Merge pull request #1815 from ddogfoodd/fix-typos

fix: typos
This commit is contained in:
ikelos
2025-05-26 10:00:50 +01:00
committed by GitHub
36 changed files with 56 additions and 56 deletions
+1 -1
View File
@@ -339,7 +339,7 @@ if __name__ == "__main__":
"--vol3path",
type=str,
default=os.path.join(os.getcwd(), "volatility3"),
help="Path ot the volatility 3 directory",
help="Path to the volatility 3 directory",
)
parser.add_argument(
"--vol2path",
+2 -2
View File
@@ -49,7 +49,7 @@ def hex_bytes_as_text(value: bytes, width: int = 16) -> str:
output += "\n"
printables = ""
# Handle leftovers when the length is not mutiple of width
# Handle leftovers when the length is not a multiple of width
if printables:
padding = width - len(printables)
output += " " * padding
@@ -182,7 +182,7 @@ class LayerDataRenderer(CLITypeRenderer):
output += "\n"
printables = ""
# Handle leftovers when the length is not mutiple of width
# Handle leftovers when the length is not a multiple of width
if printables:
padding = self.width - len(printables)
output += " " * padding
+2 -2
View File
@@ -485,7 +485,7 @@ class Volshell(interfaces.plugins.PluginInterface):
return
if hasattr(volobject.vol, "members"):
# display the header for this object, if the orginal object was just a type string, display the type information
# display the header for this object, if the original object was just a type string, display the type information
struct_header = f'{" " * dereference_count}{volobject.vol.type_name} ({volobject.vol.size} bytes)'
if isinstance(object, str) and offset is None:
suffix = ":"
@@ -558,7 +558,7 @@ class Volshell(interfaces.plugins.PluginInterface):
)
else: # simple type with no members, only one line to print
# if the orginal object was just a type string, display the type information
# if the original object was just a type string, display the type information
if isinstance(object, str) and offset is None:
print(self._display_simple_type(volobject, include_value=False))
+1 -1
View File
@@ -218,4 +218,4 @@ def clear_cache(complete=True):
os.unlink(cache_filename)
os.unlink(os.path.join(constants.CACHE_PATH, constants.IDENTIFIERS_FILENAME))
except FileNotFoundError:
vollog.log(constants.LOGLEVEL_VVVV, "Attempting to clear a non-existant cache")
vollog.log(constants.LOGLEVEL_VVVV, "Attempting to clear a non-existent cache")
@@ -507,7 +507,7 @@ def load_cache_manager(cache_file: Optional[str] = None) -> CacheManagerInterfac
cache_file = os.path.join(constants.CACHE_PATH, constants.IDENTIFIERS_FILENAME)
# Different implementations of cache
if not os.path.exists(cache_file):
raise ValueError("Non-existant cache file provided")
raise ValueError("Non-existent cache file provided")
with open(cache_file, "rb") as fp:
header = fp.read(4)
if header not in [b"SQLi"]:
+1 -1
View File
@@ -287,7 +287,7 @@ class Module(interfaces.context.ModuleInterface):
symbol_name: Name of the symbol (within the module) to construct
native_layer_name: Name of the layer in which constructed objects are made (for pointers)
absolute: whether the symbol's address is absolute or relative to the module
object_type: Override for the type from the symobl to use (or if the symbol type is missing)
object_type: Override for the type from the symbol to use (or if the symbol type is missing)
"""
if constants.BANG not in symbol_name:
symbol_name = self.symbol_table_name + constants.BANG + symbol_name
+1 -1
View File
@@ -267,7 +267,7 @@ class ModuleInterface(interfaces.configuration.ConfigurableInterface):
symbol_name: The name of a symbol (that must be present in the module's symbol table). The symbol's associated type will be used to construct an object at the symbol's offset.
native_layer_name: The native layer for objects that reference a different layer (if not the default provided during module construction)
absolute: A boolean specifying whether the offset is absolute within the layer, or relative to the start of the module
object_type: Override for the type from the symobl to use (or if the symbol type is missing)
object_type: Override for the type from the symbol to use (or if the symbol type is missing)
Returns:
The constructed object
+1 -1
View File
@@ -136,7 +136,7 @@ class Intel(linear.LinearlyMappedLayer):
return bool(entry & (1 << 6))
def canonicalize(self, addr: int) -> int:
"""Canonicalizes an address by performing an appropiate sign extension on the higher addresses"""
"""Canonicalizes an address by performing an appropriate sign extension on the higher addresses"""
if self._bits_per_register <= self._maxvirtaddr:
return addr & self.address_mask
elif addr < (1 << self._maxvirtaddr - 1):
+1 -1
View File
@@ -152,7 +152,7 @@ def bytes_to_decoded_string(
"""
Args:
data: The `bytes` buffer containing the string of a string at offset 0
encoding: An encoding value for the encoding paramater of `bytes.decode`
encoding: An encoding value for the encoding parameter of `bytes.decode`
errors: An errors value for the errors parameter of `bytes.decode`
return_truncated: Dictates whether truncated strings should be returned or
if a ValueError should be thrown if a truncated (broken) string was decoded
+1 -1
View File
@@ -62,7 +62,7 @@ class LayerWriter(plugins.PluginInterface):
Args:
context: the context from which to read the memory layer
layer_name: the name of the layer to write out
preferred_name: a string with the preferred filename for hte file
preferred_name: a string with the preferred filename for the file
chunk_size: an optional size for the chunks that should be written (defaults to 0x500000)
open_method: class for creating FileHandler context managers
progress_callback: an optional function that takes a percentage and a string that displays output
@@ -29,7 +29,7 @@ class TaskData:
@dataclass
class CapabilitiesData:
"""Stores each set of capabilties for a task"""
"""Stores each set of capabilities for a task"""
cap_inheritable: interfaces.objects.ObjectInterface
cap_permitted: interfaces.objects.ObjectInterface
@@ -417,7 +417,7 @@ class NetfilterImp_to_4_3(AbstractNetfilter):
class NetfilterImp_4_3_to_4_9(AbstractNetfilter):
"""Netfilter hooks were added to network namepaces in 4.3.
"""Netfilter hooks were added to network namespaces in 4.3.
It is still implemented as a linked list of 'struct nf_hook_ops' type but inside a
network namespace. One linked list per protocol per hook type.
@@ -611,7 +611,7 @@ class NetfilterImp_4_16_to_latest(NetfilterImp_4_14_to_4_16):
class AbstractNetfilterNetDev(AbstractNetfilter):
"""Base class to handle the Netfilter NetDev hooks.
It won't be executed. It has some common functions to all Netfilter NetDev hook
implementions.
implementations.
Netfilter NetDev hooks are set per network device which belongs to a network
namespace.
@@ -48,7 +48,7 @@ class FtraceOpsFlags(Enum):
@dataclass
class ParsedFtraceOps:
"""Parsed ftrace_ops struct representation, containing a selection of forensics valuable
informations."""
information."""
ftrace_ops_offset: int
callback_symbol: str
@@ -21,7 +21,7 @@ vollog = logging.getLogger(__name__)
@dataclass
class ParsedTracepointFunc:
"""Parsed tracepoint_func struct, containing a selection of forensics valuable
informations."""
information."""
tracepoint_name: str
tracepoint_address: int
@@ -91,7 +91,7 @@ class VmaRegExScan(plugins.PluginInterface):
):
result_data = proc_layer.read(offset, self.MAXSIZE_DEFAULT, pad=True)
# reapply the regex in order to extact just the match
# reapply the regex in order to extract just the match
regex_result = re.match(regex_pattern, result_data)
if regex_result:
+1 -1
View File
@@ -56,7 +56,7 @@ class PsList(interfaces.plugins.PluginInterface):
"""Returns the list_tasks method based on the selector
Args:
method: Must be one fo the available methods in get_task_choices
method: Must be one of the available methods in get_task_choices
Returns:
list_tasks method for listing tasks
+1 -1
View File
@@ -56,7 +56,7 @@ class RegExScan(plugins.PluginInterface):
):
result_data = layer.read(offset, self.MAXSIZE_DEFAULT, pad=True)
# reapply the regex in order to extact just the match
# reapply the regex in order to extract just the match
regex_result = re.match(regex_pattern, result_data)
if regex_result:
+1 -1
View File
@@ -54,7 +54,7 @@ class PageStartScanner(interfaces.layers.ScannerInterface):
class Vmscan(plugins.PluginInterface):
"""Scans for Intel VT-d structues and generates VM volatility configs for them"""
"""Scans for Intel VT-d structures and generates VM volatility configs for them"""
_required_framework_version = (2, 2, 0)
_version = (1, 0, 0)
@@ -42,7 +42,7 @@ syscall_finder_type.__doc__ = """
This type is used to specify how malicious system call invocations should be found.
`get_syscall_target_address` is optionally used to extract the address containing the malicious 'syscall' instruction
`wants_syscall_inst` whether or not this method expects the 'syscall' instrunction directly within the malicious code block
`wants_syscall_inst` whether or not this method expects the 'syscall' instruction directly within the malicious code block
`rule` the opcode string to search for the malicious syscall instructions
`invalid_ops` instructions that only appear in invalid code blocks. Stops processing of the code block when encountered.
`termination_ops` instructions that are expected to be present in the code block and that stop processing
@@ -116,7 +116,7 @@ class DirectSystemCalls(interfaces.plugins.PluginInterface):
address: int,
) -> Optional[Tuple[str, "capstone._cs_insn"]]:
"""
Determines if the bytes starting at `data` represent a valid syscall instrunction invocation block
Determines if the bytes starting at `data` represent a valid syscall instruction invocation block
To maliciously invoke the system call instruction, malware must do each of the following:
@@ -85,7 +85,7 @@ class Threads(thrdscan.ThrdScan):
# previous methods for determining if a thread was a kernel thread
# such as bit fields and flags are not stable in Win10+
# so we check if the thread is from the kernel itself or one its child
# kernel processes (MemCompression, Regsitry, ...)
# kernel processes (MemCompression, Registry, ...)
if pid != 4 and ppid != 4:
continue
@@ -37,7 +37,7 @@ filter_modules_type = Dict[str, filter_module_info]
found_symbols_module = List[Tuple[str, int]]
found_symbols_type = Dict[str, found_symbols_module]
# used to hold informatin about a range (VAD or kernel module)
# used to hold information about a range (VAD or kernel module)
# (start address, size, file path)
range_type = Tuple[int, int, str]
ranges_type = List[range_type]
@@ -243,7 +243,7 @@ class PESymbols(interfaces.plugins.PluginInterface):
_required_framework_version = (2, 7, 0)
# 2.0.0 - changed signature of get_kernel_modules, get_all_vads_with_file_paths, addresses_for_process_symbols, get_process_modules
# 3.0.0 - find_symbols wil now throw a ValueError if the provided wanted symbol information does not follow the spec
# 3.0.0 - find_symbols will now throw a ValueError if the provided wanted symbol information does not follow the spec
_version = (3, 0, 0)
# used for special handling of the kernel PDB file. See later notes
@@ -649,7 +649,7 @@ class PESymbols(interfaces.plugins.PluginInterface):
and wanted_addresses_identifier not in wanted_symbols
):
vollog.warning(
"Invalid `wanted_symbols` sent to `find_symbols`. addresses and names keys both misssing."
"Invalid `wanted_symbols` sent to `find_symbols`. addresses and names keys both missing."
)
return
@@ -671,7 +671,7 @@ class PESymbols(interfaces.plugins.PluginInterface):
for value_index, wanted_value in enumerate(all_wanted):
symbol_value = symbol_getter(wanted_value)
if symbol_value:
# yield out deleteion key, deletion index, symbol name, symbol address
# yield out deletion key, deletion index, symbol name, symbol address
if symbol_key == wanted_names_identifier:
yield symbol_key, wanted_value, symbol_value
else:
@@ -118,7 +118,7 @@ class ProcessGhosting(interfaces.plugins.PluginInterface):
Args:
proc:
mapped_files: A dictionary mapping vad base addreses to the path and vad instance for the process
mapped_files: A dictionary mapping vad base addresses to the path and vad instance for the process
Return:
A Generator of tuples of the file object address, the delete pending state, delete on close state, base address of the VAD, and the path
@@ -355,7 +355,7 @@ class Hashdump(interfaces.plugins.PluginInterface):
@classmethod
def get_bootkey(cls, syshive: registry_layer.RegistryHive) -> Optional[bytes]:
"""
Returns the scrambled bootkey necesary to decrypt hashes
Returns the scrambled bootkey necessary to decrypt hashes
"""
cs = 1
lsa_base = f"ControlSet{cs:03}" + "\\Control\\Lsa"
@@ -602,7 +602,7 @@ def decode_sid(data: bytes) -> Optional[str]:
Decodes a windows SID from variable-length raw bytes
Returns the string representation of the SID if decoding was successful, or None
if the data could not be parsed due to an insufficent number of bytes.
if the data could not be parsed due to an insufficient number of bytes.
"""
try:
revision, subid_count, id_authority = struct.unpack(
@@ -817,7 +817,7 @@ class TaskTrigger:
_ = reader.read_u4() # timeout seconds
repetition_interval_secs = reader.read_u4()
_ = reader.read_u4() # reptition duration seconds
_ = reader.read_u4() # repetition duration seconds
_ = reader.read_u4() # repetition duration seconds 2
_ = reader.read_bool() # stop at duration end
@@ -236,7 +236,7 @@ class ShimcacheMem(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterf
2) Iterate over every 4/8 bytes (depending on OS bitness) in the .data
section and test for the following:
a) offset represents a valid RTL_AVL_TABLE object
b) RTL_AVL_TABLE is preceeded by an ERESOURCE object
b) RTL_AVL_TABLE is preceded by an ERESOURCE object
c) RTL_AVL_TABLE is followed by the beginning of the SHIM LRU list
:param context: The context to retrieve required elements (layers, symbol tables) from
@@ -129,7 +129,7 @@ class SuspiciousThreads(interfaces.plugins.PluginInterface):
):
yield (
vad_path,
"VAD at base address ({vad_base:#x}) hosting this thread maps an application executable that is not the process exectuable",
"VAD at base address ({vad_base:#x}) hosting this thread maps an application executable that is not the process executable",
)
def _enumerate_processes(
@@ -86,7 +86,7 @@ class VadRegExScan(plugins.PluginInterface):
):
result_data = proc_layer.read(offset, self.MAXSIZE_DEFAULT, pad=True)
# reapply the regex in order to extact just the match
# reapply the regex in order to extract just the match
regex_result = re.match(regex_pattern, result_data)
if regex_result:
+1 -1
View File
@@ -93,7 +93,7 @@ class Disassembly(interfaces.renderers.BasicType):
class LayerData(interfaces.renderers.BasicType):
"""Layer data
This requires the contex to be passed in, in case plugins want to use multiple contexts
This requires the context to be passed in, in case plugins want to use multiple contexts
and to ensure the TreeGrid interface doesn't change, since this would break all existing plugins
"""
@@ -515,7 +515,7 @@ class LinuxUtilities(interfaces.configuration.VersionableInterface):
vmlinux: interfaces.context.ModuleInterface,
) -> Optional[interfaces.objects.ObjectInterface]:
"""Cast a member of a structure out to the containing structure.
It mimicks the Linux kernel macro container_of() see include/linux.kernel.h
It mimics the Linux kernel macro container_of() see include/linux.kernel.h
Args:
addr: The pointer to the member.
@@ -984,9 +984,9 @@ class maple_tree(objects.StructType):
current_depth + 1,
)
else:
# unkown maple node type
# unknown maple node type
raise AttributeError(
f"Unkown Maple Tree node type {node_type} at offset {hex(pointer)}."
f"Unknown Maple Tree node type {node_type} at offset {hex(pointer)}."
)
@@ -2295,7 +2295,7 @@ class kernel_cap_t(kernel_cap_struct):
class Timespec64Abstract(abc.ABC):
"""Abstract class to handle all required timespec64 operations, convertions and
"""Abstract class to handle all required timespec64 operations, conversions and
adjustments."""
@classmethod
@@ -2391,7 +2391,7 @@ class Timespec64Abstract(abc.ABC):
class Timespec64Concrete(Timespec64Abstract):
"""Handle all required timespec64 operations, convertions and adjustments.
"""Handle all required timespec64 operations, conversions and adjustments.
This is used to dynamically create timespec64-like objects, each with its own variables
and the same methods as a timespec64 object extension.
"""
@@ -2402,7 +2402,7 @@ class Timespec64Concrete(Timespec64Abstract):
class timespec64(Timespec64Abstract, objects.StructType):
"""Handle all required timespec64 operations, convertions and adjustments.
"""Handle all required timespec64 operations, conversions and adjustments.
This works as an extension of the timespec64 object while maintaining the same methods
as a Timespec64Concrete object.
"""
@@ -2770,7 +2770,7 @@ class IDR(objects.StructType):
vmlinux = linux.LinuxUtilities.get_module_from_volobj_type(self._context, self)
if not vmlinux.get_type("idr_layer").has_member("layer"):
vollog.info(
"Unsupported IDR implementation, it should be a very very old kernel, probabably < 2.6"
"Unsupported IDR implementation, it should be a very very old kernel, probably < 2.6"
)
return None
@@ -65,7 +65,7 @@ class net_device(objects.StructType):
hwaddr = parent_layer.read(self.dev_addr, self.addr_len, pad=True)
except exceptions.InvalidAddressException:
vollog.debug(
f"Unable to read network inteface mac address from {self.dev_addr:#x}"
f"Unable to read network interface mac address from {self.dev_addr:#x}"
)
return None
@@ -255,10 +255,10 @@ class net_device(objects.StructType):
return None
def get_queue_length(self) -> int:
"""Return the netwrok device transmision qeueue length (qlen)
"""Return the network device transmission queue length (qlen)
Returns:
int: the netwrok device transmision qeueue length (qlen)
int: the network device transmission queue length (qlen)
"""
return self.tx_queue_len
@@ -121,7 +121,7 @@ class _KallsymsIO:
self._endian = endian
def read(self, size: int) -> bytes:
"""Return 'size' bytes from the current postion"""
"""Return 'size' bytes from the current position"""
layer = self._context.layers[self._layer_name]
buf = layer.read(offset=self._position, length=size)
self._position += size
@@ -21,7 +21,7 @@ from volatility3.framework.symbols.linux import extensions
vollog = logging.getLogger(__name__)
# This module is responsbile for producing an ELF file of a kernel module (LKM) loaded in memory
# This module is responsible for producing an ELF file of a kernel module (LKM) loaded in memory
# This extraction task is quite complicated as the Linux kernel discards the ELF header at load time
# Due to this, to support static analysis, we must create an ELF header and proper file based on the sections
# There are also several other significant complications that we must deal with when trying to extract an LKM
@@ -423,7 +423,7 @@ class ModuleExtract(interfaces.configuration.VersionableInterface):
)
if not data:
vollog.debug(
f"Coult not construct a symbol table for module at {module.vol.offset}. Cannot recover."
f"Could not construct a symbol table for module at {module.vol.offset}. Cannot recover."
)
return None, None, None
@@ -469,7 +469,7 @@ class ModuleExtract(interfaces.configuration.VersionableInterface):
e_shentsize_int = 64
header_size = 64
e_type = struct.pack("<H", 1) # relocateble
e_type = struct.pack("<H", 1) # relocatable
e_machine = struct.pack("<H", e_machine_int)
e_version = struct.pack("<I", 1)
e_entry = b"\x00" * int(
@@ -762,7 +762,7 @@ class ModuleExtract(interfaces.configuration.VersionableInterface):
# ndex into the string table
name_index += len(name) + 1
# concatanate the header and section bytes
# concatenate the header and section bytes
sections_headers += header_bytes
sections_data += section_data
@@ -418,7 +418,7 @@ class Modules(interfaces.configuration.VersionableInterface):
):
vollog.warning(
f"Module addresses aren't aligned to {module_address_alignment} bytes. "
"Switching to 1 byte aligment scan method."
"Switching to 1 byte alignment scan method."
)
module_address_alignment = 1
@@ -641,7 +641,7 @@ class Modules(interfaces.configuration.VersionableInterface):
kernel = context.modules[vmlinux_name]
# For arrays, recusively get the value of each member as the type can be different
# For arrays, recursively get the value of each member as the type can be different
if param_func == getters["param_array_get"]:
array = param.arr
@@ -862,7 +862,7 @@ class ModuleGathererKernel(ModuleGathererInterface):
) -> ModuleGathererInterface.gatherer_return_type:
"""
Returns a ModuleInfo instance that encodes the kernel
This is required to map function pointers to the kerenl executable
This is required to map function pointers to the kernel executable
"""
kernel = context.modules[kernel_module_name]
@@ -168,7 +168,7 @@ class SCREEN_INFORMATION(objects.StructType):
@param truncate: True if the empty rows at the
end (i.e. bottom) of the screen buffer should be
supressed.
suppressed.
"""
rows = []
@@ -146,7 +146,7 @@ class GUIExtensions(interfaces.configuration.VersionableInterface):
self, window, max_windows
) -> Generator[Tuple[interfaces.objects.ObjectInterface, str], None, None]:
"""
Recusively walks and yields the adjacent and child windows
Recursively walks and yields the adjacent and child windows
"""
seen_windows = set()
seen_children = set()