mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 05:24:52 +02:00
yield UnreadableValues when key not found, and set default RootCell on exception
This commit is contained in:
@@ -5,6 +5,7 @@ from volatility.framework import constants, exceptions, interfaces, objects
|
||||
from volatility.framework.configuration import requirements
|
||||
from volatility.framework.configuration.requirements import IntRequirement
|
||||
from volatility.framework.interfaces.configuration import TranslationLayerRequirement
|
||||
from volatility.framework.exceptions import SwappedInvalidAddressException
|
||||
from volatility.framework.symbols import intermed
|
||||
from volatility.plugins.windows import pslist
|
||||
|
||||
@@ -78,7 +79,10 @@ class RegistryHive(interfaces.layers.TranslationLayerInterface):
|
||||
@property
|
||||
def root_cell_offset(self) -> int:
|
||||
"""Returns the offset for the root cell in this hive"""
|
||||
if self._base_block.Length <= 0:
|
||||
try:
|
||||
if self._base_block.Length <= 0:
|
||||
return 0x20
|
||||
except SwappedInvalidAddressException:
|
||||
return 0x20
|
||||
return self._base_block.RootCell
|
||||
|
||||
|
||||
@@ -103,16 +103,35 @@ class PrintKey(plugins.PluginInterface):
|
||||
|
||||
# Walk it
|
||||
if 'key' in self.config:
|
||||
node_path = None
|
||||
try:
|
||||
node_path = hive.get_key(self.config['key'], return_list=True)
|
||||
except KeyError:
|
||||
vollog.debug("Key {} not found in Hive at offset {}.".format(self.config['key'], hex(hive_offset)))
|
||||
vollog.debug("Key '{}' not found in Hive at offset {}.".format(self.config['key'], hex(hive_offset)))
|
||||
result = (0,
|
||||
(renderers.UnreadableValue(),
|
||||
renderers.format_hints.Hex(hive.hive_offset),
|
||||
"Key",
|
||||
self.config['key'],
|
||||
renderers.UnreadableValue(),
|
||||
renderers.UnreadableValue(),
|
||||
renderers.UnreadableValue()))
|
||||
yield result
|
||||
continue
|
||||
else:
|
||||
node_path = [hive.get_node(hive.root_cell_offset)]
|
||||
yield from self.hive_walker(hive, node_path)
|
||||
except exceptions.PagedInvalidAddressException as excp:
|
||||
vollog.debug("Invalid address identified in Hive: {}".format(hex(excp.invalid_address)))
|
||||
result = (0,
|
||||
(renderers.UnreadableValue(),
|
||||
renderers.format_hints.Hex(hive.hive_offset),
|
||||
"Key",
|
||||
self.config['key'],
|
||||
renderers.UnreadableValue(),
|
||||
renderers.UnreadableValue(),
|
||||
renderers.UnreadableValue()))
|
||||
yield result
|
||||
|
||||
def run(self):
|
||||
|
||||
|
||||
Reference in New Issue
Block a user