File: usnjls_lib.c

package info (click to toggle)
sleuthkit 4.12.1%2Bdfsg-3
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 18,608 kB
  • sloc: ansic: 143,795; cpp: 52,225; java: 37,892; xml: 2,416; python: 1,076; perl: 874; makefile: 439; sh: 184
file content (330 lines) | stat: -rw-r--r-- 11,371 bytes parent folder | download | duplicates (5)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
/*
** usnjls
** The Sleuth Kit
**
** Given an NTFS image and UsnJrnl file inode, parses its content showing
** the list of recent changes wihtin the File System.
**
** Matteo Cafasso [noxdafox <at> gmail [dot] com]
**
** This software is distributed under the Common Public License 1.0
**
*/

/** \file usnjls_lib.c
 * Contains the library code associated with the TSK usnjs tool
 * to list changes within a NTFS File System.
 */


#include "tsk_fs_i.h"
#include "tsk_ntfs.h"


static void
print_date(time_t secs, time_t subsecs)
{
    char buf[128];

    tsk_fs_time_to_str_subsecs(secs, subsecs, buf);
    tsk_fprintf(stdout, "%s", buf);
}


/*
 * unpack reason field and print its content
 */
static void
print_usn_reason(TSK_FS_USN_REASON reason)
{
    uint32_t flag = 1;

    for (flag = 1; flag > 0 && flag <= reason; flag *= 2)
        if (reason & flag)
            switch (flag) {
            case TSK_FS_USN_REASON_DATA_OVERWRITE:
                tsk_fprintf(stdout, "DATA_OVERWRITE ");
                break;
            case TSK_FS_USN_REASON_DATA_EXTEND:
                tsk_fprintf(stdout, "DATA_EXTEND ");
                break;
            case TSK_FS_USN_REASON_DATA_TRUNCATION:
                tsk_fprintf(stdout, "DATA_TRUNCATION ");
                break;
            case TSK_FS_USN_REASON_NAMED_DATA_OVERWRITE:
                tsk_fprintf(stdout, "NAMED_DATA_OVERWRITE ");
                break;
            case TSK_FS_USN_REASON_NAMED_DATA_EXTEND:
                tsk_fprintf(stdout, "NAMED_DATA_EXTEND ");
                break;
            case TSK_FS_USN_REASON_NAMED_DATA_TRUNCATION:
                tsk_fprintf(stdout, "NAMED_DATA_TRUNCATION ");
                break;
            case TSK_FS_USN_REASON_FILE_CREATE:
                tsk_fprintf(stdout, "FILE_CREATE ");
                break;
            case TSK_FS_USN_REASON_FILE_DELETE:
                tsk_fprintf(stdout, "FILE_DELETE ");
                break;
            case TSK_FS_USN_REASON_EA_CHANGE:
                tsk_fprintf(stdout, "EA_CHANGE ");
                break;
            case TSK_FS_USN_REASON_SECURITY_CHANGE:
                tsk_fprintf(stdout, "SECURITY_CHANGE ");
                break;
            case TSK_FS_USN_REASON_RENAME_OLD_NAME:
                tsk_fprintf(stdout, "RENAME_OLD_NAME ");
                break;
            case TSK_FS_USN_REASON_RENAME_NEW_NAME:
                tsk_fprintf(stdout, "RENAME_NEW_NAME ");
                break;
            case TSK_FS_USN_REASON_INDEXABLE_CHANGE:
                tsk_fprintf(stdout, "INDEXABLE_CHANGE ");
                break;
            case TSK_FS_USN_REASON_BASIC_INFO_CHANGE:
                tsk_fprintf(stdout, "BASIC_INFO_CHANGE ");
                break;
            case TSK_FS_USN_REASON_HARD_LINK_CHANGE:
                tsk_fprintf(stdout, "HARD_LINK_CHANGE ");
                break;
            case TSK_FS_USN_REASON_COMPRESSION_CHANGE:
                tsk_fprintf(stdout, "COMPRESSION_CHANGE ");
                break;
            case TSK_FS_USN_REASON_ENCRYPTION_CHANGE:
                tsk_fprintf(stdout, "ENCRYPTION_CHANGE ");
                break;
            case TSK_FS_USN_REASON_OBJECT_ID_CHANGE:
                tsk_fprintf(stdout, "OBJECT_ID_CHANGE ");
                break;
            case TSK_FS_USN_REASON_REPARSE_POINT_CHANGE:
                tsk_fprintf(stdout, "REPARSE_POINT_CHANGE ");
                break;
            case TSK_FS_USN_REASON_STREAM_CHANGE:
                tsk_fprintf(stdout, "STREAM_CHANGE ");
                break;
            case TSK_FS_USN_REASON_CLOSE:
                tsk_fprintf(stdout, "CLOSE ");
                break;
            default:
                tsk_fprintf(stdout, "UNKNOWN ");
                break;
            }
}


/*
 * unpack source info field and print its content
 */
static void
print_usn_source_info(TSK_FS_USN_SOURCE_INFO sinfo)
{
    uint32_t flag = 1;

    for (flag = 1; flag > 0 && flag <= sinfo; flag *= 2)
        if (sinfo & flag)
            switch (flag) {
            case TSK_FS_USN_SOURCE_INFO_DATA_MANAGEMENT:
                tsk_fprintf(stdout, "DATA_MANAGEMENT ");
                break;
            case TSK_FS_USN_SOURCE_INFO_AUXILIARY_DATA:
                tsk_fprintf(stdout, "AUXILIARY_DATA ");
                break;
            case TSK_FS_USN_SOURCE_INFO_REPLICATION_MANAGEMENT:
                tsk_fprintf(stdout, "REPLICATION_MANAGEMENT ");
                break;
            case TSK_FS_USN_SOURCE_INFO_CLIENT_REPLICATION_MANAGEMENT:
                tsk_fprintf(stdout, "CLIENT_REPLICATION_MANAGEMENT ");
                break;
            default:
                tsk_fprintf(stdout, "UNKNOWN ");
                break;
            }
}


/*
 * unpack attributes field and print its content
 */
static void
print_usn_attributes(TSK_FS_NTFS_FILE_ATTRIBUTES attributes)
{
    uint32_t flag = 1;

    for (flag = 1; flag > 0 && flag <= attributes; flag *= 2)
        if (attributes & flag)
            switch (flag) {
            case TSK_FS_NTFS_FILE_ATTRIBUTE_READONLY:
                tsk_fprintf(stdout, "READONLY ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_HIDDEN:
                tsk_fprintf(stdout, "HIDDEN ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_SYSTEM:
                tsk_fprintf(stdout, "SYSTEM ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_DIRECTORY:
                tsk_fprintf(stdout, "DIRECTORY ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_ARCHIVE:
                tsk_fprintf(stdout, "ARCHIVE ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_DEVICE:
                tsk_fprintf(stdout, "DEVICE ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_NORMAL:
                tsk_fprintf(stdout, "NORMAL ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_TEMPORARY:
                tsk_fprintf(stdout, "TEMPORARY ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_SPARSE_FILE:
                tsk_fprintf(stdout, "SPARSE_FILE ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_REPARSE_POINT:
                tsk_fprintf(stdout, "REPARSE_POINT ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_COMPRESSED:
                tsk_fprintf(stdout, "COMPRESSED ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_OFFLINE:
                tsk_fprintf(stdout, "OFFLINE ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_NOT_CONTENT_INDEXED:
                tsk_fprintf(stdout, "NOT_CONTENT_INDEXED ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_ENCRYPTED:
                tsk_fprintf(stdout, "ENCRYPTED ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_INTEGRITY_STREAM:
                tsk_fprintf(stdout, "INTEGRITY_STREAM ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_VIRTUAL:
                tsk_fprintf(stdout, "VIRTUAL ");
                break;
            case TSK_FS_NTFS_FILE_ATTRIBUTE_NO_SCRUB_DATA:
                tsk_fprintf(stdout, "NO_SCRUB_DATA ");
                break;
            default:
                tsk_fprintf(stdout, "UNKNOWN ");
                break;
            }
}


static TSK_WALK_RET_ENUM
print_v2_record(TSK_USN_RECORD_HEADER *header, TSK_USN_RECORD_V2 *record)
{
    tsk_fprintf(stdout, "%" PRIu64 "-%" PRIu32 "\t" "%" PRIu64 "-%" PRIu32 "\t"
                "%" PRIu32 ".%" PRIu32 "\t",
                record->refnum, record->refnum_seq, record->parent_refnum,
                record->parent_refnum_seq, record->time_sec, record->time_nsec);
    print_usn_reason(record->reason);
    tsk_fprintf(stdout, "\t");
    if (tsk_print_sanitized(stdout, record->fname) == 1)
        return TSK_WALK_ERROR;
    tsk_fprintf(stdout, "\n");

    return TSK_WALK_CONT;
}


static TSK_WALK_RET_ENUM
print_v2_record_long(TSK_USN_RECORD_HEADER *header, TSK_USN_RECORD_V2 *record)
{
    tsk_fprintf(stdout,
                "Version: %" PRIu32 ".%" PRIu32 " Length: %" PRIu32 "\n"
                "Reference Number: %" PRIu64 "-%" PRIu32 "\n"
                "Parent Reference Number: %" PRIu64 "-%" PRIu32 "\n"
                "Update Sequence Number: %" PRIu32 "\n",
                header->major_version, header->minor_version,
                header->length, record->refnum, record->refnum_seq,
                record->parent_refnum, record->parent_refnum_seq, record->usn);
    tsk_fprintf(stdout, "Time: ");
    print_date(record->time_sec, record->time_nsec);
    tsk_fprintf(stdout, "\n");
    tsk_fprintf(stdout, "Reason: ");
    print_usn_reason(record->reason);
    tsk_fprintf(stdout, "\n");
    tsk_fprintf(stdout, "Source Info: ");
    print_usn_source_info(record->source_info);
    tsk_fprintf(stdout, "\n");
    tsk_fprintf(stdout, "Security Id: %" PRIu32 "\n", record->security);
    tsk_fprintf(stdout, "Attributes: ");
    print_usn_attributes(record->attributes);
    tsk_fprintf(stdout, "\n");
    tsk_fprintf(stdout, "Name: ");
    if (tsk_print_sanitized(stdout, record->fname) == 1)
        return TSK_WALK_ERROR;
    tsk_fprintf(stdout, "\n\n");

    return TSK_WALK_CONT;
}


static TSK_WALK_RET_ENUM
print_v2_record_mac(TSK_USN_RECORD_HEADER *header, TSK_USN_RECORD_V2 *record)
{
    tsk_fprintf(stdout, "%" PRIu32 ".%" PRIu32 "|" "%" PRIu32 "|"
                "%" PRIu64 "-%" PRIu32 "|" "%" PRIu64 "-%" PRIu32 "|"
                "%" PRIu32 "|" "%" PRIu32 ".%" PRIu32 "|" "%" PRIu32 "|"
                "%" PRIu32 "|" "%" PRIu32 "|" "%" PRIu32 "|",
                header->major_version, header->minor_version,
                header->length, record->refnum, record->refnum_seq,
                record->parent_refnum, record->parent_refnum_seq,
                record->usn, record->time_sec, record->time_nsec,
                record->reason, record->source_info, record->security,
                record->attributes);
    if (tsk_print_sanitized(stdout, record->fname) == 1)
        return TSK_WALK_ERROR;
    tsk_fprintf(stdout, "\n");

    return TSK_WALK_CONT;
}


/*
 * call back action function for usnjentry_walk
 */
static TSK_WALK_RET_ENUM
print_usnjent_act(TSK_USN_RECORD_HEADER *a_header, void *a_record, void *a_ptr)
{
    TSK_FS_USNJLS_FLAG_ENUM *flag = (TSK_FS_USNJLS_FLAG_ENUM*) a_ptr;

    switch(a_header->major_version) {
    case 2: {
        TSK_USN_RECORD_V2 *record = (TSK_USN_RECORD_V2 *) a_record;

        switch(*flag) {
        case TSK_FS_USNJLS_NONE:
            return print_v2_record(a_header, record);
        case TSK_FS_USNJLS_LONG:
            return print_v2_record_long(a_header, record);
        case TSK_FS_USNJLS_MAC:
            return print_v2_record_mac(a_header, record);
        }
    }
    default: return TSK_WALK_ERROR;
    }
}


/* Returns 0 on success and 1 on error */
uint8_t
tsk_fs_usnjls(TSK_FS_INFO * fs, TSK_INUM_T inode, TSK_FS_USNJLS_FLAG_ENUM flags)
{
    uint8_t ret = 0;

    tsk_error_reset();

    if (fs == NULL || fs->ftype != TSK_FS_TYPE_NTFS) {
        tsk_error_set_errno(TSK_ERR_FS_ARG);
        tsk_error_set_errstr("Invalid FS type, valid types: NTFS");
        return 1;
    }

    ret = tsk_ntfs_usnjopen(fs, inode);
    if (ret == 1)
        return 1;

    return tsk_ntfs_usnjentry_walk(fs, print_usnjent_act, &flags);
}