$ which python /usr/bin/python $ ls /usr/bin/ |grep python dh_python python python2.4 python2.4-config python2.4-dbg python2.4-dbg-config python2.5 python2.5-config python2.5-dbg python2.5-dbg-config python-config python-dbg python-dbg-config xmlproc_parse.python-xml xmlproc_val.python-xml $ python -V Python 2.5.1 $ uname -a Linux u-laptop 2.6.20-16-generic #2 SMP Sun Sep 23 18:31:23 UTC 2007 x86_64 GNU/Linux $ ./volatility pslist -f ../image.vmem Traceback (most recent call last): File "./volatility", line 143, in main() File "./volatility", line 139, in main modules[argv[1]].execute(argv[1], argv[2:]) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vmodules.py", line 54, in execute self.cmd_execute(module, args) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vmodules.py", line 165, in get_pslist (addr_space, symtab, types) = load_and_identify_image(op, opts) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vutils.py", line 152, in load_and_identify_image dtb = guess_dtb(filename, op) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vutils.py", line 69, in guess_dtb dtb = find_dtb(flat_address_space, types) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/win32/tasks.py", line 104, in find_dtb return process_dtb(addr_space, types, offset) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/win32/tasks.py", line 138, in process_dtb ['_EPROCESS', 'Pcb', 'DirectoryTableBase', 0], task_vaddr) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/object.py", line 168, in read_obj return read_value(addr_space, current_type, vaddr + offset) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/object.py", line 70, in read_value (val, ) = struct.unpack(type_unpack_char, buf) File "/usr/lib/python2.5/struct.py", line 87, in unpack return o.unpack(s) struct.error: unpack requires a string argument of length 8 $ python2.5 volatility pslist -f ../image.vmem Traceback (most recent call last): File "volatility", line 143, in main() File "volatility", line 139, in main modules[argv[1]].execute(argv[1], argv[2:]) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vmodules.py", line 54, in execute self.cmd_execute(module, args) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vmodules.py", line 165, in get_pslist (addr_space, symtab, types) = load_and_identify_image(op, opts) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vutils.py", line 152, in load_and_identify_image dtb = guess_dtb(filename, op) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/vutils.py", line 69, in guess_dtb dtb = find_dtb(flat_address_space, types) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/win32/tasks.py", line 104, in find_dtb return process_dtb(addr_space, types, offset) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/win32/tasks.py", line 138, in process_dtb ['_EPROCESS', 'Pcb', 'DirectoryTableBase', 0], task_vaddr) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/object.py", line 168, in read_obj return read_value(addr_space, current_type, vaddr + offset) File "/home/remc/Desktop/memoryDmptools/Volatility-1.1.1/forensics/object.py", line 70, in read_value (val, ) = struct.unpack(type_unpack_char, buf) File "/usr/lib/python2.5/struct.py", line 87, in unpack return o.unpack(s) struct.error: unpack requires a string argument of length 8 $ cat /proc/cpuinfo processor : 0 vendor_id : GenuineIntel cpu family : 6 model : 15 model name : Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz stepping : 6 cpu MHz : 1000.000 cache size : 2048 KB physical id : 0 siblings : 2 core id : 0 cpu cores : 2 fpu : yes fpu_exception : yes cpuid level : 10 wp : yes flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm syscall nx lm constant_tsc pni monitor ds_cpl est tm2 ssse3 cx16 xtpr lahf_lm bogomips : 3328.93 clflush size : 64 cache_alignment : 64 address sizes : 36 bits physical, 48 bits virtual power management: processor : 1 vendor_id : GenuineIntel cpu family : 6 model : 15 model name : Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz stepping : 6 cpu MHz : 1000.000 cache size : 2048 KB physical id : 0 siblings : 2 core id : 1 cpu cores : 2 fpu : yes fpu_exception : yes cpuid level : 10 wp : yes flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm syscall nx lm constant_tsc pni monitor ds_cpl est tm2 ssse3 cx16 xtpr lahf_lm bogomips : 3325.24 clflush size : 64 cache_alignment : 64 address sizes : 36 bits physical, 48 bits virtual power management: