Bug 1120779 - Improve profile support
Summary: Improve profile support
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: python-volatility
Version: 22
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Michal Ambroz
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-07-17 16:14 UTC by Steve Grubb
Modified: 2016-08-04 23:21 UTC (History)
2 users (show)

Fixed In Version: python-volatility-2.5.0-7.fc24 python-volatility-2.5.0-7.fc23 python-volatility-2.5.0-7.el7
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-07-10 06:00:13 UTC


Attachments (Terms of Use)
volatility resource configuration file (37 bytes, text/plain)
2014-07-17 16:17 UTC, Steve Grubb
no flags Details

Description Steve Grubb 2014-07-17 16:14:29 UTC
Description of problem:
The current setup with volatility leaves a lot to the user to configure. I was thinking that a few changes could be made

1) ship a /etc/volatilityrc file
2) create /etc/volatility.d/
3) ship module.c in the docs directory
4) ship a utility that creates a profile from current installation
5) add a man page documenting where plugins & profiles go

I have some of these already. I am considering adding libvmi to fedora which contains a plugin for volatility. So, standardizing some of this would be helpful.

Comment 1 Steve Grubb 2014-07-17 16:17:53 UTC
Created attachment 918782 [details]
volatility resource configuration file

Assuming /etc/volatility.d/ is acceptable, the attached file should work.

Comment 3 Jaroslav Reznik 2015-03-03 16:08:06 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle.
Changing version to '22'.

More information and reason for this action is here:
https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22

Comment 4 Michal Ambroz 2016-06-16 16:29:31 UTC
Things are possibly bit different with 2.5, and I hope it is better.

>1) ship a /etc/volatilityrc file
probably not needed - configuration works with the built-in defaults

>2) create /etc/volatility.d/
Plugins are in the python site packages.
Maybe I do not understand what you want to put there to /etc/volatility.d/


>3) ship module.c in the docs directory
It is in /usr/share/python-volatility/tools/linux
in the 2.5 package (rawhide, fc24). I will push the update to fc23/epel7.

>4) ship a utility that creates a profile from current installation
I do have vol_genprofile in the 2.5 package (rawhide, fc24).
I will push the update to fc23/epel7.

>5) add a man page documenting where plugins & profiles go
I have added the Debian manpage modified for Fedora.

Comment 5 Steve Grubb 2016-06-16 16:48:20 UTC
> >2) create /etc/volatility.d/
> Plugins are in the python site packages.
> Maybe I do not understand what you want to put there to /etc/volatility.d/

There are 3rd party modules that people might want to install. That is unless you've packaged more than just volatility.

Also, do we have lime or some other way of getting memory dumps?

Comment 6 Fedora Update System 2016-06-16 16:54:17 UTC
python-volatility-2.5.0-7.fc24 has been submitted as an update to Fedora 24. https://bodhi.fedoraproject.org/updates/FEDORA-2016-578e66ffeb

Comment 7 Fedora Update System 2016-06-16 16:54:24 UTC
python-volatility-2.5.0-7.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-1fe917cc79

Comment 8 Fedora Update System 2016-06-16 16:54:29 UTC
python-volatility-2.5.0-7.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2016-275852c853

Comment 9 Fedora Update System 2016-06-16 16:54:33 UTC
python-volatility-2.5.0-7.fc22 has been submitted as an update to Fedora 22. https://bodhi.fedoraproject.org/updates/FEDORA-2016-6a17942d55

Comment 10 Michal Ambroz 2016-06-16 17:08:43 UTC
>Also, do we have lime or some other way of getting memory dumps?
Lime module is not included ... I believe that Lime should go to separate package.

Comment 11 Fedora Update System 2016-06-18 05:24:10 UTC
python-volatility-2.5.0-7.fc22 has been pushed to the Fedora 22 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-6a17942d55

Comment 12 Fedora Update System 2016-06-18 05:24:54 UTC
python-volatility-2.5.0-7.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-275852c853

Comment 13 Fedora Update System 2016-06-18 16:26:38 UTC
python-volatility-2.5.0-7.fc24 has been pushed to the Fedora 24 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-578e66ffeb

Comment 14 Fedora Update System 2016-06-18 17:20:01 UTC
python-volatility-2.5.0-7.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-1fe917cc79

Comment 15 Fedora Update System 2016-07-10 06:00:10 UTC
python-volatility-2.5.0-7.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 16 Fedora Update System 2016-08-04 00:50:53 UTC
python-volatility-2.5.0-7.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 17 Fedora Update System 2016-08-04 23:21:29 UTC
python-volatility-2.5.0-7.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.