""" Created on 10 Mar 2013 @author: mike """ import logging import pdb import volatility.framework.symbols.windows.extensions from volatility import framework from volatility.framework import contexts from volatility.framework import layers, plugins from volatility.framework.interfaces import objects from volatility.framework.symbols import vtypes, native from volatility.framework.symbols.windows import xp_sp2_x86_vtypes def utils_load_as(): # TODO: This should hold the smarts for determining the physical layers and guessing at various values and so on native_list = native.x86NativeTable ctx = framework.contexts.Context(native_list) ctx.symbol_space.append(native_list) from volatility.framework.symbols.windows import xp_sp2_x86_vtypes virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, ctx.symbol_space.natives) ntkrnlmp.set_type_class('_ETHREAD', volatility.framework.symbols.windows.extensions._ETHREAD) ntkrnlmp.set_type_class('_LIST_ENTRY', volatility.framework.symbols.windows.extensions._LIST_ENTRY) ctx.symbol_space.append(ntkrnlmp) # contexts.windows.WindowsContextModifier(ctx.config).modify_context(ctx) return ctx def test_symbols(): ctx = utils_load_as() print("Symbols,", ctx.symbol_space.natives.types) virtual_types = xp_sp2_x86_vtypes.ntkrnlmp_types virtual_types['TEST_POINTER'] = [0x4, {'point1': [0x0, ['pointer', ['TEST_SYMBOL']]]}] virtual_types['TEST_SYMBOL'] = [0x6, {'test1': [0x0, ['unsigned int']], 'test2': [0x4, ['unsigned short']]}] ntkrnlmp = vtypes.VTypeSymbolTable('ntkrnlmp', virtual_types, ctx.symbol_space.natives) ctx.symbol_space.append(ntkrnlmp) for i in list(ctx.symbol_space['ntkrnlmp'].types): symbol = ctx.symbol_space.get_type('ntkrnlmp!' + i) print(symbol.vol.type_name, symbol, symbol.vol.size) _ = symbol(ctx, objects.ObjectInformation(layer_name = '', offset = 0)) symbol = ctx.symbol_space.get_type('ntkrnlmp!_EPROCESS') return symbol def test_memory(): ctx = utils_load_as() base = layers.physical.FileLayer(ctx, config_path = "memtest", name = 'physical', filename = 'trig_data.bin') ctx.memory.add_layer(base) val = ctx.object('ntkrnlmp!TEST_POINTER', 'physical', 0) print(hex(val.point1.test1), val.point1.test2) def test_kdbgfind(): ctx = utils_load_as() base = layers.physical.FileLayer(ctx, config_path = "memtest", name = 'physical', filename = '/run/media/mike/disk/memory/xp-laptop-2005-06-25.img') ctx.memory.add_layer(base) intel = layers.intel.Intel(ctx, 'kernel', 'physical', page_map_offset = 0x39000) ctx.memory.add_layer(intel) def intel32(ctx): base = layers.physical.FileLayer(ctx, config_path = "memtest", name = 'physical', filename = '/run/media/mike/disk/memory/xp-laptop-2005-06-25.img') ctx.memory.add_layer(base) intel = layers.intel.Intel(ctx, config_path = "memtest", name = 'kernel', memory_layer = 'physical', page_map_offset = 0x39000) x = [0x823c87c0, 0x81fdf020, 0x81f5a3b8, 0x81f8eb10, 0x820e0da0, 0x82199668, 0x81fa5aa0, 0x81fa8650, 0x81faba78, 0x81fa8240, 0x81f8dda0, 0x81f6e7e8, 0x81f9a670, 0x81f5f020, 0x8202bda0, 0x82113c48, 0x81f67500, 0x81f6ca90, 0x820dd588, 0x82025608, 0x81faf280, 0x821125d0, 0x82076558, 0x81f68518, 0x82059da0, 0x81f6db28, 0x82021a78, 0x81f48da0, 0x820238e0, 0x82081da0, 0x821ca3d0, 0x821ce4d8, 0x821d4da0, 0x81343790, 0xffab8020, 0x8205eda0, 0xffaa0c10, 0x82218020, 0x814b13b0, 0x81ed76b0, 0x81f269e0, 0xffadc9d0, 0x821fb3b8, 0x82079c18, 0x82000980, 0x822148f0, 0x81ed84e8] return intel, x def intelpae(ctx): base = layers.physical.FileLayer(ctx, config_path = "memtest", name = 'physical', filename = '/run/media/mike/disk/memory/private/jon-fres.dmp') ctx.memory.add_layer(base) intel = layers.intel.IntelPAE(ctx, config_path = "memtest", name = 'intel', memory_layer = 'physical', page_map_offset = 0x319000) x = [0x81bcc830, 0x81989940, 0x81915020, 0x8192ad18, 0x818fa7b8, 0x818f6da0, 0x818d1020, 0x818b2878, 0x8189f180, 0x8188db58, 0x81884a40, 0x818766b0, 0x8185a948, 0x8183ad70, 0x81826020, 0x818a64c8, 0x81818020, 0x81800020, 0x817ff460, 0x817eb020, 0x817e9020, 0x817a62a8, 0x817a4b28, 0x81865020, 0x817972c0] return intel, x def intel32e(ctx): base = layers.physical.FileLayer(ctx, config_path = "memtest", name = 'data', filename = '/run/media/mike/disk/memory/private/ikelos-winxpsp2-x64.dmp') ctx.memory.add_layer(base) intel = layers.intel.Intel32e(ctx, config_path = "memtest", name = 'kernel', memory_layer = 'data', page_map_offset = 0x3c3000) x = [0xfffffadffa517c20, 0xfffffadffa2c9510, 0xfffffadffb16a660, 0xfffffadff9d77c20, 0xfffffadffb0fe040, 0xfffffadffb0f2040, 0xfffffadffb0c2040, 0xfffffadffb0b7c20, 0xfffffadffb087c20, 0xfffffadffb06a760, 0xfffffadffb039c20, 0xfffffadffb02c040, 0xfffffadffafe9c20, 0xfffffadffafa7040, 0xfffffadffaf2e040, 0xfffffadffaf279a0, 0xfffffadffaf24600, 0xfffffadffaed3040, 0xfffffadffaecf040, 0xfffffadffaeb35a0, 0xfffffadffae747b0, 0xfffffadffae30040, 0xfffffadffae2b040, 0xfffffadffae1d8b0, 0xfffffadffae1a040, 0xfffffadffae34810] return intel, x def test_translation(): nativelst = native.x86NativeTable ctx = contexts.Context(nativelst) intel, x = intel32(ctx) base = layers.physical.BufferDataLayer(ctx, config_path = "memtest", name = 'base', buffer = b" ") print(base.is_valid(0), base.is_valid(0) == True) print(base.is_valid(1), base.is_valid(1) == False) print(base.is_valid(0, 2), base.is_valid(0, 2) == False) for val in x: a, b = intel._translate(val) print(hex(val), hex(a), hex(b)) # print(bin(0x39000), bin(0xffab8020)) # print(hex(intel.mapping(0xffab8020, 0))) def test_plugin(): ctx = utils_load_as() base = layers.physical.FileLayer(ctx, config_path = "memtest", name = 'physical', filename = '/run/media/mike/disk/memory/xp-laptop-2005-06-25.img') ctx.memory.add_layer(base) intel = layers.intel.Intel(ctx, config_path = "memtest", name = 'kernel', memory_layer = 'physical', page_map_offset = 0x39000) ctx.memory.add_layer(intel) import volatility.plugins.windows.pslist as pslist # _ETHREAD physical offset for System process of xp-laptop-2005-06-25 eproc = pslist.PsList.kernel_process_from_physical_process(ctx, 'physical', 'kernel', 0x23c87c0) for proc in eproc.ActiveProcessLinks: print(proc.UniqueProcessId) # TODO: # # X - Config system # X - Dataout Tree/List input/output # - Plugins taking TranslationLayers # - Plugins # - Architectures # - Scanning Framework # - GUI/UI # if __name__ == '__main__': logger = logging.getLogger() logger.setLevel(logging.DEBUG) plugins.import_plugins() # import timeit # print(timeit.Timer(main).timeit(10)) try: print("[!] Testing Symbols") test_symbols() print("[!] Testing Memory") test_memory() print("[!] Testing Intel Translations") test_translation() print("[!] Testing Plugin") test_plugin() except Exception as e: print(repr(e)) pdb.post_mortem()