From 3bb8ddf089f0503884fcffa249b3082638411242 Mon Sep 17 00:00:00 2001 From: Frank Block Date: Thu, 11 Mar 2021 14:11:39 +0100 Subject: [PATCH 1/6] Temporary workaround for changes in transition PTE --- volatility3/framework/layers/intel.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/framework/layers/intel.py b/volatility3/framework/layers/intel.py index 89ffcdbaf..bd5e49a17 100644 --- a/volatility3/framework/layers/intel.py +++ b/volatility3/framework/layers/intel.py @@ -265,7 +265,7 @@ class Intel32e(Intel): _direct_metadata = collections.ChainMap({'architecture': 'Intel64'}, Intel._direct_metadata) _entry_format = " Date: Thu, 11 Mar 2021 14:14:33 +0100 Subject: [PATCH 2/6] Temporary workaround for changes in transition PTE --- volatility3/framework/symbols/windows/extensions/__init__.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index f402c800f..68660c41a 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -972,7 +972,7 @@ class CONTROL_AREA(objects.StructType): # If the entry is not a valid physical address then see if it is in transition. elif mmpte.u.Trans.Transition == 1: - physoffset = mmpte.u.Trans.PageFrameNumber << 12 + physoffset = (mmpte.u.Trans.PageFrameNumber &~ (0b1111 << 32)) << 12 yield physoffset, file_offset, self.PAGE_SIZE # Go to the next PTE entry From 085aacc86a6e5f7884cf171a3a56178131210936 Mon Sep 17 00:00:00 2001 From: Frank Block Date: Thu, 11 Mar 2021 23:24:21 +0100 Subject: [PATCH 3/6] Moved new _maxphyaddr to WindowsIntel32e --- volatility3/framework/layers/intel.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/volatility3/framework/layers/intel.py b/volatility3/framework/layers/intel.py index bd5e49a17..296ea36ca 100644 --- a/volatility3/framework/layers/intel.py +++ b/volatility3/framework/layers/intel.py @@ -265,7 +265,7 @@ class Intel32e(Intel): _direct_metadata = collections.ChainMap({'architecture': 'Intel64'}, Intel._direct_metadata) _entry_format = " Tuple[int, int, str]: return self._translate_swap(self, offset, self._bits_per_register // 2) From 5d55bcfa52c993b1ef7a953dc16dfced1c7e98d2 Mon Sep 17 00:00:00 2001 From: Frank Block Date: Thu, 11 Mar 2021 23:33:39 +0100 Subject: [PATCH 4/6] Adjusted bit operation for PFN calculation --- volatility3/framework/symbols/windows/extensions/__init__.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index 68660c41a..bf054a91b 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -972,7 +972,8 @@ class CONTROL_AREA(objects.StructType): # If the entry is not a valid physical address then see if it is in transition. elif mmpte.u.Trans.Transition == 1: - physoffset = (mmpte.u.Trans.PageFrameNumber &~ (0b1111 << 32)) << 12 + # Strips the bit flag in 'PageFrameNumber' for pages in transition state + physoffset = (mmpte.u.Trans.PageFrameNumber & (( 1 << 33 ) - 1 ) ) << 12 yield physoffset, file_offset, self.PAGE_SIZE # Go to the next PTE entry From 3e04b347cd08c1b31b2b2b8a48422dbac5e83031 Mon Sep 17 00:00:00 2001 From: Frank Block Date: Thu, 11 Mar 2021 23:54:03 +0100 Subject: [PATCH 5/6] Added Comment/TODO for transition state issue See https://github.com/volatilityfoundation/volatility3/pull/475 --- volatility3/framework/layers/intel.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/volatility3/framework/layers/intel.py b/volatility3/framework/layers/intel.py index 296ea36ca..94b15d3a0 100644 --- a/volatility3/framework/layers/intel.py +++ b/volatility3/framework/layers/intel.py @@ -329,6 +329,10 @@ class WindowsIntelPAE(WindowsMixin, IntelPAE): class WindowsIntel32e(WindowsMixin, Intel32e): + # TODO: Fix appropriately in a future release. + # Currently just a temprorary workaround to deal with custom bit flag + # in the PFN field for pages in transition state. + # See https://github.com/volatilityfoundation/volatility3/pull/475 _maxphyaddr = 45 def _translate(self, offset: int) -> Tuple[int, int, str]: From 9c1603e37259b1472ea6bb98948d643542eee0f5 Mon Sep 17 00:00:00 2001 From: Frank Block Date: Thu, 11 Mar 2021 23:55:37 +0100 Subject: [PATCH 6/6] Added Comment/TODO for transition state issue See https://github.com/volatilityfoundation/volatility3/pull/475 --- .../framework/symbols/windows/extensions/__init__.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index bf054a91b..997175fba 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -972,8 +972,12 @@ class CONTROL_AREA(objects.StructType): # If the entry is not a valid physical address then see if it is in transition. elif mmpte.u.Trans.Transition == 1: - # Strips the bit flag in 'PageFrameNumber' for pages in transition state + # TODO: Fix appropriately in a future release. + # Currently just a temprorary workaround to deal with custom bit flag + # in the PFN field for pages in transition state. + # See https://github.com/volatilityfoundation/volatility3/pull/475 physoffset = (mmpte.u.Trans.PageFrameNumber & (( 1 << 33 ) - 1 ) ) << 12 + yield physoffset, file_offset, self.PAGE_SIZE # Go to the next PTE entry