Files
volatility3/volatility/framework/plugins/linux/check_modules.py
T
mtresslerandikelos 79cf041283 Update check_modules.py
Removed unnecessary header info. A symbol table without the module_kset struct will now raise a TypeError
2020-07-21 23:00:52 +01:00

80 lines
3.2 KiB
Python

# This file is Copyright 2020 Volatility Foundation and licensed under the Volatility Software License 1.0
# which is available at https://www.volatilityfoundation.org/license/vsl-v1.0
#
import logging
from typing import List
from volatility.framework import interfaces, renderers, exceptions, constants, contexts
from volatility.framework.automagic import linux
from volatility.framework.configuration import requirements
from volatility.framework.interfaces import plugins
from volatility.framework.layers import intel
from volatility.framework.objects import utility
from volatility.plugins.linux import lsmod
from volatility.framework.renderers import format_hints
vollog = logging.getLogger(__name__)
class check_modules(plugins.PluginInterface):
"""Compares module list to sysfs info, if available"""
@classmethod
def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]:
return [
requirements.TranslationLayerRequirement(name='primary',
description='Memory layer for the kernel',
architectures=["Intel32", "Intel64"]),
requirements.SymbolTableRequirement(
name="vmlinux", description="Linux kernel symbols"),
requirements.PluginRequirement(
name='lsmod', plugin=lsmod.Lsmod, version=(1, 0, 0))
]
def get_kset_modules(self, vmlinux):
try:
module_kset = vmlinux.object_from_symbol("module_kset")
except exceptions.SymbolError:
module_kset = None
if not module_kset:
raise TypeError("This plugin requires the module_kset structure. This structure is not present in the supplied symbol table. This means you are either analyzing an unsupported kernel version or that your symbol table is corrupt.")
ret = {}
kobj_off = self.context.symbol_space.get_type(
self.config['vmlinux'] + constants.BANG + 'module_kobject').relative_child_offset('kobj')
for kobj in module_kset.list.to_list(vmlinux.name + constants.BANG + "kobject", "entry"):
mod_kobj = vmlinux.object(
object_type="module_kobject", offset=kobj.vol.offset - kobj_off)
mod = mod_kobj.mod
name = utility.pointer_to_string(kobj.name, 32)
if kobj.name and kobj.reference_count() > 2:
ret[name] = mod
return ret
def _generator(self):
vmlinux = contexts.Module(
self.context, self.config['vmlinux'], self.config['primary'], 0)
kset_modules = self.get_kset_modules(vmlinux)
lsmod_modules = set(str(utility.array_to_string(modules.name)) for modules in
lsmod.Lsmod.list_modules(self.context,
self.config['primary'], self.config['vmlinux']))
for mod_name in set(kset_modules.keys()).difference(lsmod_modules):
yield(0, (format_hints.Hex(kset_modules[mod_name]), str(mod_name)))
def run(self):
return renderers.TreeGrid([("Module Address", format_hints.Hex),
("Module Name", str)], self._generator())