Difference between revisions of "Truxton child file get attributes"
Jump to navigation
Jump to search
| Line 17: | Line 17: | ||
=Sample= | =Sample= | ||
<source lang="C" highlight="35"> | <source lang="C" highlight="35"> | ||
| − | void add_folder(uint64_t truxton, uint64_t parent_file) | + | void add_folder( uint64_t truxton, uint64_t parent_file ) |
{ | { | ||
| − | truxton_start_adding_files(truxton); | + | truxton_start_adding_files( truxton ); |
| − | uint64_t child = truxton_child_file_create(truxton); | + | uint64_t child = truxton_child_file_create( truxton ); |
char id[40]; | char id[40]; | ||
| − | truxton_file_get_id(parent_file, id, sizeof(id)); | + | truxton_file_get_id( parent_file, id, sizeof(id) ); |
| − | truxton_child_file_set_parent_id(child, id); | + | truxton_child_file_set_parent_id( child, id ); |
| − | truxton_child_file_set_type(child, Type_Directory); | + | truxton_child_file_set_type( child, Type_Directory ); |
| − | truxton_child_file_set_name(child, "Custom Exploits Folder"); | + | truxton_child_file_set_name( child, "Custom Exploits Folder" ); |
FILETIME now; | FILETIME now; | ||
| − | GetSystemTimePreciseAsFileTime(&now); | + | GetSystemTimePreciseAsFileTime( &now ); |
ULARGE_INTEGER ticks; | ULARGE_INTEGER ticks; | ||
| Line 39: | Line 39: | ||
ticks.HighPart = now.dwHighDateTime; | ticks.HighPart = now.dwHighDateTime; | ||
| − | truxton_child_file_set_created(child, ticks.QuadPart); | + | truxton_child_file_set_created( child, ticks.QuadPart ); |
| − | truxton_child_file_set_accessed(child, ticks.QuadPart); | + | truxton_child_file_set_accessed( child, ticks.QuadPart ); |
| − | truxton_child_file_set_modified(child, ticks.QuadPart); | + | truxton_child_file_set_modified( child, ticks.QuadPart ); |
| − | truxton_child_file_set_origin(child, ORIGIN_GENERATED); | + | truxton_child_file_set_origin( child, ORIGIN_GENERATED ); |
| − | if ( truxton_child_file_save(child) == 0 ) | + | if ( truxton_child_file_save( child ) == 0 ) |
{ | { | ||
printf( "Failed to add child to Truxton\n" ); | printf( "Failed to add child to Truxton\n" ); | ||
| Line 51: | Line 51: | ||
else | else | ||
{ | { | ||
| − | uint64_t attributes = truxton_child_file_get_attributes(child_file); | + | uint64_t attributes = truxton_child_file_get_attributes( child_file ); |
printf( "Atrributes is %" PRIu64 "\n", attributes ); | printf( "Atrributes is %" PRIu64 "\n", attributes ); | ||
} | } | ||
| − | truxton_child_file_destroy(child); | + | truxton_child_file_destroy( child ); |
} | } | ||
</source> | </source> | ||
| + | |||
| + | The <code>PRIu64</code> in the sample code above is a standard way of [https://en.wikipedia.org/wiki/C_data_types#Printf_and_scanf_format_specifiers formatting] a 64-bit unsigned integer in C. | ||
| + | Over the years, different compilers on different operating systems used different format specifiers for things, these <code>PRI</code> macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic. | ||
Revision as of 07:35, 6 February 2021
This retrieves the attributes of the child file.
This corresponds to the [Attributes] column of the [File] table.
Contents
Syntax
uint64_t truxton_child_file_get_attributes( uint64_t child_handle );
Parameters
child_handle
The handle created by the truxton_child_file_create or truxton_file_create_child call.
Return
The attributes of the file. For a Microsoft filesystem, it will return a combination of the file attribute flags.
Sample
void add_folder( uint64_t truxton, uint64_t parent_file )
{
truxton_start_adding_files( truxton );
uint64_t child = truxton_child_file_create( truxton );
char id[40];
truxton_file_get_id( parent_file, id, sizeof(id) );
truxton_child_file_set_parent_id( child, id );
truxton_child_file_set_type( child, Type_Directory );
truxton_child_file_set_name( child, "Custom Exploits Folder" );
FILETIME now;
GetSystemTimePreciseAsFileTime( &now );
ULARGE_INTEGER ticks;
ticks.LowPart = now.dwLowDateTime;
ticks.HighPart = now.dwHighDateTime;
truxton_child_file_set_created( child, ticks.QuadPart );
truxton_child_file_set_accessed( child, ticks.QuadPart );
truxton_child_file_set_modified( child, ticks.QuadPart );
truxton_child_file_set_origin( child, ORIGIN_GENERATED );
if ( truxton_child_file_save( child ) == 0 )
{
printf( "Failed to add child to Truxton\n" );
}
else
{
uint64_t attributes = truxton_child_file_get_attributes( child_file );
printf( "Atrributes is %" PRIu64 "\n", attributes );
}
truxton_child_file_destroy( child );
}
The PRIu64 in the sample code above is a standard way of formatting a 64-bit unsigned integer in C.
Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.