From 93e66381ada476f2cc8fcc3a857c7d01290359a6 Mon Sep 17 00:00:00 2001 From: Analyst Date: Wed, 20 Mar 2019 11:53:26 -0500 Subject: [PATCH] use an alignmemt based on the cpu arch, not the pool header size this fixes an issue with pool scanning on win10 32-bit samples, because the size of a pool header increased to 16 bytes, but we still want 8 byte alignment on 32-bit machines --- volatility/framework/symbols/windows/extensions/__init__.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/volatility/framework/symbols/windows/extensions/__init__.py b/volatility/framework/symbols/windows/extensions/__init__.py index 1ebcf9dc2..8fe1127e3 100644 --- a/volatility/framework/symbols/windows/extensions/__init__.py +++ b/volatility/framework/symbols/windows/extensions/__init__.py @@ -70,7 +70,10 @@ class _POOL_HEADER(objects.Struct): # otherwise we have an executive object in the pool else: - alignment = pool_header_size + if symbols.symbol_table_is_64bit(self._context, symbol_table_name): + alignment = 16 + else: + alignment = 8 # FIXME: calculate and cache this max_optional_headers_length = 0x60