4 ms·
There is a tool used in malware analysis and computer forensics called Volatility[0]. It has some very powerful analysis tools and works on Linux Mac and Windo
by sdmike1 7y ago
There is a tool used in malware analysis and computer forensics called Volatility[0]. It has some very powerful analysis tools and works on Linux Mac and Windows. In your case its ability to dump the memory of a running process without messing with the process state [1] may be very helpful! It also has the ability to run a Yara scan against the dumped memory which could let you find the region of memory containing the config file (so long as you know some of the strings in it).
Hope this helps!
[0] https://github.com/volatilityfoundation/volatility https://github.com/volatilityfoundation/volatility
[1] https://www.andreafortuna.org/2017/07/10/volatility-my-own-cheatsheet-part-3-process-memory/ https://www.andreafortuna.org/2017/07/10/volatility-my-own-c...
- john_moscow 7y agoI would advise exercising caution though. Even if the tool works perfectly fine, the service going down anywhere within days to weeks after you captured its state would be seen by the management as your fault. They won't care for the explanations, they will just need a scapegoat and that would be whoever touched the thing last time. That said, there are plenty of legitimate (albeit low-probability) reasons for the dumping tool to screw up the service. Slightly affecting memory timing and triggering some rare race condition, using up more RAM than usual (or increasing the HDD utilization) and again triggering some conditions that wouldn't happen normally. You name it. If it was me, I would try to run the binary on another machine and do a "clean room" recreation of the config file. That said, service without sources and missing configs without backups indicate severe organizational problems, so I would probably not want to work in such a place for a long time, unless I was hired by the CEO specifically to rectify things.
- marcus_holmes 7y agoI agree, there are actually two problems here: One is technical, and to do with the service and how to deal with it. One is political, and to do with who gets the blame when the service inevitably fails. OP needs to work out if they're being tasked with the job as the answer to the technical problem or the political problem. Because management could be very aware that this is a ticking bomb with no technical solution, and have appointed OP as a scapegoat to take the blame when it blows up.
- ashish5887 7y agoWhat good is a memory dump if you don't have the codebase to navigate? without the code and structure of how its managed a memory dump would just look like an alien language.
- dsr_ 7y agoThe phrase you want to google is "reverse engineering from memory dump". Prepare to be astounded. You need to know how machine instructions work, details of the operating system, and a bunch of other things... but any number of copy-protection systems have been bypassed this way. Any number of devices have had their firmware dumped, their memory scanned, and the resulting data analyzed to make patches or build compatible systems.
- harha 7y ago> so I would probably not want to work in such a place for a long time, unless I was hired by the CEO specifically to rectify things. Reminds me of The Phoenix Project.