Add in a NativeSymbolTable validator.

This commit is contained in:
Mike Auty
2016-01-16 21:38:00 +00:00
parent 84815d204e
commit 78cd3c84c0
5 changed files with 22 additions and 7 deletions
+3
View File
@@ -7,6 +7,7 @@ import volatility.plugins
from volatility.cli import argparse_adapter
from volatility.framework import plugins, contexts
from volatility.framework.configuration import depresolver
from volatility.framework.configuration.depresolver import DependencyError
__author__ = 'mike'
@@ -53,6 +54,8 @@ class CommandLine(object):
if dldr.validate_dependencies(dependencies, context = ctx, path = config_path):
# Construct and run the plugin
plugin(ctx, config_path).run()
else:
raise DependencyError("Unable to validate all the dependencies, please check configuration parameters")
def main():
@@ -1,3 +1,5 @@
import logging
import volatility.framework as framework
import volatility.framework.validity as validity
from volatility.framework.interfaces import configuration
@@ -60,12 +62,16 @@ class DependencyResolver(validity.ValidityRoutines):
provider.fulfill(context, node.requirement, node_path)
break
else:
logging.debug("Unable to fulfill requirement " + repr(node.requirement))
return False
try:
value = context.config[node_path]
node.requirement.validate(value, context)
except BaseException as e:
except Exception as e:
if not node.requirement.optional:
logging.debug(
"Unable to fulfill non-optional requirement " + repr(node.requirement) +
" [" + str(e) + "]")
return False
return True
@@ -59,6 +59,12 @@ class SymbolRequirement(config_interface.ConstraintInterface):
raise IndexError((value or "") + " is not present in the symbol space")
class NativeSymbolRequirement(SymbolRequirement):
def validate(self, value, context):
if not isinstance(value, str):
raise TypeError("SymbolRequirement only accepts string labels")
class ChoiceRequirement(config_interface.RequirementInterface):
"""Allows one from a choice of strings"""
+1 -1
View File
@@ -79,7 +79,7 @@ class DataLayerInterface(configuration.ProviderInterface, validity.ValidityRouti
# Construct the layer
requirement_dict = node_config.data
print("Requirement_dict", cls, requirement_dict)
print("Requirement_dict", requirement_dict)
context.add_layer(cls(context, config_path, layer_name, **requirement_dict))
context.config[config_path] = layer_name
@@ -1,7 +1,7 @@
import importlib
import volatility.framework.configuration.requirements
from volatility.framework import interfaces
from volatility.framework.configuration import requirements
from volatility.framework.symbols import vtypes, native
from volatility.framework.symbols.windows import basic
@@ -13,6 +13,7 @@ class X86NativeSymbolProvider(interfaces.symbols.SymbolTableProviderInterface):
@classmethod
def fulfill(cls, context, requirement, config_path):
context.symbol_space.natives = native.x86NativeTable
context.config[config_path] = "natives"
class WindowsKernelSymbolProvider(interfaces.symbols.SymbolTableProviderInterface):
@@ -61,7 +62,6 @@ class XPSP2WindowsKernelSymbolProvider(WindowsKernelSymbolProvider):
@classmethod
def get_schema(cls):
return [volatility.framework.configuration.requirements.SymbolRequirement("natives",
description = "Native Symbols for x86",
constraints = {"type": "natives",
"architecture": "ia32"})]
return [requirements.NativeSymbolRequirement("natives", description = "Native Symbols for x86",
constraints = {"type": "natives",
"architecture": "ia32"})]