Difference between revisions of "Truxton child file set disk offset"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "Sets the physical disk offset of the first byte of the contents of the file. =Syntax= <syntaxhighlight lang="C"> void truxton_child_file_set_disk_offset( uint64_t child_handl...")
 
Line 48: Line 48:
 
   {
 
   {
 
       printf( "Failed to add child to Truxton\n" );
 
       printf( "Failed to add child to Truxton\n" );
  }
 
  else
 
  {
 
      truxton_child_file_get_id(child_file, id, sizeof(id));
 
      printf( "Added child id %s\n", id );
 
 
   }
 
   }
  

Revision as of 16:36, 9 June 2020

Sets the physical disk offset of the first byte of the contents of the file.

Syntax

void truxton_child_file_set_disk_offset( uint64_t child_handle, uint64_t offset );

Parameters

child_handle

The handle created by the truxton_child_file_create or truxton_file_create_child call.

offset

The offset, in bytes, from the beginning of the physical disk where the first byte of the file contents was stored.

Sample

void add_folder(uint64_t truxton, uint64_t parent_file)
{
   truxton_start_adding_files(truxton);

   uint64_t child = truxton_child_file_create(truxton);

   char id[40];

   truxton_file_get_id(parent_file, id, sizeof(id));
   truxton_child_file_set_parent_id(child, id);
   truxton_child_file_set_type(child, Type_Directory);
   truxton_child_file_set_name(child, "Custom Exploits Folder");

   FILETIME now;

   GetSystemTimeAsFileTime(&now);

   ULARGE_INTEGER ticks;

   ticks.LowPart = now.dwLowDateTime;
   ticks.HighPart = now.dwHighDateTime;

   truxton_child_file_set_created(child, ticks.QuadPart);
   truxton_child_file_set_accessed(child, ticks.QuadPart);
   truxton_child_file_set_modified(child, ticks.QuadPart);

   truxton_child_file_set_disk_offset(child, 5464419);
   truxton_child_file_set_path(child, "Files/This File" );

   if ( truxton_child_file_save(child) == 0 )
   {
      printf( "Failed to add child to Truxton\n" );
   }

   truxton_child_file_destroy(child);
}