lambda x: x[0])[0] - words = [] - for k, l in numlen: - if (k == 0) and (l == max_zero_run[1]) and not (None in words): - words.append(None) - else: - for i in range(l): - words.append(k) - - # Handle encapsulated IPv4 addresses - encapsulated = "" - if (words[0] is None) and (len(words) == 3 or (len(words) == 4 and words[1] == 0xffff)): - words = words[:-2] - encapsulated = inet_ntop4(packed_ip[-4:]) - # If we start or end with None, then add an additional : - if words[0] is None: - words = [None] + words - if words[-1] is None: - words += [None] - # Join up everything we've got using :s - return ":".join(["{0:x}".format(w) if w is not None else "" for w in words]) + encapsulated - - if address_family == socket.AF_INET: - return inet_ntop4(packed_ip) - elif address_family == socket.AF_INET6: - return inet_ntop6(packed_ip) +def inet_ntop(address_family: int, packed_ip: Union[List[int], Array]) -> str: + if address_family in [socket.AF_INET6, socket.AF_INET]: + return socket.inet_ntop(address_family, bytes(packed_ip)) raise socket.error("[Errno 97] Address family not supported by protocol") @@ -213,8 +163,7 @@ class _TCP_ENDPOINT(_TCP_LISTENER): def get_local_address(self): try: - inaddr = self.AddrInfo.dereference().Local.\ - pData.dereference().dereference() + inaddr = self.AddrInfo.dereference().Local.pData.dereference().dereference() return self._ipv4_or_ipv6(inaddr) @@ -223,8 +172,7 @@ class _TCP_ENDPOINT(_TCP_LISTENER): def get_remote_address(self): try: - inaddr = self.AddrInfo.dereference().\ - Remote.dereference() + inaddr = self.AddrInfo.dereference().Remote.dereference() return self._ipv4_or_ipv6(inaddr)