diff --git a/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/EmbeddedFileExtractorIngestModule.java b/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/EmbeddedFileExtractorIngestModule.java index 5e67e9da8b..0fee416799 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/EmbeddedFileExtractorIngestModule.java +++ b/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/EmbeddedFileExtractorIngestModule.java @@ -30,6 +30,7 @@ import org.sleuthkit.autopsy.modules.filetypeid.FileTypeDetector; import net.sf.sevenzipjbinding.SevenZipNativeInitializationException; import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException; import org.sleuthkit.autopsy.ingest.FileIngestModuleAdapter; +import org.sleuthkit.autopsy.ingest.IngestModuleReferenceCounter; /** * A file level ingest module that extracts embedded files from supported @@ -48,8 +49,10 @@ public final class EmbeddedFileExtractorIngestModule extends FileIngestModuleAda private String moduleDirRelative; private String moduleDirAbsolute; private MSOfficeEmbeddedContentExtractor officeExtractor; - private SevenZipExtractor archiveExtractor; + private static SevenZipExtractor archiveExtractor; private FileTypeDetector fileTypeDetector; + private long jobId; + private static final IngestModuleReferenceCounter refCounter = new IngestModuleReferenceCounter(); /** * Constructs a file level ingest module that extracts embedded files from @@ -66,10 +69,11 @@ public final class EmbeddedFileExtractorIngestModule extends FileIngestModuleAda * case database for extracted (derived) file paths. The absolute path * is used to write the extracted (derived) files to local storage. */ + jobId = context.getJobId(); try { - final Case currentCase = Case.getCurrentCaseThrows(); - moduleDirRelative = Paths.get(currentCase.getModuleOutputDirectoryRelativePath(), EmbeddedFileExtractorModuleFactory.getModuleName()).toString(); - moduleDirAbsolute = Paths.get(currentCase.getModuleDirectory(), EmbeddedFileExtractorModuleFactory.getModuleName()).toString(); + final Case currentCase = Case.getCurrentCaseThrows(); + moduleDirRelative = Paths.get(currentCase.getModuleOutputDirectoryRelativePath(), EmbeddedFileExtractorModuleFactory.getModuleName()).toString(); + moduleDirAbsolute = Paths.get(currentCase.getModuleDirectory(), EmbeddedFileExtractorModuleFactory.getModuleName()).toString(); } catch (NoCurrentCaseException ex) { throw new IngestModuleException(Bundle.EmbeddedFileExtractorIngestModule_NoOpenCase_errMsg(), ex); } @@ -93,16 +97,17 @@ public final class EmbeddedFileExtractorIngestModule extends FileIngestModuleAda } catch (FileTypeDetector.FileTypeDetectorInitException ex) { throw new IngestModuleException(Bundle.CannotRunFileTypeDetection(), ex); } + if (refCounter.incrementAndGet(jobId) == 1) { + /* + * Construct a 7Zip file extractor for processing archive files. + */ + try { + this.archiveExtractor = new SevenZipExtractor(context, fileTypeDetector, moduleDirRelative, moduleDirAbsolute); + } catch (SevenZipNativeInitializationException ex) { + throw new IngestModuleException(Bundle.UnableToInitializeLibraries(), ex); + } - /* - * Construct a 7Zip file extractor for processing archive files. - */ - try { - this.archiveExtractor = new SevenZipExtractor(context, fileTypeDetector, moduleDirRelative, moduleDirAbsolute); - } catch (SevenZipNativeInitializationException ex) { - throw new IngestModuleException(Bundle.UnableToInitializeLibraries(), ex); } - /* * Construct an embedded content extractor for processing Microsoft * Office documents. @@ -112,6 +117,7 @@ public final class EmbeddedFileExtractorIngestModule extends FileIngestModuleAda } catch (NoCurrentCaseException ex) { throw new IngestModuleException(Bundle.EmbeddedFileExtractorIngestModule_UnableToGetMSOfficeExtractor_errMsg(), ex); } + } @Override @@ -150,6 +156,11 @@ public final class EmbeddedFileExtractorIngestModule extends FileIngestModuleAda return ProcessResult.OK; } + @Override + public void shutDown() { + refCounter.decrementAndGet(jobId); + } + /** * Creates a unique name for a file by concatentating the file name and the * file object id. diff --git a/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/SevenZipExtractor.java b/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/SevenZipExtractor.java index 9e78e0d58e..3b8ced7752 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/SevenZipExtractor.java +++ b/Core/src/org/sleuthkit/autopsy/modules/embeddedfileextractor/SevenZipExtractor.java @@ -85,7 +85,7 @@ class SevenZipExtractor { private static final long MIN_COMPRESSION_RATIO_SIZE = 500 * 1000000L; private static final long MIN_FREE_DISK_SPACE = 1 * 1000 * 1000000L; //1GB //counts archive depth - private ArchiveDepthCountTree archiveDepthCountTree; + private volatile ArchiveDepthCountTree archiveDepthCountTree; private String moduleDirRelative; private String moduleDirAbsolute; @@ -150,8 +150,8 @@ class SevenZipExtractor { } } return false; - } - + } + /** * Check if the item inside archive is a potential zipbomb * @@ -460,7 +460,7 @@ class SevenZipExtractor { * * @param archiveFile file to unpack * - * @return list of unpacked derived files + * @return true if unpacking is complete */ void unpack(AbstractFile archiveFile) { unpack(archiveFile, null); @@ -473,7 +473,7 @@ class SevenZipExtractor { * @param archiveFile - file to unpack * @param password - the password to use, null for no password * - * @return list of unpacked derived files + * @return true if unpacking is complete */ @Messages({"SevenZipExtractor.indexError.message=Failed to index encryption detected artifact for keyword search."}) boolean unpack(AbstractFile archiveFile, String password) { @@ -580,7 +580,8 @@ class SevenZipExtractor { //check if possible zip bomb if (isZipBombArchiveItemCheck(archiveFile, item)) { - continue; //skip the item + unpackSuccessful = false; + return unpackSuccessful; } SevenZipExtractor.UnpackedTree.UnpackedNode unpackedNode = unpackedTree.addNode(pathInArchive); //update progress bar