Commit Graph
5072 Commits
Author SHA1 Message Date
ikelosandGitHub 89d32df403 Merge pull request #1540 from volatilityfoundation/certificates_traceback
Windows: Certificates - handle uncaught RegistryFormatException
2025-01-10 19:54:00 +00:00
David McDonald a7661d45e7 Windows: Certificates - handle uncaught RegistryFormatException
Changes variable import to module import, and catches an unhandled
`RegistryFormatException` in certificates.py
2025-01-10 09:26:53 -06:00
ikelosandGitHub 803c4ec364 Merge pull request #1533 from j-t-1/typo
Change one letter of a typo
2025-01-09 23:42:39 +00:00
ikelosandGitHub c0d83de90d Merge pull request #1532 from volatilityfoundation/duplicated_module_docstrings
Linux: Fix copy-pasted module docstrings
2025-01-09 23:41:39 +00:00
ikelosandGitHub 77ebb428ba Merge pull request #1531 from j-t-1/conversion
Use in-place subtraction
2025-01-09 23:40:42 +00:00
j-t-1andGitHub 32cb6e11f6 Change one letter of a typo 2025-01-07 19:41:02 +00:00
David McDonald 43ac6c4d62 Fix copy-pasted module docstrings
This updates the module docstrings for 5 modules that duplicate the
docstring from the `proc` module. This was presumably the result of using
the `proc` module as a template for the others.
2025-01-07 10:24:46 -06:00
j-t-1andGitHub b5bc54cfae Use in-place subtraction
Also tweak comments.
2025-01-07 15:18:34 +00:00
ikelosandGitHub a98a23fa41 Merge pull request #1529 from j-t-1/cmdscan
Tiny comment changes
2025-01-05 22:20:05 +00:00
j-t-1andGitHub 94ec7d89c0 Tiny comment changes 2025-01-05 21:55:58 +00:00
ikelosandGitHub 429b006646 Merge pull request #1530 from j-t-1/case
Update case insensitive check
2025-01-05 21:42:27 +00:00
j-t-1andGitHub 8f4f576e93 Update case insensitive check
Update link and use casefold() instead of lower().
2025-01-05 21:09:15 +00:00
ikelosandGitHub a9e10a4b48 Merge pull request #1513 from volatilityfoundation/env_var_missing_exception_handler
Add missing exception handling in env var recovery. Prevent backtraces
2025-01-05 20:41:32 +00:00
ikelosandGitHub 4363539f7b Merge pull request #1510 from j-t-1/shim
Make f-string slightly more readable
2025-01-05 20:38:23 +00:00
j-t-1andGitHub ab60add993 Update case insensitive check
Update link and use casefold() instead of lower().
2025-01-05 17:14:21 +00:00
j-t-1andGitHub 5f1d318c71 Tiny comment changes 2025-01-05 13:39:00 +00:00
ikelosandGitHub a8c449aa0c Merge pull request #1521 from volatilityfoundation/linux_add_process_layer
Change add_process_layer to return None instead of throwing an except…
2025-01-04 19:16:41 +00:00
Andrew Case 8ba60a2aad Change add_process_layer to return None instead of throwing an exception as it was meant to be designed 2025-01-04 16:49:02 +00:00
Andrew Case 03049f7895 Add missing exception handling in env var recovery. Prevent backtraces 2025-01-03 18:40:52 +00:00
j-t-1andGitHub 32ca62bbb1 Make f-string slightly more readable 2025-01-03 15:20:35 +00:00
ikelosandGitHub cedc0b074a Merge pull request #1500 from volatilityfoundation/issue_1469_cachedump_exception
Exception handling in registry-related code
2025-01-03 00:24:50 +00:00
ikelosandGitHub 66eb16172e Merge pull request #1503 from volatilityfoundation/issues/kmsg-msglen
Linux: Fix kmsg unguarded read of msg.len
2025-01-03 00:23:23 +00:00
ikelosandGitHub 801c933824 Merge pull request #1506 from Abyss-W4tcher/page_class_multi_arch
Linux: ground work for multi-arch vmemmap_start calculation
2025-01-03 00:21:39 +00:00
ikelosandGitHub 1e2ca8fb75 Merge pull request #1508 from gcmoreira/linux_kmsg_fix_1502_1496_1364
linux: kmsg plugin: Fix f'string bug introduced in #1502
2025-01-03 00:08:33 +00:00
Gustavo Moreira d2bb5c9f31 linux: fix kmsg fstring bug introduced in #1502 2025-01-03 10:01:37 +11:00
Abyss Watcher b61ba66223 multi-architecture vmemmap_start calculation 2025-01-02 14:51:23 +01:00
Abyss Watcher 7278bb244f move get_flags_list at bottom 2025-01-02 14:47:18 +01:00
ikelosandGitHub dce5ff1f5c Merge pull request #1502 from volatilityfoundation/issues/issue1496
Linux: Fix kmsg f-strings
2025-01-02 11:36:29 +00:00
Mike Auty 97b93abe43 Linux: Remove unnecessary int cast 2025-01-02 11:26:21 +00:00
David McDonald c8e67e526a Convert ValueError to TypeError
All other methods in this class raise a `TypeError` if the hive was not
instantiated on a registry layer; this changes makes this method
consistent with the convention used in the others.

All `except` blocks checking for `ValueError` have been audited to
ensure that this doesn't break exception handling in existing code
within the framework. This also includes a minor version bump because:

1. RegistryHives are currently only instantiated one way, which is
   through the `hivelist` plugin. `hivelist` uses the correct layers when
   instantiating the hives.
2. Because there is currently a single source for registry hives, and
   it's unlikely that a hive from that source will ever be created on
   the wrong layer, it's unlikely that the existing `ValueError` is
   being raised anywhere within the framework's code.
3. It seems unlikely that consumers of this framework would be
   instantiating registry hives independent of the `hivelist` plugin,
   given that they would effectively have to duplicate the `hivelist`
   code to do so.

For these reasons, we're going to do a minor version bump, even though
an argument can be made that this warrants a major version bump
according to the SemVer rules. This is a one-off and does not indicate
any change in the way that we typically update version numbers.
2025-01-01 22:43:01 -06:00
Mike Auty ac3e76665b Linux: Fix kmsg unguarded read of msg.len 2025-01-01 15:29:07 +00:00
Mike Auty 9c02f0d12a Linux: Fix kmsf f-strings
Closes #1496
2025-01-01 15:23:04 +00:00
ikelosandGitHub e0869da092 Merge pull request #1420 from volatilityfoundation/issues/issue1417
Automagic: Use a dummy ProgressCallback if None is supplied
2025-01-01 14:06:29 +00:00
ikelosandGitHub f9d967aba6 Merge branch 'develop' into issue_1469_cachedump_exception 2025-01-01 13:05:33 +00:00
ikelosandGitHub 9a4ec65e19 Merge pull request #1501 from volatilityfoundation/issue_1484_printkey_traceback
Windows Registry: Catch RegistryInvalidIndex
2025-01-01 12:59:49 +00:00
David McDonald fa67f10d31 Windows Registry: Catch RegistryInvalidIndex
refs #1484

This catches uncaught exceptions when casting the cell to a string in
`get_node`.
2024-12-31 11:54:16 -06:00
David McDonald f87d2459e0 Windows Registry: Update docstrings + exceptions
This updates the docstrings on several methods to indicate that they may
raise an exception.
2024-12-31 11:18:25 -06:00
David McDonald 263c87611b Windows Registry: Handle exceptions in read calls
These calls to `.read()` can raise an `InvalidAddressException`. Instead
of propagating this exception to the caller, this adds debug logging,
and pads the data will null bytes.

Also updates the docstring for `decode_data()` to indicate that it can
raise `TypeError` and `ValueError`.
2024-12-31 10:43:27 -06:00
ikelosandGitHub 6d0d9c4ec0 Merge pull request #1499 from volatilityfoundation/issue_1493_handles_bugs
Windows Handles: Fix remaining tracebacks
2024-12-31 12:42:02 +00:00
ikelosandGitHub d9807579cf Merge pull request #1498 from j-t-1/sort
Sort imports and swap two assignments
2024-12-31 12:35:35 +00:00
David McDonald 9a5365e681 Windows Handles: Fix unbound local in exception handler
This fixes an unbound local used in a debug message; If the exception is
raised during the dereference operation, the `objct` variable may be
uninitialized. This uses the offset of `ptr` instead.
2024-12-30 16:59:40 -06:00
David McDonald 3288ac9713 Windows Handles: Handle possibly invalid memory accesses
Any number of member accesses here can raise an
`InvalidAddressException`; each is now checked, and `None` returned if
any `InvalidAddressException` occurs.
2024-12-30 16:31:22 -06:00
j-t-1andGitHub 21077f909f Sort imports and swap two assignments 2024-12-30 22:28:47 +00:00
David McDonald f3294ef5f1 Windows Registry: Handle possible exception in get_node
Encountered a `SwappedInvalidAddressException` within the call to `cast`
due to an underlying call to `read`.
2024-12-30 14:29:20 -06:00
David McDonald 3eeb10be29 Windows Registry: Handle uncaught exceptions
A number of calls to `get_key` across multiple plugins are not made
within a `try/except` block that handles
`registry.RegistryFormatException` - the calls are either unprotected or
only check for `KeyError`. This adds the required `try/except` blocks,
or updates the existing ones as needed.
2024-12-30 14:29:20 -06:00
David McDonald 5af5363c46 Windows Handles: Work in fixes from @attrc
These changes fix bugs encountered during regression testing related to
virtual offset validation and string length checks.
2024-12-30 13:52:43 -06:00
ikelosandGitHub 9a6ab5831d Merge pull request #1497 from volatilityfoundation/issue_1477_skeleton_key
Fix uncheck read() call and remove variable that would not be definie…
2024-12-30 18:57:18 +00:00
Andrew Case a3844e8bc5 Fix uncheck read() call and remove variable that would not be definied if exception triggers 2024-12-30 18:08:30 +00:00
Andrew Case 2153b742a1 Fix uncheck read() call and remove variable that would not be definied if exception triggers 2024-12-30 18:06:04 +00:00
David McDonald e9d9345cef Windows Cachedump: Handle uncaught InvalidAddressException 2024-12-30 09:37:40 -06:00