From ee31ece0062ce762ed38f6d0a1c54e9f1cd37970 Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Sun, 3 Nov 2019 23:10:50 +0000 Subject: [PATCH] Fix a logging on add_process_layer exceptions. There were a number of issues with commit 3df5e995 that was applied in haste (notably, that exceptions wasn't imported in several cases, which would break the code if it were ever run). We now give debugging output when a process can't be constructed and provide as much available information as possible. Two unused lines were also removed from verinfo. --- .../framework/plugins/windows/cmdline.py | 10 ++++++++-- .../framework/plugins/windows/dlldump.py | 10 +++++++--- .../framework/plugins/windows/malfind.py | 11 +++++++++-- .../framework/plugins/windows/moddump.py | 14 +++++++------- .../framework/plugins/windows/procdump.py | 19 ++++++++++--------- .../framework/plugins/windows/strings.py | 8 ++++++-- .../framework/plugins/windows/svcscan.py | 8 ++++++-- .../framework/plugins/windows/vaddump.py | 6 +++++- .../framework/plugins/windows/verinfo.py | 10 ++++++---- 9 files changed, 64 insertions(+), 32 deletions(-) diff --git a/volatility/framework/plugins/windows/cmdline.py b/volatility/framework/plugins/windows/cmdline.py index a883f4379..932140680 100644 --- a/volatility/framework/plugins/windows/cmdline.py +++ b/volatility/framework/plugins/windows/cmdline.py @@ -1,7 +1,7 @@ # This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # - +import logging from typing import List from volatility.framework import constants, exceptions, renderers, interfaces @@ -9,6 +9,8 @@ from volatility.framework.configuration import requirements from volatility.framework.objects import utility from volatility.plugins.windows import pslist +vollog = logging.getLogger(__name__) + class CmdLine(interfaces.plugins.PluginInterface): """Lists process command line arguments.""" @@ -31,9 +33,13 @@ class CmdLine(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue try: diff --git a/volatility/framework/plugins/windows/dlldump.py b/volatility/framework/plugins/windows/dlldump.py index 38484556c..71c5277e3 100644 --- a/volatility/framework/plugins/windows/dlldump.py +++ b/volatility/framework/plugins/windows/dlldump.py @@ -6,7 +6,7 @@ import logging import ntpath from typing import List -from volatility.framework import interfaces, constants +from volatility.framework import interfaces, constants, exceptions from volatility.framework import renderers from volatility.framework.configuration import requirements from volatility.framework.objects import utility @@ -53,10 +53,14 @@ class DllDump(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) - + + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue for vad in vadinfo.VadInfo.list_vads(proc, filter_func = filter_func): diff --git a/volatility/framework/plugins/windows/malfind.py b/volatility/framework/plugins/windows/malfind.py index d6e2d1eb0..f4e196242 100644 --- a/volatility/framework/plugins/windows/malfind.py +++ b/volatility/framework/plugins/windows/malfind.py @@ -1,15 +1,18 @@ # This file is Copyright 2019 Volatility Foundation and licensed under the Volatility Software License 1.0 # which is available at https://www.volatilityfoundation.org/license/vsl-v1.0 # +import logging from typing import Iterable, Tuple -from volatility.framework import interfaces, symbols +from volatility.framework import interfaces, symbols, exceptions from volatility.framework import renderers from volatility.framework.configuration import requirements from volatility.framework.objects import utility from volatility.framework.renderers import format_hints from volatility.plugins.windows import pslist, vadinfo +vollog = logging.getLogger(__name__) + class Malfind(interfaces.plugins.PluginInterface): """Lists process memory ranges that potentially contain injected code.""" @@ -73,9 +76,13 @@ class Malfind(interfaces.plugins.PluginInterface): Returns: An iterable of VAD instances and the first 64 bytes of data containing in that region """ + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) return proc_layer = context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/moddump.py b/volatility/framework/plugins/windows/moddump.py index 32564ceb4..4a5ecc6f6 100644 --- a/volatility/framework/plugins/windows/moddump.py +++ b/volatility/framework/plugins/windows/moddump.py @@ -5,14 +5,13 @@ import logging from typing import List, Generator, Iterable -from volatility.plugins.windows import pslist, modules - from volatility.framework import constants, exceptions, renderers from volatility.framework import interfaces from volatility.framework.configuration import requirements from volatility.framework.renderers import format_hints from volatility.framework.symbols import intermed from volatility.framework.symbols.windows.extensions import pe +from volatility.plugins.windows import pslist, modules vollog = logging.getLogger(__name__) @@ -60,12 +59,11 @@ class ModDump(interfaces.plugins.PluginInterface): layer_name = layer_name, symbol_table = symbol_table, filter_func = filter_func): + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: - continue - try: # create the session space object in the process' own layer. # not all processes have a valid session pointer. session_space = context.object(symbol_table + constants.BANG + "_MM_SESSION_SPACE", @@ -76,8 +74,10 @@ class ModDump(interfaces.plugins.PluginInterface): continue except exceptions.InvalidAddressException: - vollog.log(constants.LOGLEVEL_VVV, - "Process {} does not have a valid Session".format(proc.UniqueProcessId)) + vollog.log( + constants.LOGLEVEL_VVV, + "Process {} does not have a valid Session or a layer could not be constructed for it".format( + proc_id)) continue # save the layer if we haven't seen the session yet diff --git a/volatility/framework/plugins/windows/procdump.py b/volatility/framework/plugins/windows/procdump.py index 0ac09b1ab..dc2471143 100644 --- a/volatility/framework/plugins/windows/procdump.py +++ b/volatility/framework/plugins/windows/procdump.py @@ -42,13 +42,12 @@ class ProcDump(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) - - try: - proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: - continue + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId + proc_layer_name = proc.add_process_layer() + peb = self._context.object(self.config["nt_symbols"] + constants.BANG + "_PEB", layer_name = proc_layer_name, offset = proc.Peb) @@ -71,14 +70,16 @@ class ProcDump(interfaces.plugins.PluginInterface): result_text = "PE parsing error" except exceptions.SwappedInvalidAddressException as exp: - result_text = "Required memory at {0:#x} is inaccessible (swapped)".format(exp.invalid_address) + result_text = "Process {}: Required memory at {:#x} is inaccessible (swapped)".format( + proc_id, exp.invalid_address) except exceptions.PagedInvalidAddressException as exp: - result_text = "Required memory at {0:#x} is not valid (process exited?)".format(exp.invalid_address) + result_text = "Process {}: Required memory at {:#x} is not valid (process exited?)".format( + proc_id, exp.invalid_address) except exceptions.InvalidAddressException as exp: - result_text = "Required memory at {0:#x} is not valid (incomplete layer {1}?)".format( - exp.invalid_address, exp.layer_name) + result_text = "Process {}: Required memory at {:#x} is not valid (incomplete layer {}?)".format( + proc_id, exp.invalid_address, exp.layer_name) yield (0, (proc.UniqueProcessId, process_name, result_text)) diff --git a/volatility/framework/plugins/windows/strings.py b/volatility/framework/plugins/windows/strings.py index 696b0489f..e961e45c5 100644 --- a/volatility/framework/plugins/windows/strings.py +++ b/volatility/framework/plugins/windows/strings.py @@ -6,7 +6,7 @@ import logging import re from typing import Dict, Generator, List, Set, Tuple -from volatility.framework import interfaces, renderers +from volatility.framework import interfaces, renderers, exceptions from volatility.framework.configuration import requirements from volatility.framework.layers import intel, resources, linear from volatility.framework.renderers import format_hints @@ -95,9 +95,13 @@ class Strings(interfaces.plugins.PluginInterface): for process in pslist.PsList.list_processes(self.context, self.config['primary'], self.config['nt_symbols']): + proc_id = "Unknown" try: + proc_id = process.UniqueProcessId proc_layer_name = process.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format( + proc_id, excp.invalid_address, excp.layer_name)) continue proc_layer = self.context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/svcscan.py b/volatility/framework/plugins/windows/svcscan.py index 554c5b0a2..d020dd2f1 100644 --- a/volatility/framework/plugins/windows/svcscan.py +++ b/volatility/framework/plugins/windows/svcscan.py @@ -5,7 +5,7 @@ import logging from typing import List -from volatility.framework import interfaces, renderers, constants, symbols +from volatility.framework import interfaces, renderers, constants, symbols, exceptions from volatility.framework.configuration import requirements from volatility.framework.layers import scanners from volatility.framework.renderers import format_hints @@ -131,9 +131,13 @@ class SvcScan(interfaces.plugins.PluginInterface): symbol_table = self.config['nt_symbols'], filter_func = filter_func): + proc_id = "Unknown" try: + proc_id = task.UniqueProcessId proc_layer_name = task.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue layer = self.context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/vaddump.py b/volatility/framework/plugins/windows/vaddump.py index 922c9abda..2ba44d055 100644 --- a/volatility/framework/plugins/windows/vaddump.py +++ b/volatility/framework/plugins/windows/vaddump.py @@ -47,9 +47,13 @@ class VadDump(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) continue proc_layer = self.context.layers[proc_layer_name] diff --git a/volatility/framework/plugins/windows/verinfo.py b/volatility/framework/plugins/windows/verinfo.py index 52b391003..a6e4f186e 100644 --- a/volatility/framework/plugins/windows/verinfo.py +++ b/volatility/framework/plugins/windows/verinfo.py @@ -123,10 +123,14 @@ class VerInfo(interfaces.plugins.PluginInterface): # now go through the process and dll lists for proc in procs: + proc_id = "Unknown" try: + proc_id = proc.UniqueProcessId proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException: - continue + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) + continue for entry in proc.load_order_modules(): @@ -135,8 +139,6 @@ class VerInfo(interfaces.plugins.PluginInterface): except exceptions.InvalidAddressException: BaseDllName = renderers.UnreadableValue() - session_layer_name = moddump.ModDump.find_session_layer(self.context, session_layers, mod.DllBase) - (major, minor, product, build) = [renderers.NotAvailableValue()] * 4 try: (major, minor, product, build) = self.get_version_information(self._context, pe_table_name, proc_layer_name, entry.DllBase)