Hey Jim
It seems like some 64 bit profiles were placed in the 32 bit directory,
effectively duplicating them. I will look into this tonight and get it
fixed.
Also, it is not recommended to load all Mac/Linux profiles into your
install as each one mus then be loaded when you run Volatility. Instead
just active (copy into the directory) the ones you need for a particular
investigation.
Thanks,
Andrew (@attrc)
On 08/13/2014 02:18 PM, Jim Clausing wrote:
I just installed volatility 2.4 and git cloned
the profiles and I get
the following error when I try to see what profiles I've got. It also
takes quite a while before it crashes out. Am I doing something wrong?
$ vol.py --plugins ./profiles --info | grep Profile
Volatility Foundation Volatility Framework 2.4
Traceback (most recent call last):
File "/usr/local/bin/vol.py", line 5, in <module>
pkg_resources.run_script('volatility==2.4', 'vol.py')
File "/usr/lib/python2.7/dist-packages/pkg_resources.py", line 499, in
run_script
self.require(requires)[0].run_script(script_name, ns)
File "/usr/lib/python2.7/dist-packages/pkg_resources.py", line 1235,
in run_script
execfile(script_filename, namespace, namespace)
File
"/usr/local/lib/python2.7/dist-packages/volatility-2.4-py2.7.egg/EGG-INFO/scripts/vol.py",
line 192, in <module>
main()
File
"/usr/local/lib/python2.7/dist-packages/volatility-2.4-py2.7.egg/EGG-INFO/scripts/vol.py",
line 152, in main
print_info()
File
"/usr/local/lib/python2.7/dist-packages/volatility-2.4-py2.7.egg/EGG-INFO/scripts/vol.py",
line 117, in print_info
plugins = registry.get_plugin_classes(c, lower = lower)
File
"/usr/local/lib/python2.7/dist-packages/volatility-2.4-py2.7.egg/volatility/registry.py",
line 152, in get_plugin_classes
raise Exception("Object {0} has already been defined by
{1}".format(name, plugin))
Exception: Object LinuxRedHat56x64 has already been defined by <class
'volatility.plugins.overlays.linux.linux.LinuxRedHat56x64'>
--
Jim Clausing
GIAC GSE #26, CISSP
GPG Fingerprint = A507 774A 39D6 A702 9F7C 8808 3D13 77B8 AACD 848D
On or about Wed, 13 Aug 2014, Andrew Case pontificated thusly:
The Volatility Team is happy to announce that
Volatility 2.4 is now
publicly released.
Volatility 2.4 adds support for Windows 8, 8.1, 2012, and 2012 R2 memory
dumps, Mac OS X Mavericks (up to 10.9.4), and Linux kernels up to 3.16.
It also contains a large number of new plugins and features. Full
information can be found here:
http://volatility-labs.blogspot.com/2014/08/presenting-volatility-foundatio…
Please let me know if you have any issues or questions with the release.
--
Thanks,
Andrew (@attrc)
_______________________________________________
Vol-users mailing list
Vol-users(a)volatilityfoundation.org
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users