volatility3 icon indicating copy to clipboard operation
volatility3 copied to clipboard

hashdump Hbootkey is not valid

Open mabangde opened this issue 3 years ago • 1 comments

Describe the bug A clear and concise description of what the bug is.

Context Volatility Version: Volatility 3 Framework 2.0.0 Operating System:
Python Version: Python 3.8.5 Suspected Operating System: Ubuntu 18.04.5 LTS (wls 1) Command: ./vol.py -f /tmp/memory.dmp windows.hashdump.Hashdump

Screenshots image image

lQLPDhsLBtQy_1vNBrPNDmSw3KsqMVr3RXUB4r1CYwC8AA_3684_1715

image image image image

mabangde avatar Jan 11 '22 11:01 mabangde

Thanks for the report, could you please include a short description about the issue? It's difficult to figure out what's going wrong based only on the screenshots.

As far as I can tell, you'd get the error Hbootkey is not valid, when SAM\\Domains\\Account\\F doesn't contain a starting byte of 2 or 3. The volatility 2 options you show don't demonstrate that it can get the information either, so it's unclear why they're included? If you'd be willing to provide the image file for analysis we might be able to figure out why you're not getting data from hashdump, but as it stands it's very difficult to interpret what you'd like to see change?

ikelos avatar Jan 11 '22 12:01 ikelos