-
Notifications
You must be signed in to change notification settings - Fork 389
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows XP: Symbol type not in nt_symbols1 SymbolTable: _ETHREAD` #242
Comments
My guess is that the volatility automagic may not have been able to find the kernel's PDB to generate the appropriate symbols, but I'll know more once the download request goes through... 5:) |
Sorry, I thought the link could be shared. Updated link to winxp dump file on google drive. Update 2: The link can now be opened by anyone. |
Hmmm, that image seems to work fine for me? You might want to try clearing out your cache ( winxp-4da5322a-f55c-4124-92e0-a4520647bb36.json.txt I've included a file that is the symbol table to the image you linked (it can be downloaded and put at |
Hi @ikelos, thanks for the feedback. I tried removing my volatility cache, didn't work. I downloaded your JSON profile in the ntkrpamp.pdb directory, and this solution worked:
My compressed JSON profile is really different than yours: C40DD53A8D3D4AE3A24CE6BE866649C9-1.txt So I have no clue why the generated profile is not working for me ? maybe incomplete ? Thanks ! |
Hmmmm, very strange? Was it just the profile (as in, if you dropped my profile in place of yours, would it work?). Also, are you running the latest git release of volatility3, there's been a fair bit of development work since the first beta? Hmmm, so the metadata suggests mine wasn't built by volatility, but by another tool we used to use before hand (which was used for all the profiles in windows.zip):
It's for a different database and an earlier age than the one you generated:
But essentially yours didn't generate any types (no base_types or user_types) which will be why it failed. With the image you sent I can start to do some analysis and see what's going on at least. I'll let you know if I find anything... |
Hmmm, so it appears as though the PDB files that Microsoft offers (even for the earlier PDB of age 1 and name ntkrpamp.pdb) is reduced and contains only symbols and not types? 5:S Which is strange that they'd change files they've previously provided? @npetroni Have we seen examples of this happening before? It might mean that windows.zip archive is more useful than we expected? |
@ikelos I created a Dockerfile for you to repro the bug; FROM ubuntu:20.04
RUN apt-get update && apt-get install -y git python3 python3-dev python3-venv
RUN git clone https://github.com/volatilityfoundation/volatility3
RUN python3 -m venv venv
RUN . venv/bin/activate && pip install wheel && pip install /volatility3
ENTRYPOINT . venv/bin/activate && vol -f /image -vvvv windows.ssdt.SSDT
|
For reference, here is the most recent PDB file available from Microsoft: |
IIRC, we saw this once before for a similarly old PDB. I verified that the DIA library does not seem to find types in the PDB in the attachment. |
What file will this replace? |
@thall63 It would need to be converted to the appropriate JSON, it's in PDB format at the moment. The file was more for us to debug what was happening. The PDB can be processed into a JSON file if you're interested in seeing what it would look like, but it would be much more helpful to keep discussions like this which are more interactive on a medium like slack (which you can join by going to https://www.volatilityfoundation.org/slack) so please contact me there if you'd like to do that... |
This issue is stale because it has been open for 200 days with no activity. |
This issue was closed because it has been inactive for 60 days since being marked as stale. |
Describe the bug
Volatility3 failed to run the SSDT plugin on a windows XP dump
Automagic exception occurred: ValueError: Symbol type not in nt_symbols1 SymbolTable: _ETHREAD
Context
Volatility Version:
master
Operating System:
Ubuntu 20.04
Python Version:
3.8
Suspected Operating System: Windows XP
Command:
vol -f winxp-4da5322a-f55c-4124-92e0-a4520647bb36.dump windows.ssdt.SSDT
To Reproduce
Steps to reproduce the behavior:
vol -f winxp-4da5322a-f55c-4124-92e0-a4520647bb36.dump windows.ssdt.SSDT
Expected behavior
SSDT table should have been printed
Screenshots
Additional information
Gist of the volatility log file
Thanks !
The text was updated successfully, but these errors were encountered: