I just did an svn update to version 1327 and I'm now noticing the
following errors upon execution of any volatility command. For example:
~/tools/Volatility/vol.py -f XP_SP3.vmem imageinfo
Volatile Systems Volatility Framework 2.1_alpha
*** Failed to import volatility.plugins.overlays.windows.win2k8_sp1_x86
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import
volatility.plugins.overlays.windows.win2k8_sp1_x86_vtypes
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import
volatility.plugins.overlays.windows.win2k8_sp2_x86_vtypes
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import volatility.plugins.overlays.windows.win2k8_sp2_x86
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
Suggested Profile(s) : WinXPSP3x86, WinXPSP2x86 (Instantiated
with WinXPSP2x86)
:
snip
:
~/tools/Volatility/vol.py -f XP_SP3.vmem --profile=WinXPSP3x86 connscan
Volatile Systems Volatility Framework 2.1_alpha
*** Failed to import volatility.plugins.overlays.windows.win2k8_sp1_x86
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import
volatility.plugins.overlays.windows.win2k8_sp1_x86_vtypes
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import
volatility.plugins.overlays.windows.win2k8_sp2_x86_vtypes
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import volatility.plugins.overlays.windows.win2k8_sp2_x86
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
Offset(P) Local Address Remote Address Pid
---------- ------------------------- ------------------------- ------
0x0219fa40 0.0.0.0:19272 0.0.0.0:55542 2147487916
~/tools/Volatility/vol.py -f XP_SP3.vmem --profile=WinXPSP3x86 modules
Volatile Systems Volatility Framework 2.1_alpha
*** Failed to import volatility.plugins.overlays.windows.win2k8_sp1_x86
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import
volatility.plugins.overlays.windows.win2k8_sp1_x86_vtypes
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import
volatility.plugins.overlays.windows.win2k8_sp2_x86_vtypes
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
*** Failed to import volatility.plugins.overlays.windows.win2k8_sp2_x86
(AttributeError: 'module' object has no attribute 'ntkrnlmp_types')
Offset(V) File Base
Size Name
0x823fc3a0 \WINDOWS\system32\ntkrnlpa.exe
0x00804d7000 0x1f8580 ntoskrnl.exe
0x823fc338 \WINDOWS\system32\hal.dll
0x00806d0000 0x020300 hal.dll
:
snip
:
Everything seems to complete OK so far, but I'm wondering what might
have caused these new error messages.
Thanks!
Andre'
--
Andre' M. DiMino
DeepEnd REsearch
http://deependresearch.org
http://sempersecurus.org
"Make sure that nobody pays back wrong for wrong, but always try to be
kind to each other and to everyone else" - 1 Thess 5:15 (NIV)