From a46c9d9d8ecf0a36352c672c2193227c59cd33c1 Mon Sep 17 00:00:00 2001 From: Eve Date: Fri, 29 Sep 2023 10:16:20 +0100 Subject: [PATCH 1/3] Linux: add padded read when getting magic for elf extension to help with smear and missing pages --- .../framework/symbols/linux/extensions/elf.py | 21 ++++++++++++------- 1 file changed, 14 insertions(+), 7 deletions(-) diff --git a/volatility3/framework/symbols/linux/extensions/elf.py b/volatility3/framework/symbols/linux/extensions/elf.py index 416a7e4d2..a05885a7b 100644 --- a/volatility3/framework/symbols/linux/extensions/elf.py +++ b/volatility3/framework/symbols/linux/extensions/elf.py @@ -33,14 +33,18 @@ class elf(objects.StructType): layer_name = self.vol.layer_name symbol_table_name = self.get_symbol_table_name() # We read the MAGIC: (0x0 to 0x4) 0x7f 0x45 0x4c 0x46 - magic = self._context.object( - symbol_table_name + constants.BANG + "unsigned long", - layer_name=layer_name, - offset=object_info.offset, - ) + magic = self._context.layers[layer_name].read(object_info.offset, 4, True) # Check validity - if magic != 0x464C457F: + if ( + magic[0] == 0x7F + and magic[1] == 0x45 # E + and magic[2] == 0x4C # L + and magic[3] == 0x46 # F + ): + self._valid_magic = True + else: + self._valid_magic = False return None # We need to read the EI_CLASS (0x4 offset) @@ -72,7 +76,10 @@ class elf(objects.StructType): """ Determine whether it is a valid object """ - return self._type_prefix is not None and self._hdr is not None + if self._valid_magic: + return self._type_prefix is not None and self._hdr is not None + else: + return False def __getattr__(self, name): # Just redirect to the corresponding header From 41a02fbf5b5bd860f35d53c7ed34a97bfa68f3cd Mon Sep 17 00:00:00 2001 From: Eve Date: Tue, 3 Oct 2023 07:13:28 +0100 Subject: [PATCH 2/3] Linux: use try/except in linux elf extension to catch paged and invalid addresses rather than crashing --- .../framework/symbols/linux/extensions/elf.py | 36 ++++++++++++------- 1 file changed, 24 insertions(+), 12 deletions(-) diff --git a/volatility3/framework/symbols/linux/extensions/elf.py b/volatility3/framework/symbols/linux/extensions/elf.py index a05885a7b..8b42b3075 100644 --- a/volatility3/framework/symbols/linux/extensions/elf.py +++ b/volatility3/framework/symbols/linux/extensions/elf.py @@ -3,9 +3,12 @@ # from typing import Dict, Tuple +import logging from volatility3.framework import constants -from volatility3.framework import objects, interfaces +from volatility3.framework import objects, interfaces, exceptions + +vollog = logging.getLogger(__name__) class elf(objects.StructType): @@ -33,20 +36,29 @@ class elf(objects.StructType): layer_name = self.vol.layer_name symbol_table_name = self.get_symbol_table_name() # We read the MAGIC: (0x0 to 0x4) 0x7f 0x45 0x4c 0x46 - magic = self._context.layers[layer_name].read(object_info.offset, 4, True) - - # Check validity - if ( - magic[0] == 0x7F - and magic[1] == 0x45 # E - and magic[2] == 0x4C # L - and magic[3] == 0x46 # F - ): - self._valid_magic = True - else: + try: + magic = self._context.object( + symbol_table_name + constants.BANG + "unsigned long", + layer_name=layer_name, + offset=object_info.offset, + ) + except ( + exceptions.PagedInvalidAddressException, + exceptions.InvalidAddressException, + ) as excp: + vollog.debug( + f"Unable to check magic bytes for ELF file at offset {hex(object_info.offset)} in layer {layer_name}: {excp}" + ) self._valid_magic = False return None + # Check validity + if magic != 0x464C457F: # e.g. ELF + self._valid_magic = False + return None + else: + self._valid_magic = True + # We need to read the EI_CLASS (0x4 offset) ei_class = self._context.object( symbol_table_name + constants.BANG + "unsigned char", From 5ab0e4f83f7feb5444ce8d691e58bf56e495db1a Mon Sep 17 00:00:00 2001 From: Eve Date: Tue, 14 Nov 2023 07:22:00 +0000 Subject: [PATCH 3/3] Linux: remove _valid_magic from linux elf extension, check for _type_prefix and _hdr attrs instead --- volatility3/framework/symbols/linux/extensions/elf.py | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/volatility3/framework/symbols/linux/extensions/elf.py b/volatility3/framework/symbols/linux/extensions/elf.py index 8b42b3075..629a05da5 100644 --- a/volatility3/framework/symbols/linux/extensions/elf.py +++ b/volatility3/framework/symbols/linux/extensions/elf.py @@ -49,15 +49,11 @@ class elf(objects.StructType): vollog.debug( f"Unable to check magic bytes for ELF file at offset {hex(object_info.offset)} in layer {layer_name}: {excp}" ) - self._valid_magic = False return None # Check validity if magic != 0x464C457F: # e.g. ELF - self._valid_magic = False return None - else: - self._valid_magic = True # We need to read the EI_CLASS (0x4 offset) ei_class = self._context.object( @@ -88,7 +84,7 @@ class elf(objects.StructType): """ Determine whether it is a valid object """ - if self._valid_magic: + if hasattr(self, "_type_prefix") and hasattr(self, "_hdr"): return self._type_prefix is not None and self._hdr is not None else: return False