Difference between revisions of "Truxton child file set disk offset"
Jump to navigation
Jump to search
(Created page with "Sets the physical disk offset of the first byte of the contents of the file. =Syntax= <syntaxhighlight lang="C"> void truxton_child_file_set_disk_offset( uint64_t child_handl...") |
(→Sample) |
||
| Line 48: | Line 48: | ||
{ | { | ||
printf( "Failed to add child to Truxton\n" ); | printf( "Failed to add child to Truxton\n" ); | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
} | } | ||
Revision as of 16:36, 9 June 2020
Sets the physical disk offset of the first byte of the contents of the file.
Syntax
void truxton_child_file_set_disk_offset( uint64_t child_handle, uint64_t offset );
Parameters
child_handle
The handle created by the truxton_child_file_create or truxton_file_create_child call.
offset
The offset, in bytes, from the beginning of the physical disk where the first byte of the file contents was stored.
Sample
void add_folder(uint64_t truxton, uint64_t parent_file)
{
truxton_start_adding_files(truxton);
uint64_t child = truxton_child_file_create(truxton);
char id[40];
truxton_file_get_id(parent_file, id, sizeof(id));
truxton_child_file_set_parent_id(child, id);
truxton_child_file_set_type(child, Type_Directory);
truxton_child_file_set_name(child, "Custom Exploits Folder");
FILETIME now;
GetSystemTimeAsFileTime(&now);
ULARGE_INTEGER ticks;
ticks.LowPart = now.dwLowDateTime;
ticks.HighPart = now.dwHighDateTime;
truxton_child_file_set_created(child, ticks.QuadPart);
truxton_child_file_set_accessed(child, ticks.QuadPart);
truxton_child_file_set_modified(child, ticks.QuadPart);
truxton_child_file_set_disk_offset(child, 5464419);
truxton_child_file_set_path(child, "Files/This File" );
if ( truxton_child_file_save(child) == 0 )
{
printf( "Failed to add child to Truxton\n" );
}
truxton_child_file_destroy(child);
}