From a4bbdfddedd95136f836d49256fc7a81cb7d194c Mon Sep 17 00:00:00 2001 From: Andrew Case Date: Sun, 9 Mar 2025 22:11:32 +0000 Subject: [PATCH 1/3] Make exception throwing consistent in the PDB gathering API. Avoid returning an empty symbol_table name when the PDB cannot be downloaded. --- volatility3/framework/plugins/windows/netstat.py | 4 ---- volatility3/framework/symbols/windows/pdbutil.py | 4 ++++ 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/volatility3/framework/plugins/windows/netstat.py b/volatility3/framework/plugins/windows/netstat.py index aaab4494c..655ef710a 100644 --- a/volatility3/framework/plugins/windows/netstat.py +++ b/volatility3/framework/plugins/windows/netstat.py @@ -649,10 +649,6 @@ class NetStat(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterface): vollog.error("Unable to locate symbols for the memory image's tcpip module") return - if not tcpip_symbol_table: - vollog.error("Unable to reconstruct symbol table for tcpip.sys") - return - for netw_obj in self.list_sockets( self.context, kernel.layer_name, diff --git a/volatility3/framework/symbols/windows/pdbutil.py b/volatility3/framework/symbols/windows/pdbutil.py index b5e8ca70a..c2084ea25 100644 --- a/volatility3/framework/symbols/windows/pdbutil.py +++ b/volatility3/framework/symbols/windows/pdbutil.py @@ -409,6 +409,10 @@ class PDBUtility(interfaces.configuration.VersionableInterface): _, symbol_table_name = cls._modtable_from_pdb( context, config_path, layer_name, pdb_name, module_offset, module_size ) + + if symbol_table_name is None: + raise exceptions.VolatilityException(f"Symbol table could not be reconstructed for module {pdb_name}") + return symbol_table_name @classmethod From 2a99a5378405992d1683841015d34eeff122b899 Mon Sep 17 00:00:00 2001 From: Andrew Case Date: Sun, 9 Mar 2025 22:17:39 +0000 Subject: [PATCH 2/3] Make exception throwing consistent in the PDB gathering API. Avoid returning an empty symbol_table name when the PDB cannot be downloaded. --- volatility3/framework/symbols/windows/pdbutil.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/pdbutil.py b/volatility3/framework/symbols/windows/pdbutil.py index c2084ea25..ea96b0bf8 100644 --- a/volatility3/framework/symbols/windows/pdbutil.py +++ b/volatility3/framework/symbols/windows/pdbutil.py @@ -411,7 +411,9 @@ class PDBUtility(interfaces.configuration.VersionableInterface): ) if symbol_table_name is None: - raise exceptions.VolatilityException(f"Symbol table could not be reconstructed for module {pdb_name}") + raise exceptions.VolatilityException( + f"Symbol table could not be reconstructed for module {pdb_name}" + ) return symbol_table_name From 897069c6d05cae414c3d42c72a4deeff3c77563f Mon Sep 17 00:00:00 2001 From: Andrew Case Date: Mon, 10 Mar 2025 16:27:49 +0000 Subject: [PATCH 3/3] Throw more specific exception --- volatility3/framework/symbols/windows/pdbutil.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/volatility3/framework/symbols/windows/pdbutil.py b/volatility3/framework/symbols/windows/pdbutil.py index ea96b0bf8..3c23eddb8 100644 --- a/volatility3/framework/symbols/windows/pdbutil.py +++ b/volatility3/framework/symbols/windows/pdbutil.py @@ -411,7 +411,7 @@ class PDBUtility(interfaces.configuration.VersionableInterface): ) if symbol_table_name is None: - raise exceptions.VolatilityException( + raise exceptions.SymbolSpaceError( f"Symbol table could not be reconstructed for module {pdb_name}" ) @@ -445,7 +445,7 @@ class PDBUtility(interfaces.configuration.VersionableInterface): ) if not guids: - raise exceptions.VolatilityException( + raise exceptions.SymbolSpaceError( f"Did not find GUID of {pdb_name} in module @ 0x{module_offset:x}!" )