Merge branch 'volatilityfoundation:develop' into develop

This commit is contained in:
Donghyun Kim
2022-03-05 15:43:38 +09:00
committed by GitHub
2 changed files with 21 additions and 16 deletions
@@ -307,12 +307,15 @@ class MMVAD(MMVAD_SHORT):
try:
# this is for xp and 2003
if self.has_member("ControlArea"):
file_name = self.ControlArea.FilePointer.FileName.get_string()
filename_obj = self.ControlArea.FilePointer.FileName
# this is for vista through windows 7
else:
file_name = self.Subsection.ControlArea.FilePointer.dereference().cast(
"_FILE_OBJECT").FileName.get_string()
filename_obj = self.Subsection.ControlArea.FilePointer.dereference().cast(
"_FILE_OBJECT").FileName
if filename_obj.Length > 0:
file_name = filename_obj.get_string()
except exceptions.InvalidAddressException:
pass
@@ -902,8 +905,8 @@ class CONTROL_AREA(objects.StructType):
return False
# The first SubsectionBase should not be page aligned
#subsection = self.get_subsection()
#if subsection.SubsectionBase & self.PAGE_MASK == 0:
# subsection = self.get_subsection()
# if subsection.SubsectionBase & self.PAGE_MASK == 0:
# return False
except exceptions.InvalidAddressException:
return False
@@ -952,7 +955,7 @@ class CONTROL_AREA(objects.StructType):
subsection_offset = starting_sector * 0x200
# Similar to the check in is_valid(), make sure the SubsectionBase is not page aligned.
#if subsection.SubsectionBase & self.PAGE_MASK == 0:
# if subsection.SubsectionBase & self.PAGE_MASK == 0:
# break
ptecount = 0
@@ -983,8 +986,8 @@ class CONTROL_AREA(objects.StructType):
# Currently just a temporary workaround to deal with custom bit flag
# in the PFN field for pages in transition state.
# See https://github.com/volatilityfoundation/volatility3/pull/475
physoffset = (mmpte.u.Trans.PageFrameNumber & (( 1 << 33 ) - 1 ) ) << 12
physoffset = (mmpte.u.Trans.PageFrameNumber & ((1 << 33) - 1)) << 12
yield physoffset, file_offset, self.PAGE_SIZE
# Go to the next PTE entry
@@ -5,10 +5,10 @@
import enum
import logging
import struct
from typing import Optional, Iterable, Union
from typing import Iterable, Optional, Union
from volatility3.framework import constants, exceptions, objects, interfaces
from volatility3.framework.layers.registry import RegistryHive, RegistryInvalidIndex, RegistryFormatException
from volatility3.framework import constants, exceptions, interfaces, objects
from volatility3.framework.layers.registry import RegistryFormatException, RegistryHive, RegistryInvalidIndex
vollog = logging.getLogger(__name__)
@@ -76,7 +76,9 @@ class CMHIVE(objects.StructType):
for attr in ["FileFullPath", "FileUserName", "HiveRootPath"]:
try:
return getattr(self, attr).get_string()
name = getattr(self, attr)
if name.Length > 0:
return name.get_string()
except (AttributeError, exceptions.InvalidAddressException):
pass
@@ -269,7 +271,7 @@ class CM_KEY_VALUE(objects.StructType):
if self_type == RegValueTypes.REG_DWORD_BIG_ENDIAN:
if len(data) != struct.calcsize(">L"):
raise ValueError(f"Size of data does not match the type of registry value {self.get_name()}")
res, = struct.unpack(">L", data)
res, = struct.unpack(">L", data)
return res
if self_type == RegValueTypes.REG_QWORD:
if len(data) != struct.calcsize("<Q"):
@@ -277,9 +279,9 @@ class CM_KEY_VALUE(objects.StructType):
res, = struct.unpack("<Q", data)
return res
if self_type in [
RegValueTypes.REG_SZ, RegValueTypes.REG_EXPAND_SZ, RegValueTypes.REG_LINK, RegValueTypes.REG_MULTI_SZ,
RegValueTypes.REG_BINARY, RegValueTypes.REG_FULL_RESOURCE_DESCRIPTOR, RegValueTypes.REG_RESOURCE_LIST,
RegValueTypes.REG_RESOURCE_REQUIREMENTS_LIST
RegValueTypes.REG_SZ, RegValueTypes.REG_EXPAND_SZ, RegValueTypes.REG_LINK, RegValueTypes.REG_MULTI_SZ,
RegValueTypes.REG_BINARY, RegValueTypes.REG_FULL_RESOURCE_DESCRIPTOR, RegValueTypes.REG_RESOURCE_LIST,
RegValueTypes.REG_RESOURCE_REQUIREMENTS_LIST
]:
return data
if self_type == RegValueTypes.REG_NONE: