Difference between revisions of "Truxton child file create exif"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This creates an EXIF object sourced from this file that you can use in the EXIF API. An EXIF object is how you add records to the...")
 
Line 51: Line 51:
 
   truxton_exif_set_make(exif, "Ford");
 
   truxton_exif_set_make(exif, "Ford");
 
   truxton_exif_set_model(exif, "Mustang");
 
   truxton_exif_set_model(exif, "Mustang");
   truxton_event_set_end(event, truxton_file_get_modified( parent_file ) );
+
   truxton_exif_set_device_time(exif, truxton_file_get_modified( parent_file ) );
   truxton_event_set_title(event, "Fancy Bear Panda Hurricane" );
+
   truxton_exif_set_latitude(exif, 27.94999);
   truxton_event_set_description(event, "Russian Malware repurposed by Chinese military used in FBI investigation" );
+
   truxton_exif_set_longitude(exif, -82.354748);
   truxton_event_save(event);
+
   truxton_exif_save(exif);
 +
  truxton_exif_destroy(exif);
  
 
   truxton_child_file_destroy(child);
 
   truxton_child_file_destroy(child);
 
}
 
}
 
</syntaxhighlight>
 
</syntaxhighlight>

Revision as of 16:28, 8 June 2020

This creates an EXIF object sourced from this file that you can use in the EXIF API. An EXIF object is how you add records to the EXIF table. The resulting event object will automatically be associated with the file it was created from and with the media the file belongs to.


Note: Not all camera information comes from EXIF sections. Camera information can be exploited from anywhere in the file but the meta data will be stored in the EXIF table.

Syntax

uint64_t truxton_child_file_create_exif( uint64_t child_handle );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

Return value

A handle to an EXIF object.

Sample

void add_folder(uint64_t truxton, uint64_t parent_file)
{
   truxton_start_adding_files(truxton);

   uint64_t child = truxton_child_file_create(truxton);

   char id[40];

   truxton_file_get_id(parent_file, id, sizeof(id));
   truxton_child_file_set_parent_id(child, id);
   truxton_child_file_set_type(child, Type_Directory);
   truxton_child_file_set_name(child, "Custom Exploits Folder");

   truxton_child_file_set_origin(child, ORIGIN_GENERATED);

   if ( truxton_child_file_save(child) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }
   else
   {
      ticks.QuadPart = truxton_child_file_get_disk_offset(child_file);
      printf( "Physical Disk Offset was %d\n", ticks.QuadPart );
   }

   uint64_t exif = truxton_child_file_create_exif(child);

   truxton_exif_set_make(exif, "Ford");
   truxton_exif_set_model(exif, "Mustang");
   truxton_exif_set_device_time(exif, truxton_file_get_modified( parent_file ) );
   truxton_exif_set_latitude(exif, 27.94999);
   truxton_exif_set_longitude(exif, -82.354748);
   truxton_exif_save(exif);
   truxton_exif_destroy(exif);

   truxton_child_file_destroy(child);
}