From 99672cbe759f22ff0518014a8c93d05bc2d188ca Mon Sep 17 00:00:00 2001 From: Paul Kermann Date: Mon, 15 Aug 2022 15:27:19 +0300 Subject: [PATCH 1/8] improv commit --- volatility3/framework/symbols/windows/pdbutil.py | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/volatility3/framework/symbols/windows/pdbutil.py b/volatility3/framework/symbols/windows/pdbutil.py index 430ad6a30..9f83ad973 100644 --- a/volatility3/framework/symbols/windows/pdbutil.py +++ b/volatility3/framework/symbols/windows/pdbutil.py @@ -253,7 +253,8 @@ class PDBUtility(interfaces.configuration.VersionableInterface): pdb_names: List[bytes], progress_callback: constants.ProgressCallback = None, start: Optional[int] = None, - end: Optional[int] = None) -> Generator[Dict[str, Optional[Union[bytes, str, int]]], None, None]: + end: Optional[int] = None, + maximum_invalid_count: int = 100) -> Generator[Dict[str, Optional[Union[bytes, str, int]]], None, None]: """Scans through `layer_name` at `ctx` looking for RSDS headers that indicate one of four common pdb kernel names (as listed in `self.pdb_names`) and returns the tuple (GUID, age, pdb_name, @@ -278,10 +279,15 @@ class PDBUtility(interfaces.configuration.VersionableInterface): sections = [(start, end - start)]): mz_offset = None sig_pfn = signature_offset // page_size + current_invalid_counter = 0 for i in range(sig_pfn, min_pfn, -1): - if not ctx.layers[layer_name].is_valid(i * page_size, 2): + if current_invalid_counter > maximum_invalid_count: break + + if not ctx.layers[layer_name].is_valid(i * page_size, 2): + current_invalid_counter += 1 + continue data = ctx.layers[layer_name].read(i * page_size, 2) if data == b'MZ': From afb17dfac8ef35950803e549bb127f920ae7eef0 Mon Sep 17 00:00:00 2001 From: Paul Kermann Date: Wed, 24 Aug 2022 14:14:50 +0300 Subject: [PATCH 2/8] use the maximum_invalid_count --- volatility3/framework/automagic/pdbscan.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/volatility3/framework/automagic/pdbscan.py b/volatility3/framework/automagic/pdbscan.py index 5cbdbfe0e..0cb01485e 100644 --- a/volatility3/framework/automagic/pdbscan.py +++ b/volatility3/framework/automagic/pdbscan.py @@ -212,7 +212,8 @@ class KernelPDBScanner(interfaces.automagic.AutomagicInterface): start = start_scan_address, page_size = vlayer.page_size, pdb_names = kernel_pdb_names, - progress_callback = progress_callback) + progress_callback = progress_callback, + maximum_invalid_count = constants.windows.PE_MAX_EXTRACTION_SIZE // 0x1000) for kernel in kernels: valid_kernel = test_kernel(physical_layer_name, virtual_layer_name, kernel) if valid_kernel is not None: From 26d15a3ad5069a99702c2d672d8d10c68f64f0b6 Mon Sep 17 00:00:00 2001 From: Paul Kermann Date: Wed, 31 Aug 2022 09:40:22 +0300 Subject: [PATCH 3/8] code review --- volatility3/framework/automagic/pdbscan.py | 3 +-- volatility3/framework/symbols/windows/pdbutil.py | 8 ++++++++ 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/volatility3/framework/automagic/pdbscan.py b/volatility3/framework/automagic/pdbscan.py index 0cb01485e..5cbdbfe0e 100644 --- a/volatility3/framework/automagic/pdbscan.py +++ b/volatility3/framework/automagic/pdbscan.py @@ -212,8 +212,7 @@ class KernelPDBScanner(interfaces.automagic.AutomagicInterface): start = start_scan_address, page_size = vlayer.page_size, pdb_names = kernel_pdb_names, - progress_callback = progress_callback, - maximum_invalid_count = constants.windows.PE_MAX_EXTRACTION_SIZE // 0x1000) + progress_callback = progress_callback) for kernel in kernels: valid_kernel = test_kernel(physical_layer_name, virtual_layer_name, kernel) if valid_kernel is not None: diff --git a/volatility3/framework/symbols/windows/pdbutil.py b/volatility3/framework/symbols/windows/pdbutil.py index 9f83ad973..311cc6451 100644 --- a/volatility3/framework/symbols/windows/pdbutil.py +++ b/volatility3/framework/symbols/windows/pdbutil.py @@ -264,6 +264,14 @@ class PDBUtility(interfaces.configuration.VersionableInterface): The UI should always provide the user an opportunity to specify the appropriate types and PDB values themselves + Args: + layer_name: The layer name to scan + page_size: Size of page constant + pdb_names: List of pdb names to scan + progress_callback: Means of providing the user with feedback during long processes + start: Start address to start scanning from the pdb_names + end: Minimum address to scan the pdb_names + maximum_invalid_count: Amount of pages that can be invalid during scanning before aborting signature search """ min_pfn = 0 From 2a3212e77b74d0ab0d8c3aeaebea3d0a55866a29 Mon Sep 17 00:00:00 2001 From: Paul Kermann Date: Wed, 31 Aug 2022 10:26:38 +0300 Subject: [PATCH 4/8] remove whitespace --- volatility3/framework/symbols/windows/pdbutil.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/pdbutil.py b/volatility3/framework/symbols/windows/pdbutil.py index 311cc6451..8b58442cc 100644 --- a/volatility3/framework/symbols/windows/pdbutil.py +++ b/volatility3/framework/symbols/windows/pdbutil.py @@ -292,7 +292,7 @@ class PDBUtility(interfaces.configuration.VersionableInterface): for i in range(sig_pfn, min_pfn, -1): if current_invalid_counter > maximum_invalid_count: break - + if not ctx.layers[layer_name].is_valid(i * page_size, 2): current_invalid_counter += 1 continue From e3c548686c59abadddfc135ba5c9f3ecd32adc9d Mon Sep 17 00:00:00 2001 From: ikelos Date: Sun, 13 Nov 2022 12:16:27 +0000 Subject: [PATCH 5/8] Create codeql.yml Shift from LGTM.com over to built-in github codeql analysis. --- .github/workflows/codeql.yml | 74 ++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) create mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 000000000..fcefcfa96 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,74 @@ +# For most projects, this workflow file will not need changing; you simply need +# to commit it to your repository. +# +# You may wish to alter this file to override the set of languages analyzed, +# or to provide custom queries or build logic. +# +# ******** NOTE ******** +# We have attempted to detect the languages in your repository. Please check +# the `language` matrix defined below to confirm you have the correct set of +# supported CodeQL languages. +# +name: "CodeQL" + +on: + push: + branches: [ "develop" ] + pull_request: + # The branches below must be a subset of the branches above + branches: [ "develop" ] + schedule: + - cron: '16 8 * * 0' + +jobs: + analyze: + name: Analyze + runs-on: ubuntu-latest + permissions: + actions: read + contents: read + security-events: write + + strategy: + fail-fast: false + matrix: + language: [ 'python' ] + # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ] + # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support + + steps: + - name: Checkout repository + uses: actions/checkout@v3 + + # Initializes the CodeQL tools for scanning. + - name: Initialize CodeQL + uses: github/codeql-action/init@v2 + with: + languages: ${{ matrix.language }} + # If you wish to specify custom queries, you can do so here or in a config file. + # By default, queries listed here will override any specified in a config file. + # Prefix the list here with "+" to use these queries and those in the config file. + + # Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs + # queries: security-extended,security-and-quality + + + # Autobuild attempts to build any compiled languages (C/C++, C#, Go, or Java). + # If this step fails, then you should remove it and run the build manually (see below) + - name: Autobuild + uses: github/codeql-action/autobuild@v2 + + # â„šī¸ Command-line programs to run using the OS shell. + # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun + + # If the Autobuild fails above, remove it and uncomment the following three lines. + # modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance. + + # - run: | + # echo "Run, Build Application using script" + # ./location_of_script_within_repo/buildscript.sh + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v2 + with: + category: "/language:${{matrix.language}}" From 297e1c9e81b8e7f415ce370e2fff148e281955a6 Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Sun, 13 Nov 2022 12:56:30 +0000 Subject: [PATCH 6/8] Include code quality alerts in CodeQL scans --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index fcefcfa96..72bba07aa 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -50,7 +50,7 @@ jobs: # Prefix the list here with "+" to use these queries and those in the config file. # Details on CodeQL's query packs refer to : https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs - # queries: security-extended,security-and-quality + queries: security-and-quality # ,security-extended # Autobuild attempts to build any compiled languages (C/C++, C#, Go, or Java). From 3f5fd3502d8cfcd97816cd058049b04a9951a54a Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Sun, 13 Nov 2022 13:34:39 +0000 Subject: [PATCH 7/8] Infra: Update the bug_report template to favour text over screenshots --- .github/ISSUE_TEMPLATE/bug_report.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md index 3a0cce8cc..2ccd4713c 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.md +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -23,8 +23,10 @@ Steps to reproduce the behavior: **Expected behavior** A clear and concise description of what you expected to happen. -**Screenshots** -If applicable, add screenshots to help explain your problem. +**Example output** +Please copy and paste the text demonstrating the issue, ideally with verbose output turned on (`vol.py -vvv ...`). + +Text is preferred to screenshots for searching and to talk about specific parts of the output. **Additional information** Add any other information about the problem here. From 324df0927534fd48fa61835c499bd0583b60c1cf Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Sun, 13 Nov 2022 13:46:59 +0000 Subject: [PATCH 8/8] Core: Fix code scanning warnings notes --- volatility3/framework/objects/__init__.py | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/volatility3/framework/objects/__init__.py b/volatility3/framework/objects/__init__.py index eedd22bb2..4334f9d74 100644 --- a/volatility3/framework/objects/__init__.py +++ b/volatility3/framework/objects/__init__.py @@ -611,12 +611,10 @@ class Array(interfaces.objects.ObjectInterface, collections.abc.Sequence): @overload - def __getitem__(self, i: int) -> interfaces.objects.Template: - ... + def __getitem__(self, i: int) -> interfaces.objects.Template: ... @overload - def __getitem__(self, s: slice) -> List[interfaces.objects.Template]: - ... + def __getitem__(self, s: slice) -> List[interfaces.objects.Template]: ... def __getitem__(self, i): """Returns the i-th item from the array."""