tking2 / volatility

Automatically exported from code.google.com/p/volatility
GNU General Public License v2.0
0 stars 1 forks source link

not find android profile #317

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
i use svn to download the code :
svn checkout http://volatility.googlecode.com/svn/branches/linux-trunk 
volatility
and i have a android emulator's memory dump ,but there is nothing about 
android's system in the profile shown when i type python vol.py --info in the 
directory of code. am i down the wrong version code or sth else?Need your help

Original issue reported on code.google.com by axllbe...@gmail.com on 29 Jul 2012 at 11:59

GoogleCodeExporter commented 9 years ago
or did i ignore  some important issues?

Original comment by axllbe...@gmail.com on 29 Jul 2012 at 12:00

GoogleCodeExporter commented 9 years ago

Original comment by michael.hale@gmail.com on 29 Jul 2012 at 3:50

GoogleCodeExporter commented 9 years ago
Hiya axllbeing,

Unfortunately there are so many varieties of linux (and android) available, 
that we can't store all the possible profiles for each one.  At the moment, 
because it's still in development, we don't even provide the large distribution 
versions.

As such, you'll need to construct a new profile yourself.  Unfortunately clear 
instructions on how to construct that aren't available yet because the feature 
is still in development.  Atcuno may be able to give you a clearer description 
of how to build profiles, essentially you'll need to put a dwarfdump file and 
the system.map file into a zip file, which volatility will then treat as a 
profile.

Hopefully we'll be getting some up-to-date instructions in place after the next 
version of volatility has been released, which should be very soon...

Original comment by mike.auty@gmail.com on 29 Jul 2012 at 9:42

GoogleCodeExporter commented 9 years ago
thanks a lot 

Original comment by axllbe...@gmail.com on 31 Jul 2012 at 4:25

GoogleCodeExporter commented 9 years ago

Original comment by mike.auty@gmail.com on 4 Aug 2012 at 7:40