Difference between revisions of "Truxton child file set disk offset"

From truxwiki.com
Jump to navigation Jump to search
Line 1: Line 1:
 
Sets the physical disk offset of the first byte of the contents of the file.
 
Sets the physical disk offset of the first byte of the contents of the file.
This corresponds to the <code>PhysicalDiskOffset</code> column of the <code>[[File Table | File]]</code> table.
+
This corresponds to the <code>[PhysicalDiskOffset]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
=Syntax=
 
=Syntax=
<syntaxhighlight lang="C">
+
<source lang="C">
 
void truxton_child_file_set_disk_offset( uint64_t child_handle, uint64_t offset );
 
void truxton_child_file_set_disk_offset( uint64_t child_handle, uint64_t offset );
</syntaxhighlight>
+
</source>
  
 
=Parameters=
 
=Parameters=
 
==<code>child_handle</code>==
 
==<code>child_handle</code>==
 
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
  
Line 16: Line 15:
  
 
=Sample=
 
=Sample=
<syntaxhighlight lang="C" highlight="27">
+
<source lang="C" highlight="27">
 
void add_folder(uint64_t truxton, uint64_t parent_file)
 
void add_folder(uint64_t truxton, uint64_t parent_file)
 
{
 
{
Line 32: Line 31:
 
   FILETIME now;
 
   FILETIME now;
  
   GetSystemTimeAsFileTime(&now);
+
   GetSystemTimePreciseAsFileTime(&now);
  
 
   ULARGE_INTEGER ticks;
 
   ULARGE_INTEGER ticks;
Line 53: Line 52:
 
   truxton_child_file_destroy(child);
 
   truxton_child_file_destroy(child);
 
}
 
}
</syntaxhighlight>
+
</source>

Revision as of 05:03, 13 November 2020

Sets the physical disk offset of the first byte of the contents of the file. This corresponds to the [PhysicalDiskOffset] column of the [File] table.

Syntax

void truxton_child_file_set_disk_offset( uint64_t child_handle, uint64_t offset );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

offset

The offset, in bytes, from the beginning of the physical disk where the first byte of the file contents was stored.

Sample

void add_folder(uint64_t truxton, uint64_t parent_file)
{
   truxton_start_adding_files(truxton);

   uint64_t child = truxton_child_file_create(truxton);

   char id[40];

   truxton_file_get_id(parent_file, id, sizeof(id));
   truxton_child_file_set_parent_id(child, id);
   truxton_child_file_set_type(child, Type_Directory);
   truxton_child_file_set_name(child, "Custom Exploits Folder");

   FILETIME now;

   GetSystemTimePreciseAsFileTime(&now);

   ULARGE_INTEGER ticks;

   ticks.LowPart = now.dwLowDateTime;
   ticks.HighPart = now.dwHighDateTime;

   truxton_child_file_set_created(child, ticks.QuadPart);
   truxton_child_file_set_accessed(child, ticks.QuadPart);
   truxton_child_file_set_modified(child, ticks.QuadPart);

   truxton_child_file_set_disk_offset(child, 5464419);
   truxton_child_file_set_path(child, "Files/This File" );

   if ( truxton_child_file_save(child) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }

   truxton_child_file_destroy(child);
}