mirror of
https://github.com/elisspace/autopsy.git
synced 2026-09-29 13:59:52 +00:00
cleanup FirefoxExtractor and fix it for new approach.
This commit is contained in:
@@ -40,11 +40,11 @@ import org.sleuthkit.autopsy.casemodule.services.FileManager;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.datamodel.ContentUtils;
|
||||
import org.sleuthkit.autopsy.ingest.IngestJobContext;
|
||||
import org.sleuthkit.autopsy.ingest.IngestServices;
|
||||
import org.sleuthkit.autopsy.ingest.ModuleDataEvent;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
import org.sleuthkit.datamodel.Blackboard;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_ACCOUNT;
|
||||
import org.sleuthkit.datamodel.BlackboardAttribute;
|
||||
import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME;
|
||||
@@ -68,7 +68,7 @@ import org.sleuthkit.datamodel.TskData;
|
||||
/**
|
||||
* Chrome recent activity extraction
|
||||
*/
|
||||
class ChromeExtractor extends Extractor {
|
||||
final class ChromeExtractor extends Extractor {
|
||||
|
||||
private static final Logger logger = Logger.getLogger(ChromeExtractor.class.getName());
|
||||
private static final String PARENT_MODULE_NAME = NbBundle.getMessage(ChromeExtractor.class, "Chrome.parentModuleName");
|
||||
@@ -83,6 +83,7 @@ class ChromeExtractor extends Extractor {
|
||||
|
||||
private Content dataSource;
|
||||
private IngestJobContext context;
|
||||
private FileManager fileManager;
|
||||
|
||||
@Override
|
||||
protected String getModuleName() {
|
||||
@@ -104,13 +105,15 @@ class ChromeExtractor extends Extractor {
|
||||
/**
|
||||
* Query for history databases and add artifacts
|
||||
*/
|
||||
private void getHistory() throws TskCoreException {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
@NbBundle.Messages({"# {0} - Extractor / program name",
|
||||
"Extractor.errPostingArtifacts={0}:Error while trying to post artifacts."})
|
||||
private void getHistory() {
|
||||
|
||||
List<AbstractFile> historyFiles;
|
||||
try {
|
||||
historyFiles = fileManager.findFiles(dataSource, "History", "Chrome"); //NON-NLS
|
||||
} catch (TskCoreException ex) {
|
||||
String msg = NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.errGettingFiles");
|
||||
String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errGettingFiles");
|
||||
logger.log(Level.SEVERE, msg, ex);
|
||||
this.addErrorMessage(this.getModuleName() + ": " + msg);
|
||||
return;
|
||||
@@ -126,7 +129,7 @@ class ChromeExtractor extends Extractor {
|
||||
|
||||
// log a message if we don't have any allocated history files
|
||||
if (allocatedHistoryFiles.isEmpty()) {
|
||||
String msg = NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.couldntFindAnyFiles");
|
||||
String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.couldntFindAnyFiles");
|
||||
logger.log(Level.INFO, msg);
|
||||
return;
|
||||
}
|
||||
@@ -146,13 +149,13 @@ class ChromeExtractor extends Extractor {
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
logger.log(Level.WARNING, String.format("Error reading Chrome web history artifacts file '%s' (id=%d).",
|
||||
historyFile.getName(), historyFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.errAnalyzingFile",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errAnalyzingFile",
|
||||
this.getModuleName(), historyFile.getName()));
|
||||
continue;
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome web history artifacts file '%s' (id=%d).",
|
||||
temps, historyFile.getName(), historyFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getHistory.errMsg.errAnalyzingFile",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errAnalyzingFile",
|
||||
this.getModuleName(), historyFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -183,26 +186,36 @@ class ChromeExtractor extends Extractor {
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Util.extractDomain(Objects.toString(result.get("url"), "")))); //NON-NLS
|
||||
bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY, historyFile, bbattributes));
|
||||
try {
|
||||
BlackboardArtifact bbart = historyFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to create Chrome history artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getHistory.errMsg.errAnalyzingFile",
|
||||
this.getModuleName(), historyFile.getName()));
|
||||
}
|
||||
}
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent(
|
||||
PARENT_MODULE_NAME,
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Chrome history artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Search for bookmark files and make artifacts.
|
||||
*/
|
||||
private void getBookmark() {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
List<AbstractFile> bookmarkFiles;
|
||||
try {
|
||||
bookmarkFiles = fileManager.findFiles(dataSource, "Bookmarks", "Chrome"); //NON-NLS
|
||||
} catch (TskCoreException ex) {
|
||||
String msg = NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errGettingFiles");
|
||||
String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errGettingFiles");
|
||||
logger.log(Level.SEVERE, msg, ex);
|
||||
this.addErrorMessage(this.getModuleName() + ": " + msg);
|
||||
return;
|
||||
@@ -215,25 +228,25 @@ class ChromeExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
while (j < bookmarkFiles.size()) {
|
||||
AbstractFile bookmarkFile = bookmarkFiles.get(j++);
|
||||
int index = 0;
|
||||
while (index < bookmarkFiles.size()) {
|
||||
AbstractFile bookmarkFile = bookmarkFiles.get(index++);
|
||||
if (bookmarkFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + bookmarkFile.getName() + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + bookmarkFile.getName() + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(bookmarkFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
logger.log(Level.WARNING, String.format("Error reading Chrome bookmark artifacts file '%s' (id=%d).",
|
||||
bookmarkFile.getName(), bookmarkFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile",
|
||||
this.getModuleName(), bookmarkFile.getName()));
|
||||
continue;
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome bookmark artifacts file '%s' (id=%d).",
|
||||
temps, bookmarkFile.getName(), bookmarkFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile",
|
||||
this.getModuleName(), bookmarkFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -251,7 +264,7 @@ class ChromeExtractor extends Extractor {
|
||||
} catch (FileNotFoundException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to read into the Bookmarks for Chrome.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzeFile", this.getModuleName(),
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzeFile", this.getModuleName(),
|
||||
bookmarkFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -269,7 +282,7 @@ class ChromeExtractor extends Extractor {
|
||||
jBookmarkArray = jBookmark.getAsJsonArray("children"); //NON-NLS
|
||||
} catch (JsonIOException | JsonSyntaxException | IllegalStateException ex) {
|
||||
logger.log(Level.WARNING, "Error parsing Json from Chrome Bookmark.", ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile3",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile3",
|
||||
this.getModuleName(), bookmarkFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -302,10 +315,10 @@ class ChromeExtractor extends Extractor {
|
||||
}
|
||||
String domain = Util.extractDomain(url);
|
||||
try {
|
||||
|
||||
Collection<BlackboardAttribute> bbattributes = Arrays.asList(new BlackboardAttribute(
|
||||
TSK_URL, PARENT_MODULE_NAME,
|
||||
url),
|
||||
Collection<BlackboardAttribute> bbattributes = Arrays.asList(
|
||||
new BlackboardAttribute(
|
||||
TSK_URL, PARENT_MODULE_NAME,
|
||||
url),
|
||||
new BlackboardAttribute(
|
||||
TSK_TITLE, PARENT_MODULE_NAME,
|
||||
name),
|
||||
@@ -318,34 +331,35 @@ class ChromeExtractor extends Extractor {
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
domain));
|
||||
|
||||
bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bookmarkFile, bbattributes));
|
||||
BlackboardArtifact bbart = bookmarkFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to insert Chrome bookmark artifact{0}", ex); //NON-NLS
|
||||
logger.log(Level.SEVERE, "Error while trying to insert Chrome bookmark artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(this.getClass(), "Chrome.getBookmark.errMsg.errAnalyzingFile4",
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getBookmark.errMsg.errAnalyzingFile4",
|
||||
this.getModuleName(), bookmarkFile.getName()));
|
||||
}
|
||||
}
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent(
|
||||
PARENT_MODULE_NAME,
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Chrome bookmark artifact{0}", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Queries for cookie files and adds artifacts
|
||||
*/
|
||||
private void getCookie() throws TskCoreException {
|
||||
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
private void getCookie() {
|
||||
List<AbstractFile> cookiesFiles;
|
||||
try {
|
||||
cookiesFiles = fileManager.findFiles(dataSource, "Cookies", "Chrome"); //NON-NLS
|
||||
} catch (TskCoreException ex) {
|
||||
String msg = NbBundle.getMessage(this.getClass(), "Chrome.getCookie.errMsg.errGettingFiles");
|
||||
String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errGettingFiles");
|
||||
logger.log(Level.SEVERE, msg, ex);
|
||||
this.addErrorMessage(this.getModuleName() + ": " + msg);
|
||||
return;
|
||||
@@ -358,25 +372,25 @@ class ChromeExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
while (j < cookiesFiles.size()) {
|
||||
AbstractFile cookiesFile = cookiesFiles.get(j++);
|
||||
int index = 0;
|
||||
while (index < cookiesFiles.size()) {
|
||||
AbstractFile cookiesFile = cookiesFiles.get(index++);
|
||||
if (cookiesFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + cookiesFile.getName() + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + cookiesFile.getName() + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(cookiesFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
logger.log(Level.WARNING, String.format("Error reading Chrome cookie artifacts file '%s' (id=%d).",
|
||||
cookiesFile.getName(), cookiesFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getCookie.errMsg.errAnalyzeFile",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errAnalyzeFile",
|
||||
this.getModuleName(), cookiesFile.getName()));
|
||||
continue;
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome cookie artifacts file '%s' (id=%d).",
|
||||
temps, cookiesFile.getName(), cookiesFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getCookie.errMsg.errAnalyzeFile",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errAnalyzeFile",
|
||||
this.getModuleName(), cookiesFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -409,27 +423,37 @@ class ChromeExtractor extends Extractor {
|
||||
new BlackboardAttribute(
|
||||
TSK_PROG_NAME, PARENT_MODULE_NAME,
|
||||
getModuleName()));
|
||||
bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_COOKIE, cookiesFile, bbattributes));
|
||||
try {
|
||||
BlackboardArtifact bbart = cookiesFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_COOKIE);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to insert Chrome cookie artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getCookie.errMsg.errAnalyzingFile",
|
||||
this.getModuleName(), cookiesFile.getName()));
|
||||
}
|
||||
}
|
||||
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent(
|
||||
PARENT_MODULE_NAME,
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Chrome cookie artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Queries for download files and adds artifacts
|
||||
*/
|
||||
private void getDownload() throws TskCoreException {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
private void getDownload() {
|
||||
List<AbstractFile> downloadFiles;
|
||||
try {
|
||||
downloadFiles = fileManager.findFiles(dataSource, "History", "Chrome"); //NON-NLS
|
||||
} catch (TskCoreException ex) {
|
||||
String msg = NbBundle.getMessage(this.getClass(), "Chrome.getDownload.errMsg.errGettingFiles");
|
||||
String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errGettingFiles");
|
||||
logger.log(Level.SEVERE, msg, ex);
|
||||
this.addErrorMessage(this.getModuleName() + ": " + msg);
|
||||
return;
|
||||
@@ -442,25 +466,25 @@ class ChromeExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
while (j < downloadFiles.size()) {
|
||||
AbstractFile downloadFile = downloadFiles.get(j++);
|
||||
int index = 0;
|
||||
while (index < downloadFiles.size()) {
|
||||
AbstractFile downloadFile = downloadFiles.get(index++);
|
||||
if (downloadFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + downloadFile.getName() + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + downloadFile.getName() + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(downloadFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
logger.log(Level.WARNING, String.format("Error reading Chrome download artifacts file '%s' (id=%d).",
|
||||
downloadFile.getName(), downloadFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getDownload.errMsg.errAnalyzeFiles1",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errAnalyzeFiles1",
|
||||
this.getModuleName(), downloadFile.getName()));
|
||||
continue;
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome download artifacts file '%s' (id=%d).",
|
||||
temps, downloadFile.getName(), downloadFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getDownload.errMsg.errAnalyzeFiles1",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errAnalyzeFiles1",
|
||||
this.getModuleName(), downloadFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -497,30 +521,37 @@ class ChromeExtractor extends Extractor {
|
||||
if (pathID != -1) {
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH_ID, PARENT_MODULE_NAME, pathID));
|
||||
}
|
||||
BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, downloadFile, bbattributes);
|
||||
if (bbart != null) {
|
||||
try {
|
||||
BlackboardArtifact bbart = downloadFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to insert Chrome download artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getDownload.errMsg.errAnalyzeFiles1",
|
||||
this.getModuleName(), downloadFile.getName()));
|
||||
}
|
||||
}
|
||||
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent(
|
||||
PARENT_MODULE_NAME,
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Chrome download artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Queries for login files and adds artifacts
|
||||
*/
|
||||
private void getLogin() throws TskCoreException, TskCoreException {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
private void getLogin() {
|
||||
List<AbstractFile> signonFiles;
|
||||
try {
|
||||
signonFiles = fileManager.findFiles(dataSource, "signons.sqlite", "Chrome"); //NON-NLS
|
||||
} catch (TskCoreException ex) {
|
||||
String msg = NbBundle.getMessage(this.getClass(), "Chrome.getLogin.errMsg.errGettingFiles");
|
||||
String msg = NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errGettingFiles");
|
||||
logger.log(Level.SEVERE, msg, ex);
|
||||
this.addErrorMessage(this.getModuleName() + ": " + msg);
|
||||
return;
|
||||
@@ -533,25 +564,25 @@ class ChromeExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
while (j < signonFiles.size()) {
|
||||
AbstractFile signonFile = signonFiles.get(j++);
|
||||
int index = 0;
|
||||
while (index < signonFiles.size()) {
|
||||
AbstractFile signonFile = signonFiles.get(index++);
|
||||
if (signonFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + signonFile.getName() + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "chrome") + File.separator + signonFile.getName() + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(signonFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
logger.log(Level.WARNING, String.format("Error reading Chrome login artifacts file '%s' (id=%d).",
|
||||
signonFile.getName(), signonFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getLogin.errMsg.errAnalyzingFiles",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles",
|
||||
this.getModuleName(), signonFile.getName()));
|
||||
continue;
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, String.format("Error writing temp sqlite db file '%s' for Chrome login artifacts file '%s' (id=%d).",
|
||||
temps, signonFile.getName(), signonFile.getId()), ex); //NON-NLS
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Chrome.getLogin.errMsg.errAnalyzingFiles",
|
||||
this.addErrorMessage(NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles",
|
||||
this.getModuleName(), signonFile.getName()));
|
||||
continue;
|
||||
}
|
||||
@@ -588,22 +619,47 @@ class ChromeExtractor extends Extractor {
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("signon_realm"), ""))); //NON-NLS
|
||||
|
||||
bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY, signonFile, bbattributes));
|
||||
try {
|
||||
BlackboardArtifact bbart = signonFile.newArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to insert Chrome login artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles",
|
||||
this.getModuleName(), signonFile.getName()));
|
||||
}
|
||||
|
||||
// Don't add TSK_OS_ACCOUNT artifacts to the ModuleDataEvent
|
||||
//TODO: Why not? Because it has a different artifact type?
|
||||
BlackboardAttribute osAcctAttribute = new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_USER_NAME, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("username_value"), "").replaceAll("'", "''")); //NON-NLS
|
||||
//TODO: Why not? Because it has a different artifact type? We can just post it seperately?
|
||||
try {
|
||||
BlackboardAttribute osAcctAttribute = new BlackboardAttribute(TSK_USER_NAME, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("username_value"), "").replaceAll("'", "''")); //NON-NLS
|
||||
BlackboardArtifact osAccountArtifact = signonFile.newArtifact(TSK_OS_ACCOUNT);
|
||||
osAccountArtifact.addAttributes(Collections.singleton(osAcctAttribute));
|
||||
|
||||
this.addArtifact(ARTIFACT_TYPE.TSK_OS_ACCOUNT, signonFile, Collections.singleton(osAcctAttribute));
|
||||
blackboard.postArtifact(osAccountArtifact, PARENT_MODULE_NAME);
|
||||
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to insert Chrome os account artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Chrome.getLogin.errMsg.errAnalyzingFiles",
|
||||
this.getModuleName(), signonFile.getName()));
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Chrome os account artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
IngestServices.getInstance().fireModuleDataEvent(new ModuleDataEvent(
|
||||
PARENT_MODULE_NAME,
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Chrome login artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
private boolean isChromePreVersion30(String temps) {
|
||||
|
||||
@@ -31,8 +31,8 @@ import org.openide.util.NbBundle;
|
||||
import org.openide.util.NbBundle.Messages;
|
||||
import org.sleuthkit.autopsy.casemodule.Case;
|
||||
import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
|
||||
import org.sleuthkit.autopsy.casemodule.services.FileManager;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.coreutils.MessageNotifyUtil;
|
||||
import org.sleuthkit.autopsy.coreutils.SQLiteDBConnect;
|
||||
import org.sleuthkit.autopsy.ingest.IngestJobContext;
|
||||
import org.sleuthkit.autopsy.ingest.IngestModule.IngestModuleException;
|
||||
@@ -44,6 +44,9 @@ abstract class Extractor {
|
||||
|
||||
protected Case currentCase;
|
||||
protected SleuthkitCase tskCase;
|
||||
protected Blackboard blackboard;
|
||||
protected FileManager fileManager;
|
||||
|
||||
private final ArrayList<String> errorMessages = new ArrayList<>();
|
||||
boolean dataFound = false;
|
||||
|
||||
@@ -54,11 +57,16 @@ abstract class Extractor {
|
||||
*/
|
||||
abstract protected String getModuleName();
|
||||
|
||||
@Messages({"Extract.indexError.message=Failed to index artifact for keyword search.",
|
||||
"Extract.noOpenCase.errMsg=No open case available."})
|
||||
final void init() throws IngestModuleException {
|
||||
try {
|
||||
currentCase = Case.getCurrentCaseThrows();
|
||||
tskCase = currentCase.getSleuthkitCase();
|
||||
blackboard = tskCase.getBlackboard();
|
||||
fileManager = currentCase.getServices().getFileManager();
|
||||
} catch (NoCurrentCaseException ex) {
|
||||
//TODO: fix this error message
|
||||
throw new IngestModuleException(Bundle.Extract_indexError_message(), ex);
|
||||
}
|
||||
configExtractor();
|
||||
@@ -95,51 +103,25 @@ abstract class Extractor {
|
||||
errorMessages.add(message);
|
||||
}
|
||||
|
||||
/**
|
||||
* Generic method for adding a blackboard artifact to the blackboard and
|
||||
* indexing it
|
||||
*
|
||||
* @param type is a blackboard.artifact_type enum to determine which
|
||||
* type the artifact should be
|
||||
* @param content is the AbstractFile object that needs to have the
|
||||
* artifact added for it
|
||||
* @param bbattributes is the collection of blackboard attributes that need
|
||||
* to be added to the artifact after the artifact has
|
||||
* been created
|
||||
* @return The newly-created artifact
|
||||
*
|
||||
* @throws org.sleuthkit.datamodel.TskCoreException If there was a problem
|
||||
* creating the artifact.
|
||||
*/
|
||||
protected BlackboardArtifact addArtifact(BlackboardArtifact.ARTIFACT_TYPE type, AbstractFile content, Collection<BlackboardAttribute> bbattributes) throws TskCoreException {
|
||||
BlackboardArtifact bbart = content.newArtifact(type);
|
||||
bbart.addAttributes(bbattributes);
|
||||
// index the artifact for keyword search
|
||||
this.indexArtifact(bbart);
|
||||
return bbart;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to index a blackboard artifact for keyword search
|
||||
*
|
||||
* @param bbart Blackboard artifact to be indexed
|
||||
*/
|
||||
@Messages({"Extract.indexError.message=Failed to index artifact for keyword search.",
|
||||
"Extract.noOpenCase.errMsg=No open case available."})
|
||||
void indexArtifact(BlackboardArtifact bbart) {
|
||||
try {
|
||||
Blackboard blackboard = Case.getCurrentCaseThrows().getSleuthkitCase().getBlackboard();
|
||||
// index the artifact for keyword search
|
||||
blackboard.postArtifact(bbart, getModuleName());
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Unable to index blackboard artifact " + bbart.getDisplayName(), ex); //NON-NLS
|
||||
MessageNotifyUtil.Notify.error(Bundle.Extract_indexError_message(), bbart.getDisplayName());
|
||||
} catch (NoCurrentCaseException ex) {
|
||||
logger.log(Level.SEVERE, "Exception while getting open case.", ex); //NON-NLS
|
||||
MessageNotifyUtil.Notify.error(Bundle.Extract_noOpenCase_errMsg(), bbart.getDisplayName());
|
||||
}
|
||||
}
|
||||
|
||||
//
|
||||
// /**
|
||||
// * Method to index a blackboard artifact for keyword search
|
||||
// *
|
||||
// * @param bbart Blackboard artifact to be indexed
|
||||
// */
|
||||
//
|
||||
// void postArtifacts(Collections<BlackboardArtifact> bbarts) throws Blackboard.BlackboardException {
|
||||
//
|
||||
// // index the artifact for keyword search
|
||||
// blackboard.postArtifact(bbarts, getModuleName());
|
||||
//// } catch (Blackboard.BlackboardException ex) {
|
||||
//// logger.log(Level.SEVERE, "Unable to index blackboard artifact " + bbart.getDisplayName(), ex); //NON-NLS
|
||||
//// MessageNotifyUtil.Notify.error(Bundle.Extract_indexError_message(), bbart.getDisplayName());
|
||||
//// } catch (NoCurrentCaseException ex) {
|
||||
//// logger.log(Level.SEVERE, "Exception while getting open case.", ex); //NON-NLS
|
||||
//// MessageNotifyUtil.Notify.error(Bundle.Extract_noOpenCase_errMsg(), bbart.getDisplayName());
|
||||
//// }
|
||||
// }
|
||||
/**
|
||||
* Returns a List from a result set based on sql query. This is used to
|
||||
* query sqlite databases storing user recent activity data, such as in
|
||||
|
||||
@@ -22,27 +22,42 @@
|
||||
*/
|
||||
package org.sleuthkit.autopsy.recentactivity;
|
||||
|
||||
import com.google.common.collect.Lists;
|
||||
import java.io.File;
|
||||
import java.io.IOException;
|
||||
import java.io.UnsupportedEncodingException;
|
||||
import java.net.URLDecoder;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Arrays;
|
||||
import java.util.Collection;
|
||||
import java.util.HashMap;
|
||||
import java.util.List;
|
||||
import java.util.Objects;
|
||||
import java.util.logging.Level;
|
||||
import org.openide.util.NbBundle;
|
||||
import org.sleuthkit.autopsy.casemodule.services.FileManager;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.datamodel.ContentUtils;
|
||||
import org.sleuthkit.autopsy.ingest.IngestJobContext;
|
||||
import org.sleuthkit.autopsy.ingest.IngestServices;
|
||||
import org.sleuthkit.autopsy.ingest.ModuleDataEvent;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
import org.sleuthkit.datamodel.Blackboard;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY;
|
||||
import org.sleuthkit.datamodel.BlackboardAttribute;
|
||||
import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_CREATED;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DOMAIN;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_NAME;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PATH;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PATH_ID;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PROG_NAME;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_REFERRER;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_TITLE;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_URL;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_VALUE;
|
||||
import org.sleuthkit.datamodel.Content;
|
||||
import org.sleuthkit.datamodel.ReadContentInputStream.ReadContentInputStreamException;
|
||||
import org.sleuthkit.datamodel.TskCoreException;
|
||||
@@ -50,22 +65,25 @@ import org.sleuthkit.datamodel.TskCoreException;
|
||||
/**
|
||||
* Firefox recent activity extraction
|
||||
*/
|
||||
class FirefoxExtractor extends Extractor {
|
||||
final class FirefoxExtractor extends Extractor {
|
||||
|
||||
private static final Logger logger = Logger.getLogger(FirefoxExtractor.class.getName());
|
||||
private static final String PARENT_MODULE_NAME = NbBundle.getMessage(FirefoxExtractor.class,
|
||||
"Firefox.parentModuleName.noSpace");
|
||||
|
||||
private static final String HISTORY_QUERY = "SELECT moz_historyvisits.id,url,title,visit_count,(visit_date/1000000) AS visit_date,from_visit,(SELECT url FROM moz_places WHERE id=moz_historyvisits.from_visit) as ref FROM moz_places, moz_historyvisits WHERE moz_places.id = moz_historyvisits.place_id AND hidden = 0"; //NON-NLS
|
||||
private static final String COOKIE_QUERY = "SELECT name,value,host,expiry,(lastAccessed/1000000) AS lastAccessed,(creationTime/1000000) AS creationTime FROM moz_cookies"; //NON-NLS
|
||||
private static final String COOKIE_QUERY_V3 = "SELECT name,value,host,expiry,(lastAccessed/1000000) AS lastAccessed FROM moz_cookies"; //NON-NLS
|
||||
private static final String BOOKMARK_QUERY = "SELECT fk, moz_bookmarks.title, url, (moz_bookmarks.dateAdded/1000000) AS dateAdded FROM moz_bookmarks INNER JOIN moz_places ON moz_bookmarks.fk=moz_places.id"; //NON-NLS
|
||||
private static final String DOWNLOAD_QUERY = "SELECT target, source,(startTime/1000000) AS startTime, maxBytes FROM moz_downloads"; //NON-NLS
|
||||
private static final String DOWNLOAD_QUERY_V24 = "SELECT url, content AS target, (lastModified/1000000) AS lastModified FROM moz_places, moz_annos WHERE moz_places.id = moz_annos.place_id AND moz_annos.anno_attribute_id = 3"; //NON-NLS
|
||||
private final IngestServices services = IngestServices.getInstance();
|
||||
|
||||
private Content dataSource;
|
||||
private IngestJobContext context;
|
||||
|
||||
@Override
|
||||
protected String getModuleName() {
|
||||
return NbBundle.getMessage(FirefoxExtractor.class, "Firefox.getModuleName()");
|
||||
return NbBundle.getMessage(FirefoxExtractor.class, "Firefox.moduleName");
|
||||
}
|
||||
|
||||
@Override
|
||||
@@ -75,12 +93,12 @@ class FirefoxExtractor extends Extractor {
|
||||
dataFound = false;
|
||||
this.getHistory();
|
||||
this.getBookmark();
|
||||
this.getDownload();
|
||||
getDownloadPreVersion24();
|
||||
getDownloadVersion24();
|
||||
this.getCookie();
|
||||
}
|
||||
|
||||
private void getHistory() {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
List<AbstractFile> historyFiles;
|
||||
try {
|
||||
historyFiles = fileManager.findFiles(dataSource, "places.sqlite", "Firefox"); //NON-NLS
|
||||
@@ -99,14 +117,14 @@ class FirefoxExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
int index = 0;
|
||||
for (AbstractFile historyFile : historyFiles) {
|
||||
if (historyFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
|
||||
String fileName = historyFile.getName();
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(historyFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
@@ -132,52 +150,53 @@ class FirefoxExtractor extends Extractor {
|
||||
List<HashMap<String, Object>> tempList = this.dbConnect(temps, HISTORY_QUERY);
|
||||
logger.log(Level.INFO, "{0} - Now getting history from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS
|
||||
for (HashMap<String, Object> result : tempList) {
|
||||
Collection<BlackboardAttribute> bbattributes = new ArrayList<>();
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("url").toString() != null) ? result.get("url").toString() : ""))); //NON-NLS
|
||||
//bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL_DECODED.getTypeID(), "RecentActivity", ((result.get("url").toString() != null) ? EscapeUtil.decodeURL(result.get("url").toString()) : "")));
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Long.valueOf(result.get("visit_date").toString())))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_REFERRER,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("ref").toString() != null) ? result.get("ref").toString() : ""))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_TITLE,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("title").toString() != null) ? result.get("title").toString() : ""))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()")));
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"), (Util.extractDomain((result.get("url").toString() != null) ? result.get("url").toString() : "")))); //NON-NLS
|
||||
|
||||
BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_HISTORY, historyFile, bbattributes);
|
||||
if (bbart != null) {
|
||||
Collection<BlackboardAttribute> bbattributes = Arrays.asList(
|
||||
new BlackboardAttribute(
|
||||
TSK_URL, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("url"), "")),//NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME,
|
||||
Long.valueOf(result.get("visit_date").toString())), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_REFERRER, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("ref"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_TITLE, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("title"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_PROG_NAME, PARENT_MODULE_NAME,
|
||||
getModuleName()),
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Util.extractDomain(Objects.toString(result.get("url"), "")))); //NON-NLS
|
||||
try {
|
||||
BlackboardArtifact bbart = historyFile.newArtifact(TSK_WEB_HISTORY);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to create Firefox history artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Firefox.getHistory.errMsg.errAnalyzeFile=", //NON-NLS
|
||||
this.getModuleName(), historyFile.getName()));
|
||||
}
|
||||
|
||||
}
|
||||
++j;
|
||||
index++;
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"),
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Firefox history artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Queries for bookmark files and adds artifacts
|
||||
*/
|
||||
private void getBookmark() {
|
||||
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
List<AbstractFile> bookmarkFiles;
|
||||
try {
|
||||
bookmarkFiles = fileManager.findFiles(dataSource, "places.sqlite", "Firefox"); //NON-NLS
|
||||
@@ -195,13 +214,13 @@ class FirefoxExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
int index = 0;
|
||||
for (AbstractFile bookmarkFile : bookmarkFiles) {
|
||||
if (bookmarkFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String fileName = bookmarkFile.getName();
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(bookmarkFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
@@ -227,49 +246,51 @@ class FirefoxExtractor extends Extractor {
|
||||
logger.log(Level.INFO, "{0} - Now getting bookmarks from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS
|
||||
for (HashMap<String, Object> result : tempList) {
|
||||
|
||||
Collection<BlackboardAttribute> bbattributes = new ArrayList<>();
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("url").toString() != null) ? result.get("url").toString() : ""))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_TITLE,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("title").toString() != null) ? result.get("title").toString() : ""))); //NON-NLS
|
||||
if (Long.valueOf(result.get("dateAdded").toString()) > 0) { //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_CREATED,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Long.valueOf(result.get("dateAdded").toString())))); //NON-NLS
|
||||
Collection<BlackboardAttribute> bbattributes = Lists.newArrayList(
|
||||
new BlackboardAttribute(
|
||||
TSK_URL, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("url"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_TITLE, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("title"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_PROG_NAME, PARENT_MODULE_NAME,
|
||||
getModuleName()),
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Util.extractDomain(Objects.toString(result.get("url"), "")))); //NON-NLS
|
||||
Long createdTime = Long.valueOf(result.get("dateAdded").toString());
|
||||
if (createdTime > 0) { //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(
|
||||
TSK_DATETIME_CREATED, PARENT_MODULE_NAME,
|
||||
createdTime)); //NON-NLS
|
||||
}
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()")));
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Util.extractDomain((result.get("url").toString() != null) ? result.get("url").toString() : "")))); //NON-NLS
|
||||
|
||||
BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bookmarkFile, bbattributes);
|
||||
if (bbart != null) {
|
||||
try {
|
||||
BlackboardArtifact bbart = bookmarkFile.newArtifact(TSK_WEB_BOOKMARK);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to create Firefox bookmark artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Firefox.getBookmark.errMsg.errAnalyzeFile=", //NON-NLS
|
||||
this.getModuleName(), bookmarkFile.getName()));
|
||||
}
|
||||
}
|
||||
++j;
|
||||
index++;
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"),
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Firefox bookmark artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Queries for cookies file and adds artifacts
|
||||
*/
|
||||
private void getCookie() {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
List<AbstractFile> cookiesFiles;
|
||||
try {
|
||||
cookiesFiles = fileManager.findFiles(dataSource, "cookies.sqlite", "Firefox"); //NON-NLS
|
||||
@@ -287,13 +308,13 @@ class FirefoxExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
int index = 0;
|
||||
for (AbstractFile cookiesFile : cookiesFiles) {
|
||||
if (cookiesFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String fileName = cookiesFile.getName();
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS
|
||||
try {
|
||||
ContentUtils.writeToFile(cookiesFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
} catch (ReadContentInputStreamException ex) {
|
||||
@@ -317,71 +338,57 @@ class FirefoxExtractor extends Extractor {
|
||||
break;
|
||||
}
|
||||
boolean checkColumn = Util.checkColumn("creationTime", "moz_cookies", temps); //NON-NLS
|
||||
String query;
|
||||
if (checkColumn) {
|
||||
query = COOKIE_QUERY;
|
||||
} else {
|
||||
query = COOKIE_QUERY_V3;
|
||||
}
|
||||
String query = checkColumn ? COOKIE_QUERY : COOKIE_QUERY_V3;
|
||||
|
||||
List<HashMap<String, Object>> tempList = this.dbConnect(temps, query);
|
||||
logger.log(Level.INFO, "{0} - Now getting cookies from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS
|
||||
for (HashMap<String, Object> result : tempList) {
|
||||
|
||||
Collection<BlackboardAttribute> bbattributes = new ArrayList<>();
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("host").toString() != null) ? result.get("host").toString() : ""))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Long.valueOf(result.get("lastAccessed").toString())))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_NAME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("name").toString() != null) ? result.get("name").toString() : ""))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_VALUE,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("value").toString() != null) ? result.get("value").toString() : ""))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()")));
|
||||
|
||||
if (checkColumn == true) {
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_CREATED,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
Collection<BlackboardAttribute> bbattributes = Lists.newArrayList(
|
||||
new BlackboardAttribute(
|
||||
TSK_URL, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("host"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_DATETIME, PARENT_MODULE_NAME,
|
||||
Long.valueOf(result.get("lastAccessed").toString())), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_NAME, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("name"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_VALUE, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("value"), "")), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_PROG_NAME, PARENT_MODULE_NAME,
|
||||
getModuleName()),
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Util.extractDomain(result.get("host").toString()).replaceFirst("^\\.+(?!$)", ""))); //NON-NLS
|
||||
if (checkColumn) {
|
||||
bbattributes.add(new BlackboardAttribute(
|
||||
TSK_DATETIME_CREATED, PARENT_MODULE_NAME,
|
||||
(Long.valueOf(result.get("creationTime").toString())))); //NON-NLS
|
||||
}
|
||||
String domain = Util.extractDomain(result.get("host").toString()); //NON-NLS
|
||||
domain = domain.replaceFirst("^\\.+(?!$)", "");
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"), domain));
|
||||
|
||||
BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_COOKIE, cookiesFile, bbattributes);
|
||||
if (bbart != null) {
|
||||
try {
|
||||
BlackboardArtifact bbart = cookiesFile.newArtifact(TSK_WEB_COOKIE);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to create Firefox cookie artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Firefox.getCookie.errMsg.errAnalyzeFile=", //NON-NLS
|
||||
this.getModuleName(), cookiesFile.getName()));
|
||||
}
|
||||
}
|
||||
++j;
|
||||
++index;
|
||||
dbFile.delete();
|
||||
}
|
||||
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"),
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, bbartifacts));
|
||||
}
|
||||
|
||||
/**
|
||||
* Queries for downloads files and adds artifacts
|
||||
*/
|
||||
private void getDownload() {
|
||||
getDownloadPreVersion24();
|
||||
getDownloadVersion24();
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Firefox cookie artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -391,7 +398,6 @@ class FirefoxExtractor extends Extractor {
|
||||
*/
|
||||
private void getDownloadPreVersion24() {
|
||||
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
List<AbstractFile> downloadsFiles;
|
||||
try {
|
||||
downloadsFiles = fileManager.findFiles(dataSource, "downloads.sqlite", "Firefox"); //NON-NLS
|
||||
@@ -409,13 +415,13 @@ class FirefoxExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
int index = 0;
|
||||
for (AbstractFile downloadsFile : downloadsFiles) {
|
||||
if (downloadsFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String fileName = downloadsFile.getName();
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + index + ".db"; //NON-NLS
|
||||
int errors = 0;
|
||||
try {
|
||||
ContentUtils.writeToFile(downloadsFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
@@ -443,52 +449,43 @@ class FirefoxExtractor extends Extractor {
|
||||
logger.log(Level.INFO, "{0}- Now getting downloads from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS
|
||||
for (HashMap<String, Object> result : tempList) {
|
||||
|
||||
Collection<BlackboardAttribute> bbattributes = new ArrayList<>();
|
||||
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("source").toString() != null) ? result.get("source").toString() : ""))); //NON-NLS
|
||||
//bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL_DECODED.getTypeID(), "RecentActivity", ((result.get("source").toString() != null) ? EscapeUtil.decodeURL(result.get("source").toString()) : "")));
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Long.valueOf(result.get("startTime").toString())))); //NON-NLS
|
||||
Collection<BlackboardAttribute> bbattributes = Lists.newArrayList(
|
||||
new BlackboardAttribute(TSK_URL, PARENT_MODULE_NAME,
|
||||
Objects.toString(result.get("source"), "")), //NON-NLS
|
||||
new BlackboardAttribute(TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME,
|
||||
Long.valueOf(result.get("startTime").toString())), //NON-NLS
|
||||
new BlackboardAttribute(TSK_PROG_NAME, PARENT_MODULE_NAME,
|
||||
getModuleName()),
|
||||
new BlackboardAttribute(TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Util.extractDomain(Objects.toString(result.get("source"), "")))); //NON-NLS
|
||||
|
||||
String target = result.get("target").toString(); //NON-NLS
|
||||
|
||||
if (target != null) {
|
||||
try {
|
||||
String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
decodedTarget));
|
||||
long pathID = Util.findID(dataSource, decodedTarget);
|
||||
if (pathID != -1) {
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH_ID,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
pathID));
|
||||
}
|
||||
} catch (UnsupportedEncodingException ex) {
|
||||
logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS
|
||||
errors++;
|
||||
try {
|
||||
String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(
|
||||
TSK_PATH, PARENT_MODULE_NAME,
|
||||
decodedTarget));
|
||||
long pathID = Util.findID(dataSource, decodedTarget);
|
||||
if (pathID != -1) {
|
||||
bbattributes.add(new BlackboardAttribute(
|
||||
TSK_PATH_ID, PARENT_MODULE_NAME,
|
||||
pathID));
|
||||
}
|
||||
} catch (UnsupportedEncodingException ex) {
|
||||
logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS
|
||||
errors++;
|
||||
}
|
||||
try {
|
||||
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()")));
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Util.extractDomain((result.get("source").toString() != null) ? result.get("source").toString() : "")))); //NON-NLS
|
||||
|
||||
BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, downloadsFile, bbattributes);
|
||||
if (bbart != null) {
|
||||
BlackboardArtifact bbart = downloadsFile.newArtifact(TSK_WEB_DOWNLOAD);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to create Firefox download artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Firefox.getDlPre24.errMsg.errAnalyzeFiles", //NON-NLS
|
||||
this.getModuleName(), downloadsFile.getName()));
|
||||
}
|
||||
}
|
||||
if (errors > 0) {
|
||||
@@ -496,14 +493,16 @@ class FirefoxExtractor extends Extractor {
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.getDlPre24.errMsg.errParsingArtifacts",
|
||||
this.getModuleName(), errors));
|
||||
}
|
||||
j++;
|
||||
index++;
|
||||
dbFile.delete();
|
||||
break;
|
||||
}
|
||||
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"),
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Firefox download artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -512,7 +511,6 @@ class FirefoxExtractor extends Extractor {
|
||||
* Downloads are stored in the places database.
|
||||
*/
|
||||
private void getDownloadVersion24() {
|
||||
FileManager fileManager = currentCase.getServices().getFileManager();
|
||||
List<AbstractFile> downloadsFiles;
|
||||
try {
|
||||
downloadsFiles = fileManager.findFiles(dataSource, "places.sqlite", "Firefox"); //NON-NLS
|
||||
@@ -530,13 +528,13 @@ class FirefoxExtractor extends Extractor {
|
||||
|
||||
dataFound = true;
|
||||
Collection<BlackboardArtifact> bbartifacts = new ArrayList<>();
|
||||
int j = 0;
|
||||
int index = 0;
|
||||
for (AbstractFile downloadsFile : downloadsFiles) {
|
||||
if (downloadsFile.getSize() == 0) {
|
||||
continue;
|
||||
}
|
||||
String fileName = downloadsFile.getName();
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + "-downloads" + j + ".db"; //NON-NLS
|
||||
String temps = RAImageIngestModule.getRATempPath(currentCase, "firefox") + File.separator + fileName + "-downloads" + index + ".db"; //NON-NLS
|
||||
int errors = 0;
|
||||
try {
|
||||
ContentUtils.writeToFile(downloadsFile, new File(temps), context::dataSourceIngestIsCancelled);
|
||||
@@ -566,65 +564,63 @@ class FirefoxExtractor extends Extractor {
|
||||
logger.log(Level.INFO, "{0} - Now getting downloads from {1} with {2} artifacts identified.", new Object[]{getModuleName(), temps, tempList.size()}); //NON-NLS
|
||||
for (HashMap<String, Object> result : tempList) {
|
||||
|
||||
Collection<BlackboardAttribute> bbattributes = new ArrayList<>();
|
||||
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
((result.get("url").toString() != null) ? result.get("url").toString() : ""))); //NON-NLS
|
||||
//bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_URL_DECODED.getTypeID(), "RecentActivity", ((result.get("source").toString() != null) ? EscapeUtil.decodeURL(result.get("source").toString()) : "")));
|
||||
//TODO Revisit usage of deprecated constructor as per TSK-583
|
||||
//bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_LAST_ACCESSED.getTypeID(), "RecentActivity", "Last Visited", (Long.valueOf(result.get("startTime").toString()))));
|
||||
Collection<BlackboardAttribute> bbattributes = Lists.newArrayList(
|
||||
new BlackboardAttribute(
|
||||
TSK_URL, PARENT_MODULE_NAME,
|
||||
result.get("url").toString()), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME,
|
||||
Long.valueOf(result.get("lastModified").toString())), //NON-NLS
|
||||
new BlackboardAttribute(
|
||||
TSK_PROG_NAME, PARENT_MODULE_NAME,
|
||||
getModuleName()),
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME,
|
||||
Util.extractDomain(result.get("url").toString()))); //NON-NLS
|
||||
|
||||
String target = result.get("target").toString(); //NON-NLS
|
||||
if (target != null) {
|
||||
try {
|
||||
String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
decodedTarget));
|
||||
long pathID = Util.findID(dataSource, decodedTarget);
|
||||
if (pathID != -1) {
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PATH_ID,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
pathID));
|
||||
}
|
||||
} catch (UnsupportedEncodingException ex) {
|
||||
logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS
|
||||
errors++;
|
||||
}
|
||||
}
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
Long.valueOf(result.get("lastModified").toString()))); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PROG_NAME,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.getModuleName()")));
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DOMAIN,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"Firefox.parentModuleName.noSpace"),
|
||||
(Util.extractDomain((result.get("url").toString() != null) ? result.get("url").toString() : "")))); //NON-NLS
|
||||
|
||||
BlackboardArtifact bbart = this.addArtifact(ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, downloadsFile, bbattributes);
|
||||
if (bbart != null) {
|
||||
try {
|
||||
String decodedTarget = URLDecoder.decode(target.replaceAll("file:///", ""), "UTF-8"); //NON-NLS
|
||||
bbattributes.add(new BlackboardAttribute(
|
||||
TSK_PATH, PARENT_MODULE_NAME,
|
||||
decodedTarget));
|
||||
long pathID = Util.findID(dataSource, decodedTarget);
|
||||
if (pathID != -1) {
|
||||
bbattributes.add(new BlackboardAttribute(
|
||||
TSK_PATH_ID, PARENT_MODULE_NAME,
|
||||
pathID));
|
||||
}
|
||||
} catch (UnsupportedEncodingException ex) {
|
||||
logger.log(Level.SEVERE, "Error decoding Firefox download URL in " + temps, ex); //NON-NLS
|
||||
errors++;
|
||||
}
|
||||
|
||||
try {
|
||||
BlackboardArtifact bbart = downloadsFile.newArtifact(TSK_WEB_DOWNLOAD);
|
||||
bbart.addAttributes(bbattributes);
|
||||
bbartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to create Firefox download artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(
|
||||
NbBundle.getMessage(ChromeExtractor.class, "Firefox.getDlV24.errMsg.errAnalyzeFile", //NON-NLS
|
||||
this.getModuleName(), downloadsFile.getName()));
|
||||
}
|
||||
}
|
||||
if (errors > 0) {
|
||||
this.addErrorMessage(NbBundle.getMessage(this.getClass(), "Firefox.getDlV24.errMsg.errParsingArtifacts",
|
||||
this.getModuleName(), errors));
|
||||
}
|
||||
j++;
|
||||
index++;
|
||||
dbFile.delete();
|
||||
break;
|
||||
|
||||
}
|
||||
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "Firefox.parentModuleName"),
|
||||
BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, bbartifacts));
|
||||
try {
|
||||
blackboard.postArtifacts(bbartifacts, PARENT_MODULE_NAME);
|
||||
} catch (Blackboard.BlackboardException ex) {
|
||||
logger.log(Level.SEVERE, "Error while trying to post Firefox download artifact.", ex); //NON-NLS
|
||||
this.addErrorMessage(Bundle.Extractor_errPostingArtifacts(getModuleName()));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -29,7 +29,6 @@ import java.io.FileInputStream;
|
||||
import java.io.FileNotFoundException;
|
||||
import java.io.IOException;
|
||||
import java.io.InputStreamReader;
|
||||
import java.nio.file.Path;
|
||||
import java.text.ParseException;
|
||||
import java.text.SimpleDateFormat;
|
||||
import java.util.ArrayList;
|
||||
@@ -59,7 +58,6 @@ import org.sleuthkit.datamodel.*;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_ACCOUNT;
|
||||
import static org.sleuthkit.datamodel.BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE;
|
||||
import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED;
|
||||
import static org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATETIME_CREATED;
|
||||
@@ -153,8 +151,10 @@ class IEExtractor extends Extractor {
|
||||
NbBundle.getMessage(this.getClass(), "ExtractIE.moduleName.text")),
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME_NO_SPACE, Util.extractDomain(getURLFromIEBookmarkFile(fav))));
|
||||
BlackboardArtifact bbart = fav.newArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK);
|
||||
bbart.addAttributes(bbattributes);
|
||||
|
||||
bbartifacts.add(this.addArtifact(ARTIFACT_TYPE.TSK_WEB_BOOKMARK, fav, bbattributes));
|
||||
bbartifacts.add(bbart);
|
||||
|
||||
}
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
@@ -249,8 +249,10 @@ class IEExtractor extends Extractor {
|
||||
new BlackboardAttribute(
|
||||
TSK_DOMAIN, PARENT_MODULE_NAME_NO_SPACE,
|
||||
Util.extractDomain(URL)));
|
||||
BlackboardArtifact bbart = cookiesFile.newArtifact(TSK_WEB_COOKIE);
|
||||
bbart.addAttributes(bbattributes);
|
||||
|
||||
bbartifacts.add(this.addArtifact(TSK_WEB_COOKIE, cookiesFile, bbattributes));
|
||||
bbartifacts.add(bbart);
|
||||
}
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "ExtractIE.parentModuleName"), TSK_WEB_COOKIE, bbartifacts));
|
||||
|
||||
+2
-1
@@ -122,7 +122,8 @@ class RecentDocumentsLnkExtractor extends Extractor {
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"RecentDocumentsByLnk.parentModuleName.noSpace"),
|
||||
recentFile.getCrtime()));
|
||||
this.addArtifact(ARTIFACT_TYPE.TSK_RECENT_OBJECT, recentFile, bbattributes);
|
||||
BlackboardArtifact bbart = recentFile.newArtifact(ARTIFACT_TYPE.TSK_RECENT_OBJECT);
|
||||
bbart.addAttributes(bbattributes);
|
||||
}
|
||||
services.fireModuleDataEvent(new ModuleDataEvent(
|
||||
NbBundle.getMessage(this.getClass(), "RecentDocumentsByLnk.parentModuleName"),
|
||||
|
||||
@@ -531,7 +531,8 @@ class RegistryExtractor extends Extractor {
|
||||
new BlackboardAttribute(TSK_REMOTE_PATH, PARENT_MODULE_NAME,
|
||||
remoteName));
|
||||
|
||||
addArtifact(TSK_REMOTE_DRIVE, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_REMOTE_DRIVE);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error adding network drive artifact to blackboard."); //NON-NLS
|
||||
}
|
||||
@@ -550,7 +551,8 @@ class RegistryExtractor extends Extractor {
|
||||
TSK_PATH, PARENT_MODULE_NAME,
|
||||
homeDir));
|
||||
|
||||
addArtifact(TSK_OS_ACCOUNT, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_ACCOUNT);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error adding account artifact to blackboard."); //NON-NLS
|
||||
}
|
||||
@@ -570,7 +572,8 @@ class RegistryExtractor extends Extractor {
|
||||
if (mtime != null) {
|
||||
bbattributes.add(new BlackboardAttribute(TSK_DATETIME_ACCESSED, PARENT_MODULE_NAME, mtime));
|
||||
}
|
||||
addArtifact(TSK_RECENT_OBJECT, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_RECENT_OBJECT);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error adding recent object artifact to blackboard."); //NON-NLS
|
||||
}
|
||||
@@ -593,7 +596,8 @@ class RegistryExtractor extends Extractor {
|
||||
new BlackboardAttribute(
|
||||
TSK_DATETIME, PARENT_MODULE_NAME,
|
||||
itemMtime));
|
||||
addArtifact(ARTIFACT_TYPE.TSK_INSTALLED_PROG, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(ARTIFACT_TYPE.TSK_INSTALLED_PROG);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error adding installed program artifact to blackboard."); //NON-NLS
|
||||
}
|
||||
@@ -626,7 +630,9 @@ class RegistryExtractor extends Extractor {
|
||||
new BlackboardAttribute(
|
||||
TSK_DEVICE_ID, PARENT_MODULE_NAME,
|
||||
deviceID));
|
||||
usbBBartifacts.add(addArtifact(TSK_DEVICE_ATTACHED, regAbstractFile, bbattributes));
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_DEVICE_ATTACHED);
|
||||
bbart.addAttributes(bbattributes);
|
||||
usbBBartifacts.add(bbart);
|
||||
} catch (TskCoreException ex) {
|
||||
logger.log(Level.SEVERE, "Error adding device attached artifact to blackboard."); //NON-NLS
|
||||
}
|
||||
@@ -659,7 +665,8 @@ class RegistryExtractor extends Extractor {
|
||||
// Check if there is already an OS_INFO artifact for this file and add to that if possible
|
||||
ArrayList<BlackboardArtifact> results = caseDB.getBlackboardArtifacts(TSK_OS_INFO, regAbstractFile.getId());
|
||||
if (results.isEmpty()) {
|
||||
addArtifact(TSK_OS_INFO, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_INFO);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} else {
|
||||
results.get(0).addAttributes(bbattributes);
|
||||
//TODO: does it need to get re-indexed?
|
||||
@@ -700,7 +707,8 @@ class RegistryExtractor extends Extractor {
|
||||
// Check if there is already an OS_INFO artifact for this file and add to that if possible
|
||||
ArrayList<BlackboardArtifact> results = caseDB.getBlackboardArtifacts(TSK_OS_INFO, regAbstractFile.getId());
|
||||
if (results.isEmpty()) {
|
||||
addArtifact(TSK_OS_INFO, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_INFO);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} else {
|
||||
results.get(0).addAttributes(bbattributes);
|
||||
}
|
||||
@@ -786,7 +794,8 @@ class RegistryExtractor extends Extractor {
|
||||
// Check if there is already an OS_INFO artifact for this file, and add to that if possible.
|
||||
ArrayList<BlackboardArtifact> results = caseDB.getBlackboardArtifacts(TSK_OS_INFO, regAbstractFile.getId());
|
||||
if (results.isEmpty()) {
|
||||
addArtifact(TSK_OS_INFO, regAbstractFile, bbattributes);
|
||||
BlackboardArtifact bbart = regAbstractFile.newArtifact(TSK_OS_INFO);
|
||||
bbart.addAttributes(bbattributes);
|
||||
} else {
|
||||
results.get(0).addAttributes(bbattributes);
|
||||
}
|
||||
|
||||
+2
-1
@@ -367,7 +367,8 @@ class SearchEngineURLQueryAnalyzer extends Extractor {
|
||||
bbattributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_ACCESSED,
|
||||
NbBundle.getMessage(this.getClass(),
|
||||
"SearchEngineURLQueryAnalyzer.parentModuleName"), last_accessed));
|
||||
this.addArtifact(ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY, file, bbattributes);
|
||||
BlackboardArtifact bbart = file.newArtifact(ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY);
|
||||
bbart.addAttributes(bbattributes);
|
||||
se.increment();
|
||||
++totalQueries;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user