Truxton etl set poly file expander

From truxwiki.com
Revision as of 03:59, 5 December 2020 by Sam (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

This API tells Truxton that your ETL handles data that resides in multiple files all of which must be processed as a single unit. A Poly expander resides in the Semi-Chaotic stage of an exploitation effort.

Syntax

void truxton_etl_set_poly_file_expander( uint64_t etl_handle, uint32_t poly_file );

Parameters

etl_handle

The handle created by the truxton_etl_create call.

poly_file

When set to a non-zero value, it will tell Truxton that you are a poly-file expander. Calling this API with zero tells Truxton that you are a single-file expander.

Remarks

By default, Truxton assumes that ETL processes are single-file. A poly-file expander is a process that requires multiple files in order to successfully expand. An example of this situation is a spanned zip file where all of the pieces of the zip archive must be gathered before unzipping it.

Sample

#include <TruxtonCAPI.h>

void main( void )
{
    char file_id[ 65 ];

    uint64_t message = 0;
    uint64_t app = truxton_etl_create();

    truxton_etl_set_application_name( app, "Sample C ETL" );
    truxton_etl_set_stage_number( app, 33 );
    truxton_etl_set_queue_name( app, "SampleC" );

    truxton_etl_set_poly_file( app, 0 );

    // Pause here until we get a message from the "SampleC" message queue
    message = truxton_etl_get_message( app );

    while( message != 0 )
    {
        // Do something with the message

        memset( file_id, 0x00, sizeof( file_id ) );
        truxton_message_get_file_id( message, file_id, sizeof( file_id ) );

        printf( "Received file id %s\n", file_id );

        truxton_message_destroy( message );

        // Pause here until we get another message from the "SampleC" message queue
        message = truxton_etl_get_message( app );
    }

    truxton_etl_destroy( app );
}