diff --git a/volatility/framework/plugins/mac/pslist.py b/volatility/framework/plugins/mac/pslist.py index 14f768c9e..0f9bab9e9 100644 --- a/volatility/framework/plugins/mac/pslist.py +++ b/volatility/framework/plugins/mac/pslist.py @@ -164,7 +164,7 @@ class PsList(interfaces.plugins.PluginInterface): try: proc = task.bsd_info.dereference().cast("proc") - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: continue if kernel_layer.is_valid(proc.vol.offset, proc.vol.size) and not filter_func(proc): @@ -205,7 +205,7 @@ class PsList(interfaces.plugins.PluginInterface): # it is expected that many won't be initialized try: pgrp = proc_list.lh_first - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: continue seen_pgrps = set() @@ -217,7 +217,7 @@ class PsList(interfaces.plugins.PluginInterface): # nothing can be done if this list pointer is invalid, so move on try: p = pgrp.pg_members.lh_first - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: break seen_pg = set() @@ -229,11 +229,11 @@ class PsList(interfaces.plugins.PluginInterface): try: p = p.p_pglist.le_next - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: break try: pgrp = pgrp.pg_hash.le_next - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: break def run(self): diff --git a/volatility/framework/symbols/mac/extensions/__init__.py b/volatility/framework/symbols/mac/extensions/__init__.py index 0235fba31..1d1e24d34 100644 --- a/volatility/framework/symbols/mac/extensions/__init__.py +++ b/volatility/framework/symbols/mac/extensions/__init__.py @@ -444,12 +444,12 @@ class ifnet(objects.StructType): if self.has_member("if_lladdr"): try: val = self.if_lladdr.ifa_addr.dereference().cast("sockaddr_dl") - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: val = None else: try: val = self.if_addrhead.tqh_first.ifa_addr.dereference().cast("sockaddr_dl") - except exceptions.PagedInvalidAddressException: + except exceptions.InvalidAddressException: val = None return val