From 7ec91a67954ce5ae1be4dd660fcbd6f2d9a818d8 Mon Sep 17 00:00:00 2001 From: dhurd Date: Tue, 17 Jul 2012 12:10:54 -0400 Subject: [PATCH] Adding Body File format report to the Generate Report dialog. Also adding multiple icon support, chaning a file\'s icon based on it\'s extension. --- .../sleuthkit/autopsy/images/audio-file.png | Bin 0 -> 679 bytes .../org/sleuthkit/autopsy/images/doc-file.png | Bin 0 -> 634 bytes .../org/sleuthkit/autopsy/images/exe-file.png | Bin 0 -> 663 bytes .../sleuthkit/autopsy/images/image-file.png | Bin 0 -> 726 bytes .../org/sleuthkit/autopsy/images/pdf-file.png | Bin 0 -> 500 bytes .../sleuthkit/autopsy/images/text-file.png | Bin 0 -> 402 bytes .../sleuthkit/autopsy/images/video-file.png | Bin 0 -> 718 bytes .../org/sleuthkit/autopsy/images/web-file.png | Bin 0 -> 928 bytes .../sleuthkit/autopsy/datamodel/FileNode.java | 63 +++++++++++++++++- .../autopsy/report/ReportBodyFile.java | 35 ++++++---- .../autopsy/testing/RegressionTest.java | 2 +- 11 files changed, 83 insertions(+), 17 deletions(-) create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/audio-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/doc-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/exe-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/image-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/pdf-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/text-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/video-file.png create mode 100644 CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/web-file.png diff --git a/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/audio-file.png b/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/audio-file.png new file mode 100644 index 0000000000000000000000000000000000000000..516ac7f2339dafca8aefd9ba69f88a2385796575 GIT binary patch literal 679 zcmV;Y0$BZtP)F`j)oN6$Ro2(n5s~!X^E@X7 z3=IwG0sTJc;NXB!J`?7 z0ir0P-EOnLzt7Cf47QqhM|OEC_xZNych#+vw=1CnEh4 z!Z2)}pP#=K5erxmu}UfH`@R*yCRUO-j;xo-M6FiqvQ#R)uhnW@fWIu#QW)_ur;7jp N002ovPDHLkV1lcnNz4EM literal 0 HcmV?d00001 diff --git a/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/doc-file.png b/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/doc-file.png new file mode 100644 index 0000000000000000000000000000000000000000..2d364e1cf35a248bf56becf449292d7cc8bd10ff GIT binary patch literal 634 zcmV-=0)_pFP)H8GrV`dcg}$k zGebo3K#rk=|I2_MX4cLCc%FCr+uq*VY422Ggoq#rB7n${I$ARm6E;0HRR@Lu=bZF| zzWaM}f~xRt^@x{G@?@Oyb!X=cFjBo;^Z zR^lK%5Wm-IHM_9HgLa$Z>?{il3(3uCNW7XQ^CRjSo0kJcRHT7P^= zgjTCXsZ^p`ttPkK`~H?|w>%`Ax+fj>_va%ZIOm{PEFvOoY;43?x%=lc_p=^y z#b^H65~sZ`%PY$tf$bzup-_0(>-B7Rch|bzt_4A0{eIuVFtov7U}l!=y2%76V_c7137r;B>@i-5NR*HNx^&j zM|$eN5b7-v@z5gnkS4((=r)HCva_4r?0mf>sTwKt!N)L%_r5ppF-k;GO1%S4`9FLY zk-oROoW^nd)rp|BMr(~y>cs$?Q)^AQv-1V$>$P0z1m_&1;gHl?dfhGn%c9tj6>MgW zwF6R{FdmNyf`I+~ecJ6dzxsWQF(gUC@$oUNMU>hWP)gBiwMf&H@pw$7QlZgkARwowN}lHo1_R!I_&}Pb zlx0blWgH$J(&=+?U`w3wfa&mG)mSx=B z+_1a5OS9Re)oRh{bePZQ?CtGQuh$t2h7;fp01*NBY^{|n%OuZpDT+dt%cYcMDb6{$ zy1J5!iwjATM7~{KCO{idBJ$S(uj*M>=A7f`=!jaaMz7aP&d<+30zYK6*?UcR-Sg_V xVy*psc6RpZIhnN$rBrie>tDD7em*Ay`~lhF3b`7{(sKX+002ovPDHLkV1lX%ED!(y literal 0 HcmV?d00001 diff --git a/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/image-file.png b/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/image-file.png new file mode 100644 index 0000000000000000000000000000000000000000..e2e79d0324de98b6bcd5c672ccd8a6a4cbe7fe3e GIT binary patch literal 726 zcmV;{0xA88P)&3;zE1duVaD8T+!zq_?wLz`c zL~D)0#C2^Vu1zv-1CUB3$-Q`fd2DQKHIvDVb_oilI*qzVfW{OC2tlLPqFD9OXgn#o z_3$ZP5a5J0$D=aYQ(ky2fJDq?_{=pxb!@yq0brV@?zuraHHd551T836S||bx4AO&1K;!$8 zt(_YFpMc&kxOS96^DW=YpOKY=q})-Cr6)*66DaLdk~MaBDzv2TCFuNf-O6y`^hI{O zldR<5^I}BwyN7SWfM4yVHj-!rIY};bo3gQ3UMf$;KuMNZjRic z;N|&R{=%pAHxzfb=u6m~NR6}?Elc-Q__(=(R0=2T60@Tq1kKhjlrNY}PZ1l65w%^E zZr`9w(5bNeZ5cxt^gI0wxB~!`8)ZuM51!c6#x)YV3`&h#SK<}t^(kM z9pZg)fUYmK+@E0S(Gve7%lCaNo6Q!45bQU=-<}4j*XtI*Zzdr|*I_QVrT_o{07*qo IM6N<$f+z?vl)`fBvPpq zMx&AF$wLCy=ytm>0=c0}l9HB4;AOjom&*aG)#;3Lxm-d`jBJkksU*W!iBc$CEJEW~ z^f_6~mytc8WYv?y;Q)O{3(mb{rq#lFI7Ft=z%F)v-CWgFot!&Kqg)0J)9v-}WSU6V zYEXVPjkv)12E-_z$D89Ipt=eLtfy1Fb~lTKaD6R5XUV6QNjmf!c(u;*?2rg6h-&E qE71%3KSt~`+5DZGcntQh00RJAd+!;_Gf~t40000j)f+F02`d1F zO$3f@Gx-{Eeq{V25F(1@ais*jT8+w$$#Z`a`;L+41o_-*0j)KT<1qdhl0Q_a*#@N| z0%j!3krMDck8-I*XAmq}Fn`a6Q8?RPEf9twwq-FI4#^)xo|8S8lPoi+BtflSM{CW? zAf)3*PkRv1exLI6Hl@{{Y_?!q7N5S)$^N2w@f1W5CF`f4wdTIj;JR4k)dyt0RHshk w)$SSr!!R&S6QvY|M8{L7aMKi$H|#(019a$gPo0Qhs{jB107*qoM6N<$g5GAaf&c&j literal 0 HcmV?d00001 diff --git a/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/video-file.png b/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/video-file.png new file mode 100644 index 0000000000000000000000000000000000000000..c290609f59048e61cb28af42c4500709e342f437 GIT binary patch literal 718 zcmV;<0x|uGP)}Qttcx+nud-|g&zU)A&OW;fXC^-)=!FGqvDxqY zt`D)+A|hvjHvSK3Ywedvxo9gEy)obS5K)MLh#-3ja_DCy5+NFm_5f7^JkP^%9hA~& ztq>8yFl23Qjg5^B9u1Gs-`_`j`}IBI3Rxu)C1|b5<#G%U4UtN9kj<|1c6ydn$2GdT zZqeL)4z2ay36uysJ3CBGPLr%}WPW~;*4C?}Qtc!Xi39B@rK$wgOhjmCXyD1yXMFy& zOm;O(ZEYR>eFJ1ND-7O$$l$#PM;u6b3*D~kj(NUM=Z!9oCr%KH#!y-#2qrWHB_Fro zFgf`er4(B09&7FM$bJV(DLT7u64f=FY-(bA`v=xSvOY=XYZhmB_kj9=77#&+@bbkg za=D*;+uGv$<|d_Lfz9=GYU5F+-%R~k?~xglT_lrrEPhjqAF^VljL44$AR(WQ3ZUW5l90 z=tu+sOlT;Te0)~Sc6@w11GH2&cwmT!kw_$n$KwP+fQT?LF|pFy+j|@MV9Ux?2Z1qFWn+vr#@H|n ztue+Hi^XtsboAYR)^j2E>me$3{OK+5i9m07*qoM6N<$f<6*D AG5`Po literal 0 HcmV?d00001 diff --git a/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/web-file.png b/CoreComponentInterfaces/src/org/sleuthkit/autopsy/images/web-file.png new file mode 100644 index 0000000000000000000000000000000000000000..ac5957ad62d73408cd754a27453b4ce601a2b042 GIT binary patch literal 928 zcmV;R17G}!P)Mh53JODVWnpw>WFU8GbZ8({Xk{Qr zNlj3Y*^6%g00QhuL_t(I%dL}LXj^3*hoASH_nc#sG-;dWqm6CW(4s83b+X9Bt0|~3 z6mOI%-9=?M5O0K`ptn*G#rs`|6-PnD>5WW=H?uIcvzCo^E3WHYKeL=HA5C(SbCR6b z3)#f&*5~^FdoKR`eu4)${@&~<;4NLs{R%AQ`wgX7&~)wW+|1M$58jLW!S}zMGrL#P4P+<|J^kR=q!LjUR<=1mzj7BLp1miL0MTgZr{|x^iYGDyl!|!#OL6OV`f;PXlOge)!c#$#{SGXl@)s^XbSCXaYk@OhXc|B#CG* zL-81~z96~mqojuij=b@~*=YbR90{B}oE@c7E^@~W5Fg%$Qs65I} literal 0 HcmV?d00001 diff --git a/DataModel/src/org/sleuthkit/autopsy/datamodel/FileNode.java b/DataModel/src/org/sleuthkit/autopsy/datamodel/FileNode.java index d444317e65..2a6e32087d 100644 --- a/DataModel/src/org/sleuthkit/autopsy/datamodel/FileNode.java +++ b/DataModel/src/org/sleuthkit/autopsy/datamodel/FileNode.java @@ -18,8 +18,9 @@ */ package org.sleuthkit.autopsy.datamodel; +import java.util.Arrays; +import java.util.List; import javax.swing.Action; -import org.openide.nodes.Sheet; import org.sleuthkit.datamodel.File; import org.sleuthkit.datamodel.TskData; @@ -29,7 +30,18 @@ import org.sleuthkit.datamodel.TskData; * */ public class FileNode extends AbstractFsContentNode { - + + private final static List IMAGE_EXTENSIONS = Arrays.asList(".jpg", ".jpeg", ".png", ".psd", ".nef", ".tiff"); + private final static List VIDEO_EXTENSIONS = Arrays.asList(".aaf", ".3gp", ".asf", ".avi", ".m1v", ".m2v", + ".m4v", ".mp4", ".mov", ".mpeg", ".mpg", ".mpe", ".mp4", ".rm", ".wmv", ".mpv", ".flv", ".swf"); + private final static List AUDIO_EXTENSIONS = Arrays.asList(".aiff", ".aif", ".flac", ".wav", ".m4a", ".ape", + ".wma", ".mp2", ".mp1", ".mp3", ".aac", ".mp4", ".m4p", ".m1a", ".m2a", ".m4r", ".mpa", ".m3u", ".mid", ".midi", ".ogg"); + private final static List DOCUMENT_EXTENSIONS = Arrays.asList(".doc", ".docx", ".odt", ".xls", ".xlsx", ".ppt", ".pptx"); + private final static List EXECUTABLE_EXTENSIONS = Arrays.asList(".exe", ".msi", ".cmd", ".com", ".bat", ".reg", ".scr", ".dll", ".ini"); + private final static List TEXT_EXTENSIONS = Arrays.asList(".txt", ".rtf", ".log", ".text"); + private final static List WEB_EXTENSIONS = Arrays.asList(".html", ".htm", ".css", ".js", ".php", ".aspx", ".xml"); + private final static List PDF_EXTENSIONS = Arrays.asList(".pdf"); + /** * * @param file underlying Content @@ -45,7 +57,7 @@ public class FileNode extends AbstractFsContentNode { if (File.dirFlagToValue(file.getDir_flags()).equals(TskData.TSK_FS_NAME_FLAG_ENUM.TSK_FS_NAME_FLAG_UNALLOC.toString())) { this.setIconBaseWithExtension("org/sleuthkit/autopsy/images/file-icon-deleted.png"); } else { - this.setIconBaseWithExtension("org/sleuthkit/autopsy/images/file-icon.png"); + this.setIconBaseWithExtension(getIconForFileType(file)); } } @@ -69,4 +81,49 @@ public class FileNode extends AbstractFsContentNode { public T accept(DisplayableItemNodeVisitor v) { return v.visit(this); } + + // Given a file, returns the correct icon for said + // file based off it's extension + static String getIconForFileType(File file) { + // Get the name, extension + String name = file.getName(); + int i = name.lastIndexOf("."); + String ext = name.substring(i).toLowerCase(); + + // Images + for(String s:IMAGE_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/image-file.png"; } + } + // Videos + for(String s:VIDEO_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/video-file.png"; } + } + // Audio Files + for(String s:AUDIO_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/audio-file.png"; } + } + // Documents + for(String s:DOCUMENT_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/doc-file.png"; } + } + // Executables / System Files + for(String s:EXECUTABLE_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/exe-file.png"; } + } + // Text Files + for(String s:TEXT_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/text-file.png"; } + } + // Web Files + for(String s:WEB_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/web-file.png"; } + } + // PDFs + for(String s:PDF_EXTENSIONS) { + if(ext.equals(s)) { return "org/sleuthkit/autopsy/images/pdf-file.png"; } + } + // Else return the default + return "org/sleuthkit/autopsy/images/file-icon.png"; + + } } diff --git a/Report/src/org/sleuthkit/autopsy/report/ReportBodyFile.java b/Report/src/org/sleuthkit/autopsy/report/ReportBodyFile.java index a11bb5b817..e35df54013 100644 --- a/Report/src/org/sleuthkit/autopsy/report/ReportBodyFile.java +++ b/Report/src/org/sleuthkit/autopsy/report/ReportBodyFile.java @@ -36,13 +36,14 @@ import java.util.HashMap; import java.util.List; import java.util.logging.Level; import java.util.logging.Logger; +import org.openide.util.Exceptions; import org.sleuthkit.autopsy.casemodule.Case; import org.sleuthkit.autopsy.ingest.IngestManager; import org.sleuthkit.datamodel.*; /** - * - * @author Alex/Devin + * ReportBodyFile generates a report in the body file format specified on + * The Sleuth Kit wiki as MD5|name|inode|mode_as_string|UID|GID|size|atime|mtime|ctime|crtime. */ public class ReportBodyFile implements ReportModule { //Declare our publically accessible formatted Report, this will change everytime they run a Report @@ -50,8 +51,9 @@ public class ReportBodyFile implements ReportModule { private static String bodyFilePath = ""; private ReportConfiguration config; private static ReportBodyFile instance = null; - private Case currentCase = Case.getCurrentCase(); // get the most updated case + private Case currentCase = Case.getCurrentCase(); // get the current case private SleuthkitCase skCase = currentCase.getSleuthkitCase(); + private final Logger logger = Logger.getLogger(ReportBodyFile.class.getName()); ReportBodyFile() { } @@ -80,8 +82,9 @@ public class ReportBodyFile implements ReportModule { String datenotime = dateFormat.format(date); // Run query to get all files + ResultSet rs = null; try { - ResultSet rs = skCase.runQuery("SELECT * FROM tsk_files"); + rs = skCase.runQuery("SELECT * FROM tsk_files"); List fs = skCase.resultSetToFsContents(rs); // Check if ingest finished if (IngestManager.getDefault().isIngestRunning()) { @@ -95,7 +98,7 @@ public class ReportBodyFile implements ReportModule { } // MD5|name|inode|mode_as_string|UID|GID|size|atime|mtime|ctime|crtime formatted_Report.append(file.getMd5Hash()).append("|"); - formatted_Report.append(file.getName()).append("|"); + formatted_Report.append(file.getUniquePath()).append("|"); formatted_Report.append(file.getMeta_addr()).append("|"); // Use instead of inode formatted_Report.append(file.getModeAsString()).append("|"); formatted_Report.append(file.getUid()).append("|"); @@ -107,18 +110,24 @@ public class ReportBodyFile implements ReportModule { formatted_Report.append(file.getCrtime()).append("|"); formatted_Report.append("\n"); } - // Close the query - skCase.closeRunQuery(rs); } catch(SQLException ex) { - Logger.getLogger(ReportBodyFile.class.getName()).log(Level.WARNING, "Failed to get all file information.", ex); + logger.log(Level.WARNING, "Failed to get all file information.", ex); + } catch(TskCoreException ex) { + logger.log(Level.WARNING, "Failed to get the unique path.", ex); + } finally { + try {// Close the query + if(rs!=null) { skCase.closeRunQuery(rs); } + } catch (SQLException ex) { + logger.log(Level.WARNING, "Failed to close the query.", ex); + } } try { bodyFilePath = currentCase.getCaseDirectory() + File.separator + "Reports" + File.separator + currentCase.getName() + "-" + datenotime + ".txt"; this.save(bodyFilePath); - } catch (Exception e) { - Logger.getLogger(ReportHTML.class.getName()).log(Level.WARNING, "Could not write out body file report! ", e); + } catch (Exception ex) { + logger.log(Level.WARNING, "Could not write out body file report! ", ex); } return bodyFilePath; } @@ -136,8 +145,8 @@ public class ReportBodyFile implements ReportModule { out.write(formatted_Report.toString()); out.flush(); out.close(); - } catch (IOException e) { - Logger.getLogger(ReportBodyFile.class.getName()).log(Level.WARNING, "Could not write out body file report!", e); + } catch (IOException ex) { + logger.log(Level.WARNING, "Could not write out body file report!", ex); } } @@ -169,4 +178,4 @@ public class ReportBodyFile implements ReportModule { public void getPreview(String path) { BrowserControl.openUrl(path); } -} \ No newline at end of file +} diff --git a/Testing/test/qa-functional/src/org/sleuthkit/autopsy/testing/RegressionTest.java b/Testing/test/qa-functional/src/org/sleuthkit/autopsy/testing/RegressionTest.java index 61c4ddb7f8..c9378c0034 100644 --- a/Testing/test/qa-functional/src/org/sleuthkit/autopsy/testing/RegressionTest.java +++ b/Testing/test/qa-functional/src/org/sleuthkit/autopsy/testing/RegressionTest.java @@ -254,7 +254,7 @@ public class RegressionTest extends JellyTestCase{ jcbo2.doClick(); JButtonOperator jbo0 = new JButtonOperator(reportDialogOperator, "Generate Report"); jbo0.pushNoBlock(); - new Timeout("pausing", 10000).sleep(); // Give it a few seconds to generate + new Timeout("pausing", 3000).sleep(); // Give it a few seconds to generate JDialog previewDialog = JDialogOperator.waitJDialog("Report Preview", false, false); JDialogOperator previewDialogOperator = new JDialogOperator(previewDialog);