From b85c143af9f15b002af8acecb0e7b5d0d0542a4d Mon Sep 17 00:00:00 2001 From: Dave Lassalle Date: Fri, 15 Jun 2018 16:02:49 -0500 Subject: [PATCH] yield UnreadableValues when key not found, and set default RootCell on exception --- volatility/framework/layers/registry.py | 6 +++++- volatility/plugins/windows/printkey.py | 21 ++++++++++++++++++++- 2 files changed, 25 insertions(+), 2 deletions(-) diff --git a/volatility/framework/layers/registry.py b/volatility/framework/layers/registry.py index 948dfeee7..561e9da00 100644 --- a/volatility/framework/layers/registry.py +++ b/volatility/framework/layers/registry.py @@ -5,6 +5,7 @@ from volatility.framework import constants, exceptions, interfaces, objects from volatility.framework.configuration import requirements from volatility.framework.configuration.requirements import IntRequirement from volatility.framework.interfaces.configuration import TranslationLayerRequirement +from volatility.framework.exceptions import SwappedInvalidAddressException from volatility.framework.symbols import intermed from volatility.plugins.windows import pslist @@ -78,7 +79,10 @@ class RegistryHive(interfaces.layers.TranslationLayerInterface): @property def root_cell_offset(self) -> int: """Returns the offset for the root cell in this hive""" - if self._base_block.Length <= 0: + try: + if self._base_block.Length <= 0: + return 0x20 + except SwappedInvalidAddressException: return 0x20 return self._base_block.RootCell diff --git a/volatility/plugins/windows/printkey.py b/volatility/plugins/windows/printkey.py index ab3244a3f..7c24e13a5 100644 --- a/volatility/plugins/windows/printkey.py +++ b/volatility/plugins/windows/printkey.py @@ -103,16 +103,35 @@ class PrintKey(plugins.PluginInterface): # Walk it if 'key' in self.config: + node_path = None try: node_path = hive.get_key(self.config['key'], return_list=True) except KeyError: - vollog.debug("Key {} not found in Hive at offset {}.".format(self.config['key'], hex(hive_offset))) + vollog.debug("Key '{}' not found in Hive at offset {}.".format(self.config['key'], hex(hive_offset))) + result = (0, + (renderers.UnreadableValue(), + renderers.format_hints.Hex(hive.hive_offset), + "Key", + self.config['key'], + renderers.UnreadableValue(), + renderers.UnreadableValue(), + renderers.UnreadableValue())) + yield result continue else: node_path = [hive.get_node(hive.root_cell_offset)] yield from self.hive_walker(hive, node_path) except exceptions.PagedInvalidAddressException as excp: vollog.debug("Invalid address identified in Hive: {}".format(hex(excp.invalid_address))) + result = (0, + (renderers.UnreadableValue(), + renderers.format_hints.Hex(hive.hive_offset), + "Key", + self.config['key'], + renderers.UnreadableValue(), + renderers.UnreadableValue(), + renderers.UnreadableValue())) + yield result def run(self):