Truxton child file get disk offset
Jump to navigation
Jump to search
This retrieves the offset in the physical disk where the first byte of the file contents was stored.
Syntax
uint64_t truxton_child_file_get_disk_offset( uint64_t child_handle );
Parameters
child_handle
The handle created by the truxton_child_file_create or truxton_file_create_child call.
Return value
The offset, in bytes, where the first byte of file contents was stored.
Remarks
If the media being loaded was not some form of raw storage, this will return a non-zero value. Zero will be returned if the media wasn't a storage device (like a logical files).
Sample
void add_folder(uint64_t truxton, uint64_t parent_file)
{
truxton_start_adding_files(truxton);
uint64_t child = truxton_child_file_create(truxton);
char id[40];
truxton_file_get_id(parent_file, id, sizeof(id));
truxton_child_file_set_parent_id(child, id);
truxton_child_file_set_type(child, Type_Directory);
truxton_child_file_set_name(child, "Custom Exploits Folder");
FILETIME now;
GetSystemTimeAsFileTime(&now);
ULARGE_INTEGER ticks;
ticks.LowPart = now.dwLowDateTime;
ticks.HighPart = now.dwHighDateTime;
truxton_child_file_set_created(child, ticks.QuadPart);
truxton_child_file_set_accessed(child, ticks.QuadPart);
truxton_child_file_set_modified(child, ticks.QuadPart);
truxton_child_file_set_origin(child, ORIGIN_GENERATED);
if ( truxton_child_file_save(child) == 0 )
{
printf( "Failed to add child to Truxton\n" );
}
else
{
ticks.QuadPart = truxton_child_file_get_disk_offset(child_file);
printf( "Physical Disk Offset was %d\n", ticks.QuadPart );
}
truxton_child_file_destroy(child);
}