Fix a logging on add_process_layer exceptions.

There were a number of issues with commit 3df5e995 that was applied in
haste (notably, that exceptions wasn't imported in several cases, which
would break the code if it were ever run).

We now give debugging output when a process can't be constructed and
provide as much available information as possible.

Two unused lines were also removed from verinfo.
This commit is contained in:
Mike Auty
2019-11-03 23:15:38 +00:00
committed by ikelos
parent 73aa73f30e
commit ee31ece006
9 changed files with 64 additions and 32 deletions
@@ -6,7 +6,7 @@ import logging
import re
from typing import Dict, Generator, List, Set, Tuple
from volatility.framework import interfaces, renderers
from volatility.framework import interfaces, renderers, exceptions
from volatility.framework.configuration import requirements
from volatility.framework.layers import intel, resources, linear
from volatility.framework.renderers import format_hints
@@ -95,9 +95,13 @@ class Strings(interfaces.plugins.PluginInterface):
for process in pslist.PsList.list_processes(self.context, self.config['primary'],
self.config['nt_symbols']):
proc_id = "Unknown"
try:
proc_id = process.UniqueProcessId
proc_layer_name = process.add_process_layer()
except exceptions.InvalidAddressException:
except exceptions.InvalidAddressException as excp:
vollog.debug("Process {}: invalid address {} in layer {}".format(
proc_id, excp.invalid_address, excp.layer_name))
continue
proc_layer = self.context.layers[proc_layer_name]