1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258
|
/*
* The cell values definition of a Windows NT Registry File (REGF)
*
* Copyright (C) 2009-2016, Joachim Metz <joachim.metz@gmail.com>
*
* Refer to AUTHORS for acknowledgements.
*
* This software is free software: you can redistribute it and/or modify
* it under the terms of the GNU Lesser General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This software is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public License
* along with this software. If not, see <http://www.gnu.org/licenses/>.
*/
#if !defined( _REGF_CELL_VALUES_H )
#define _REGF_CELL_VALUES_H
#include <common.h>
#include <types.h>
#if defined( __cplusplus )
extern "C" {
#endif
typedef struct regf_named_key regf_named_key_t;
struct regf_named_key
{
/* The signature
* Consists of 2 bytes
* Contains: "nk"
*/
uint8_t signature[ 2 ];
/* The flags
* Consists of 2 bytes
*/
uint8_t flags[ 2 ];
/* The key last written date and time
* Consists of 8 bytes
*/
uint8_t last_written_time[ 8 ];
/* Unknown
* Consists of 4 bytes
*/
uint8_t unknown1[ 4 ];
/* The parent key offset
* Consists of 4 bytes
*/
uint8_t parent_key_offset[ 4 ];
/* The number of sub keys
* Consists of 4 bytes
*/
uint8_t number_of_sub_keys[ 4 ];
/* The number of volatile sub keys
* Consists of 4 bytes
*/
uint8_t number_of_volatile_sub_keys[ 4 ];
/* The sub keys list offset
* Consists of 4 bytes
*/
uint8_t sub_keys_list_offset[ 4 ];
/* The volatile sub keys list offset
* Consists of 4 bytes
*/
uint8_t volatile_sub_keys_list_offset[ 4 ];
/* The number of values
* Consists of 4 bytes
*/
uint8_t number_of_values[ 4 ];
/* The values list offset
* Consists of 4 bytes
*/
uint8_t values_list_offset[ 4 ];
/* The security key offset
* Consists of 4 bytes
*/
uint8_t security_key_offset[ 4 ];
/* The class name offset
* Consists of 4 bytes
*/
uint8_t class_name_offset[ 4 ];
/* The largest sub key name size
* Consists of 4 bytes
*/
uint8_t largest_sub_key_name_size[ 4 ];
/* The largest sub key class name size
* Consists of 4 bytes
*/
uint8_t largest_sub_key_class_name_size[ 4 ];
/* The largest value name size
* Consists of 4 bytes
*/
uint8_t largest_value_name_size[ 4 ];
/* The largest value data size
* Consists of 4 bytes
*/
uint8_t largest_value_data_size[ 4 ];
/* Unknown
* Consists of 4 bytes
*/
uint8_t unknown6[ 4 ];
/* The key name size
* Consists of 2 bytes
*/
uint8_t key_name_size[ 2 ];
/* The class name size
* Consists of 2 bytes
*/
uint8_t class_name_size[ 2 ];
/* The key name
*/
};
typedef struct regf_sub_key_list regf_sub_key_list_t;
struct regf_sub_key_list
{
/* The signature
* Consists of 2 bytes
* Contains: "lf", "lh", "li" or "ri"
*/
uint8_t signature[ 2 ];
/* The number of elements
* Consists of 2 bytes
*/
uint8_t number_of_elements[ 2 ];
};
typedef struct regf_security_key regf_security_key_t;
struct regf_security_key
{
/* The signature
* Consists of 2 bytes
* Contains: "sk"
*/
uint8_t signature[ 2 ];
/* Unknown
* Consists of 2 bytes
*/
uint8_t unknown1[ 2 ];
/* The previous security key offset
* Consists of 4 bytes
*/
uint8_t previous_security_key_offset[ 4 ];
/* The next security key offset
* Consists of 4 bytes
*/
uint8_t next_security_key_offset[ 4 ];
/* The reference count
* Consists of 4 bytes
*/
uint8_t reference_count[ 4 ];
};
typedef struct regf_value_key regf_value_key_t;
struct regf_value_key
{
/* The signature
* Consists of 2 bytes
* Contains: "vk"
*/
uint8_t signature[ 2 ];
/* The value name size
* Consists of 2 bytes
*/
uint8_t value_name_size[ 2 ];
/* The data size
* Consists of 4 bytes
*/
uint8_t data_size[ 4 ];
/* The data offset
* Consists of 4 bytes
*/
uint8_t data_offset[ 4 ];
/* The data type
* Consists of 4 bytes
*/
uint8_t data_type[ 4 ];
/* The flags
* Consists of 2 bytes
*/
uint8_t flags[ 2 ];
/* Unknown
* Consists of 2 bytes
*/
uint8_t unknown1[ 2 ];
/* The value name
*/
};
typedef struct regf_data_block_key regf_data_block_key_t;
struct regf_data_block_key
{
/* The signature
* Consists of 2 bytes
* Contains: "db"
*/
uint8_t signature[ 2 ];
/* The number of segments
* Consists of 2 bytes
*/
uint8_t number_of_segments[ 2 ];
/* The data block segment list offset
* Consists of 4 bytes
*/
uint8_t data_block_list_offset[ 4 ];
};
#if defined( __cplusplus )
}
#endif
#endif /* !defined( _REGF_CELL_VALUES_H ) */
|