Difference between revisions of "Truxton child file get disk offset"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This retrieves the offset in the physical disk where the first byte of the file contents was stored. =Syntax= <syntaxhighlight lang="C"> uint64_t truxton_child_file_get_disk_...")
 
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
This retrieves the offset in the physical disk where the first byte of the file contents was stored.
 
This retrieves the offset in the physical disk where the first byte of the file contents was stored.
 +
This corresponds to the <code>[PhysicalDiskOffset]</code> column of the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table.
  
 
=Syntax=
 
=Syntax=
<syntaxhighlight lang="C">
+
<source lang="C">
 
uint64_t truxton_child_file_get_disk_offset( uint64_t child_handle );
 
uint64_t truxton_child_file_get_disk_offset( uint64_t child_handle );
</syntaxhighlight>
+
</source>
  
 
=Parameters=
 
=Parameters=
 
==<code>child_handle</code>==
 
==<code>child_handle</code>==
 
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
 
The handle created by the [[truxton_child_file_create]] or [[truxton_file_create_child]] call.
  
 
=Return value=
 
=Return value=
The offset, in bytes, where the first byte of file contents was stored.
+
The offset, in bytes, where the first byte of file contents was found in the source media.
  
 
=Remarks=
 
=Remarks=
Line 19: Line 19:
  
 
=Sample=
 
=Sample=
 
+
<source lang="C" highlight="28">
<syntaxhighlight lang="C" highlight="35">
+
void add_folder( uint64_t truxton, uint64_t parent_file )
void add_folder(uint64_t truxton, uint64_t parent_file)
 
 
{
 
{
   truxton_start_adding_files(truxton);
+
   truxton_start_adding_files( truxton );
  
   uint64_t child = truxton_child_file_create(truxton);
+
   uint64_t child = truxton_child_file_create( truxton );
  
 
   char id[40];
 
   char id[40];
  
   truxton_file_get_id(parent_file, id, sizeof(id));
+
   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id(child, id);
+
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type(child, Type_Directory);
+
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name(child, "Custom Exploits Folder");
+
   truxton_child_file_set_name( child, "Custom Exploits Folder" );
 
 
  FILETIME now;
 
 
 
  GetSystemTimeAsFileTime(&now);
 
  
   ULARGE_INTEGER ticks;
+
   uint64_t now = truxton_time_now();
  
   ticks.LowPart = now.dwLowDateTime;
+
   truxton_child_file_set_created( child, now );
   ticks.HighPart = now.dwHighDateTime;
+
   truxton_child_file_set_accessed( child, now );
 +
  truxton_child_file_set_modified( child, now );
  
   truxton_child_file_set_created(child, ticks.QuadPart);
+
   truxton_child_file_set_origin( child, ORIGIN_GENERATED );
  truxton_child_file_set_accessed(child, ticks.QuadPart);
 
  truxton_child_file_set_modified(child, ticks.QuadPart);
 
  
  truxton_child_file_set_origin(child, ORIGIN_GENERATED);
+
   if ( truxton_child_file_save( child ) == 0 )
 
 
   if ( truxton_child_file_save(child) == 0 )
 
 
   {
 
   {
 
       printf( "Failed to add child to Truxton\n" );
 
       printf( "Failed to add child to Truxton\n" );
Line 55: Line 47:
 
   else
 
   else
 
   {
 
   {
       ticks.QuadPart = truxton_child_file_get_disk_offset(child_file);
+
       now = truxton_child_file_get_disk_offset( child_file );
       printf( "Physical Disk Offset was %d\n", ticks.QuadPart );
+
       printf( "Physical Disk Offset was %" PRIu64 "\n", now );
 
   }
 
   }
  
   truxton_child_file_destroy(child);
+
   truxton_child_file_destroy( child );
 
}
 
}
</syntaxhighlight>
+
</source>
 +
 
 +
Note, the <code>PRIu64</code> in the sample code above is the new standard way of [https://en.wikipedia.org/wiki/C_data_types#Printf_and_scanf_format_specifiers formatting] a 64-bit integer in C.
 +
Over the years, different compilers on different operating systems used different format specifiers for things, these <code>PRI</code> macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.

Latest revision as of 03:06, 14 April 2024

This retrieves the offset in the physical disk where the first byte of the file contents was stored. This corresponds to the [PhysicalDiskOffset] column of the [File] table.

Syntax

uint64_t truxton_child_file_get_disk_offset( uint64_t child_handle );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

Return value

The offset, in bytes, where the first byte of file contents was found in the source media.

Remarks

If the media being loaded was not some form of raw storage, this will return a non-zero value. Zero will be returned if the media wasn't a storage device (like a logical files).

Sample

void add_folder( uint64_t truxton, uint64_t parent_file )
{
   truxton_start_adding_files( truxton );

   uint64_t child = truxton_child_file_create( truxton );

   char id[40];

   truxton_file_get_id( parent_file, id, sizeof(id) );
   truxton_child_file_set_parent_id( child, id );
   truxton_child_file_set_type( child, Type_Directory );
   truxton_child_file_set_name( child, "Custom Exploits Folder" );

   uint64_t now = truxton_time_now();

   truxton_child_file_set_created( child, now );
   truxton_child_file_set_accessed( child, now );
   truxton_child_file_set_modified( child, now );

   truxton_child_file_set_origin( child, ORIGIN_GENERATED );

   if ( truxton_child_file_save( child ) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }
   else
   {
      now = truxton_child_file_get_disk_offset( child_file );
      printf( "Physical Disk Offset was %" PRIu64 "\n", now );
   }

   truxton_child_file_destroy( child );
}

Note, the PRIu64 in the sample code above is the new standard way of formatting a 64-bit integer in C. Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.