mirror of
https://github.com/elisspace/autopsy.git
synced 2026-10-04 00:09:53 +00:00
further improvements (cleanup, speed) in running regripper and pasco
This commit is contained in:
@@ -41,7 +41,8 @@ public final class ExecUtil {
|
||||
|
||||
/**
|
||||
* Execute a process. Redirect asynchronously stdout to a string and stderr
|
||||
* to nowhere. Use only for small outputs, otherwise use the execute() variant with Writer.
|
||||
* to nowhere. Use only for small outputs, otherwise use the execute()
|
||||
* variant with Writer.
|
||||
*
|
||||
* @param aCommand command to be executed
|
||||
* @param params parameters of the command
|
||||
@@ -100,10 +101,9 @@ public final class ExecUtil {
|
||||
return output;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Execute a process. Redirect asynchronously stdout to a passed in writer and stderr
|
||||
* to nowhere.
|
||||
/**
|
||||
* Execute a process. Redirect asynchronously stdout to a passed in writer
|
||||
* and stderr to nowhere.
|
||||
*
|
||||
* @param stdoutWriter file writer to write stdout to
|
||||
* @param aCommand command to be executed
|
||||
@@ -128,12 +128,14 @@ public final class ExecUtil {
|
||||
logger.log(Level.INFO, "Executing " + arrayCommandToLog.toString());
|
||||
|
||||
proc = rt.exec(arrayCommand);
|
||||
if (false) {
|
||||
try {
|
||||
//give time to fully start the process
|
||||
Thread.sleep(2000);
|
||||
} catch (InterruptedException ex) {
|
||||
logger.log(Level.WARNING, "Pause interrupted", ex);
|
||||
}
|
||||
}
|
||||
|
||||
//stderr redirect
|
||||
errorStringRedirect = new ExecUtil.StreamToStringRedirect(proc.getErrorStream(), "ERROR");
|
||||
@@ -148,17 +150,13 @@ public final class ExecUtil {
|
||||
final int exitVal = proc.waitFor();
|
||||
logger.log(Level.INFO, aCommand + " exit value: " + exitVal);
|
||||
|
||||
errorStringRedirect.stopRun();
|
||||
errorStringRedirect = null;
|
||||
|
||||
outputWriterRedirect.stopRun();
|
||||
outputWriterRedirect = null;
|
||||
|
||||
//gc process with its streams
|
||||
proc = null;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Interrupt the running process and stop its stream redirect threads
|
||||
*/
|
||||
public synchronized void stop() {
|
||||
logger.log(Level.INFO, "Stopping Execution of: " + command);
|
||||
|
||||
@@ -171,7 +169,7 @@ public final class ExecUtil {
|
||||
outputStringRedirect.stopRun();
|
||||
outputStringRedirect = null;
|
||||
}
|
||||
|
||||
|
||||
if (outputWriterRedirect != null) {
|
||||
outputWriterRedirect.stopRun();
|
||||
outputWriterRedirect = null;
|
||||
@@ -210,15 +208,25 @@ public final class ExecUtil {
|
||||
@Override
|
||||
public final void run() {
|
||||
final String SEP = System.getProperty("line.separator");
|
||||
InputStreamReader isr = null;
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
final InputStreamReader isr = new InputStreamReader(this.is);
|
||||
final BufferedReader br = new BufferedReader(isr);
|
||||
isr = new InputStreamReader(this.is);
|
||||
br = new BufferedReader(isr);
|
||||
String line = null;
|
||||
while (doRun && (line = br.readLine()) != null) {
|
||||
this.output.append(line).append(SEP);
|
||||
}
|
||||
} catch (final IOException ex) {
|
||||
logger.log(Level.WARNING, "Error redirecting stream to string buffer", ex);
|
||||
} finally {
|
||||
if (br != null) {
|
||||
try {
|
||||
br.close();
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, "Error closing stream reader", ex);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -271,9 +279,11 @@ public final class ExecUtil {
|
||||
@Override
|
||||
public final void run() {
|
||||
final String SEP = System.getProperty("line.separator");
|
||||
InputStreamReader isr = null;
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
final InputStreamReader isr = new InputStreamReader(this.is);
|
||||
final BufferedReader br = new BufferedReader(isr);
|
||||
isr = new InputStreamReader(this.is);
|
||||
br = new BufferedReader(isr);
|
||||
String line = null;
|
||||
while (doRun && (line = br.readLine()) != null) {
|
||||
writer.append(line).append(SEP);
|
||||
@@ -282,7 +292,13 @@ public final class ExecUtil {
|
||||
logger.log(Level.SEVERE, "Error reading output and writing to file writer", ex);
|
||||
} finally {
|
||||
try {
|
||||
writer.flush();
|
||||
if (doRun) {
|
||||
writer.flush();
|
||||
}
|
||||
if (br != null) {
|
||||
br.close();
|
||||
}
|
||||
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, "Error flushing file writer", ex);
|
||||
}
|
||||
@@ -290,7 +306,7 @@ public final class ExecUtil {
|
||||
}
|
||||
|
||||
/**
|
||||
* Stop running the stream redirect. The thread will exit out gracefully
|
||||
* Stop running the stream redirect. The thread will exit out gracefully
|
||||
* after the current readLine() on stream unblocks
|
||||
*/
|
||||
public void stopRun() {
|
||||
|
||||
@@ -26,12 +26,9 @@ package org.sleuthkit.autopsy.recentactivity;
|
||||
import java.io.File;
|
||||
import java.io.FileInputStream;
|
||||
import java.io.FileNotFoundException;
|
||||
import java.io.FileWriter;
|
||||
import java.io.IOException;
|
||||
import java.io.UnsupportedEncodingException;
|
||||
|
||||
// SQL imports
|
||||
import java.sql.ResultSet;
|
||||
import java.sql.SQLException;
|
||||
import java.io.Writer;
|
||||
|
||||
//Util Imports
|
||||
import java.text.ParseException;
|
||||
@@ -392,19 +389,15 @@ public class ExtractIE extends Extract implements IngestModuleImage {
|
||||
}
|
||||
boolean success = true;
|
||||
|
||||
Writer writer = null;
|
||||
try {
|
||||
StringBuilder command = new StringBuilder();
|
||||
|
||||
command.append(" -cp");
|
||||
command.append(" \"").append(PASCO_LIB_PATH).append("\"");
|
||||
command.append(" isi.pasco2.Main");
|
||||
command.append(" -T history");
|
||||
command.append(" \"").append(indexFilePath).append("\"");
|
||||
command.append(" > \"").append(PASCO_RESULTS_PATH).append("\\" + filename + "\"");
|
||||
// command.add(" > " + "\"" + PASCO_RESULTS_PATH + File.separator + Long.toString(bbId) + "\"");
|
||||
String cmd = command.toString();
|
||||
final String pascoOutFile = PASCO_RESULTS_PATH + File.separator + filename;
|
||||
logger.log(Level.INFO, "Writing pasco results to: " + pascoOutFile);
|
||||
writer = new FileWriter(pascoOutFile);
|
||||
execPasco = new ExecUtil();
|
||||
execPasco.execute("\"" + JAVA_PATH + " " + cmd + "\"");
|
||||
execPasco.execute(writer, JAVA_PATH,
|
||||
"-cp", PASCO_LIB_PATH,
|
||||
"isi.pasco2.Main", "-T", "history", indexFilePath );
|
||||
|
||||
} catch (IOException ex) {
|
||||
success = false;
|
||||
@@ -413,6 +406,16 @@ public class ExtractIE extends Extract implements IngestModuleImage {
|
||||
success = false;
|
||||
logger.log(Level.SEVERE, "Pasco has been interrupted, failed to extract some web history from Internet Explorer.", ex);
|
||||
}
|
||||
finally {
|
||||
if (writer != null) {
|
||||
try {
|
||||
writer.flush();
|
||||
writer.close();
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.WARNING, "Error closing writer stream after for Pasco result", ex);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return success;
|
||||
}
|
||||
|
||||
@@ -165,34 +165,50 @@ public class ExtractRegistry extends Extract implements IngestModuleImage {
|
||||
String txtPath = regFilePath + Integer.toString(fileIndex) + ".txt";
|
||||
String type = "";
|
||||
|
||||
Writer writer = null;
|
||||
try {
|
||||
if (regFilePath.toLowerCase().contains("system")) {
|
||||
type = "autopsysystem";
|
||||
}
|
||||
if (regFilePath.toLowerCase().contains("software")) {
|
||||
else if (regFilePath.toLowerCase().contains("software")) {
|
||||
type = "autopsysoftware";
|
||||
}
|
||||
if (regFilePath.toLowerCase().contains("ntuser")) {
|
||||
else if (regFilePath.toLowerCase().contains("ntuser")) {
|
||||
type = "autopsy";
|
||||
}
|
||||
if (regFilePath.toLowerCase().contains("default")) {
|
||||
else if (regFilePath.toLowerCase().contains("default")) {
|
||||
type = "1default";
|
||||
}
|
||||
if (regFilePath.toLowerCase().contains("sam")) {
|
||||
else if (regFilePath.toLowerCase().contains("sam")) {
|
||||
type = "1sam";
|
||||
}
|
||||
if (regFilePath.toLowerCase().contains("security")) {
|
||||
else if (regFilePath.toLowerCase().contains("security")) {
|
||||
type = "1security";
|
||||
}
|
||||
String command = "\"" + RR_PATH + "\" -r \"" + regFilePath + "\" -f " + type + " > \"" + txtPath + "\" 2> NUL";
|
||||
else {
|
||||
type = "1default";
|
||||
}
|
||||
|
||||
logger.log(Level.INFO, "Writing RegRipper results to: " + txtPath);
|
||||
writer = new FileWriter(txtPath);
|
||||
execRR = new ExecUtil();
|
||||
execRR.execute("\"" + command + "\"");
|
||||
execRR.execute(writer, RR_PATH,
|
||||
"-r", regFilePath, "-f", type);
|
||||
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, "Unable to RegRipper and process parse some registry files.", ex);
|
||||
} catch (InterruptedException ex) {
|
||||
logger.log(Level.SEVERE, "RegRipper has been interrupted, failed to parse registry.", ex);
|
||||
}
|
||||
finally {
|
||||
if (writer != null) {
|
||||
try {
|
||||
writer.close();
|
||||
} catch (IOException ex) {
|
||||
logger.log(Level.SEVERE, "Error closing output writer after running RegRipper", ex);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return txtPath;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user