From b9adcb2b877588a1fb6316493fc277dd41a8c9dc Mon Sep 17 00:00:00 2001 From: iMHLv2 Date: Wed, 19 Jul 2017 17:10:49 +0000 Subject: [PATCH 1/2] move the hive name decision to _CMHIVE extension for hivelist (and other plugins in the future) --- volatility/framework/symbols/windows/__init__.py | 1 + .../symbols/windows/extensions/__init__.py | 16 +++++++++++++++- volatility/plugins/windows/hivelist.py | 7 +------ 3 files changed, 17 insertions(+), 7 deletions(-) diff --git a/volatility/framework/symbols/windows/__init__.py b/volatility/framework/symbols/windows/__init__.py index 74f1d2d3b..0261268e1 100644 --- a/volatility/framework/symbols/windows/__init__.py +++ b/volatility/framework/symbols/windows/__init__.py @@ -14,6 +14,7 @@ class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable): self.set_type_class('_LIST_ENTRY', extensions._LIST_ENTRY) self.set_type_class('_EPROCESS', extensions._EPROCESS) self.set_type_class('_UNICODE_STRING', extensions._UNICODE_STRING) + self.set_type_class('_CMHIVE', extensions._CMHIVE) @classmethod def get_requirements(cls): diff --git a/volatility/framework/symbols/windows/extensions/__init__.py b/volatility/framework/symbols/windows/extensions/__init__.py index 19253c474..c4f342836 100644 --- a/volatility/framework/symbols/windows/extensions/__init__.py +++ b/volatility/framework/symbols/windows/extensions/__init__.py @@ -4,7 +4,7 @@ import string from volatility.framework import interfaces from volatility.framework import objects - +from volatility.framework import exceptions # Keep these in a basic module, to prevent import cycles when symbol providers require them @@ -13,6 +13,20 @@ class _ETHREAD(objects.Struct): """Return the EPROCESS that owns this thread""" return self.ThreadsProcess.dereference(kernel_layer) +class _CMHIVE(objects.Struct): + def name(self): + """Determine a name for the hive. Note that some attributes + are unpredictably blank while others are populated, so we + check all possibilities and take the first one that's not empty""" + + for attr in ["FileFullPath", "FileUserName", "HiveRootPath"]: + if hasattr(self, attr): + try: + return getattr(self, attr).String + except exceptions.InvalidAddressException: + pass + + return None class _UNICODE_STRING(objects.Struct): @property diff --git a/volatility/plugins/windows/hivelist.py b/volatility/plugins/windows/hivelist.py index 2eacf2e9d..4901a98b6 100644 --- a/volatility/plugins/windows/hivelist.py +++ b/volatility/plugins/windows/hivelist.py @@ -21,13 +21,8 @@ class HiveList(plugins.PluginInterface): def _generator(self): for hive in self.list_hives(): - try: - FileFullPath = hive.FileFullPath.String - except exceptions.InvalidAddressException: - FileFullPath = "" - yield (0, (format_hints.Hex(hive.vol.offset), - FileFullPath)) + hive.name() or "")) def list_hives(self): """Lists all the hives in the primary layer""" From 770dba1f0a1c57c8529b0f0671d536ae527e6780 Mon Sep 17 00:00:00 2001 From: iMHLv2 Date: Wed, 19 Jul 2017 18:12:50 +0000 Subject: [PATCH 2/2] use @property and update pydoc for _CMHIVE.name. catch AttributeError instead of checking hasattr --- .../symbols/windows/extensions/__init__.py | 16 ++++++++-------- volatility/plugins/windows/hivelist.py | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/volatility/framework/symbols/windows/extensions/__init__.py b/volatility/framework/symbols/windows/extensions/__init__.py index c4f342836..ce0f33791 100644 --- a/volatility/framework/symbols/windows/extensions/__init__.py +++ b/volatility/framework/symbols/windows/extensions/__init__.py @@ -14,17 +14,17 @@ class _ETHREAD(objects.Struct): return self.ThreadsProcess.dereference(kernel_layer) class _CMHIVE(objects.Struct): + @property def name(self): - """Determine a name for the hive. Note that some attributes - are unpredictably blank while others are populated, so we - check all possibilities and take the first one that's not empty""" + """Determine a name for the hive. Note that some attributes are + unpredictably blank across different OS versions while others are populated, + so we check all possibilities and take the first one that's not empty""" for attr in ["FileFullPath", "FileUserName", "HiveRootPath"]: - if hasattr(self, attr): - try: - return getattr(self, attr).String - except exceptions.InvalidAddressException: - pass + try: + return getattr(self, attr).String + except (AttributeError, exceptions.InvalidAddressException): + pass return None diff --git a/volatility/plugins/windows/hivelist.py b/volatility/plugins/windows/hivelist.py index 4901a98b6..9cd1a0c04 100644 --- a/volatility/plugins/windows/hivelist.py +++ b/volatility/plugins/windows/hivelist.py @@ -22,7 +22,7 @@ class HiveList(plugins.PluginInterface): for hive in self.list_hives(): yield (0, (format_hints.Hex(hive.vol.offset), - hive.name() or "")) + hive.name or "")) def list_hives(self): """Lists all the hives in the primary layer"""