Autopsy  4.10.0
Graphical digital forensics platform for The Sleuth Kit and other tools.
CustomFileTypesManager.java
Go to the documentation of this file.
1 /*
2  * Autopsy Forensic Browser
3  *
4  * Copyright 2011-2016 Basis Technology Corp.
5  * Contact: carrier <at> sleuthkit <dot> org
6  *
7  * Licensed under the Apache License, Version 2.0 (the "License");
8  * you may not use this file except in compliance with the License.
9  * You may obtain a copy of the License at
10  *
11  * http://www.apache.org/licenses/LICENSE-2.0
12  *
13  * Unless required by applicable law or agreed to in writing, software
14  * distributed under the License is distributed on an "AS IS" BASIS,
15  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16  * See the License for the specific language governing permissions and
17  * limitations under the License.
18  */
19 package org.sleuthkit.autopsy.modules.filetypeid;
20 
21 import java.io.File;
22 import java.io.FileInputStream;
23 import java.io.FileOutputStream;
24 import java.io.IOException;
25 import java.nio.file.Path;
26 import java.nio.file.Paths;
27 import java.util.ArrayList;
28 import java.util.List;
29 import javax.xml.bind.DatatypeConverter;
30 import javax.xml.parsers.ParserConfigurationException;
31 import org.openide.util.io.NbObjectInputStream;
32 import org.openide.util.io.NbObjectOutputStream;
36 import org.w3c.dom.Document;
37 import org.w3c.dom.Element;
38 import org.w3c.dom.Node;
39 import org.w3c.dom.NodeList;
40 import org.xml.sax.SAXException;
41 
46 final class CustomFileTypesManager {
47 
48  private static final String SERIALIZED_SETTINGS_FILE = "UserFileTypeDefinitions.settings"; //NON-NLS
49  private static final String XML_SETTINGS_FILE = "UserFileTypeDefinitions.xml"; //NON-NLS
50  private static final String FILE_TYPES_TAG_NAME = "FileTypes"; //NON-NLS
51  private static final String FILE_TYPE_TAG_NAME = "FileType"; //NON-NLS
52  private static final String MIME_TYPE_TAG_NAME = "MimeType"; //NON-NLS
53  private static final String SIGNATURE_TAG_NAME = "Signature"; //NON-NLS
54  private static final String SIGNATURE_TYPE_ATTRIBUTE = "type"; //NON-NLS
55  private static final String BYTES_TAG_NAME = "Bytes"; //NON-NLS
56  private static final String OFFSET_TAG_NAME = "Offset"; //NON-NLS
57  private static final String RELATIVE_ATTRIBUTE = "RelativeToStart"; //NON-NLS
58  private static CustomFileTypesManager instance;
59  private final List<FileType> autopsyDefinedFileTypes = new ArrayList<>();
60  private List<FileType> userDefinedFileTypes = new ArrayList<>();
61 
71  synchronized static CustomFileTypesManager getInstance() throws CustomFileTypesException {
72  if (null == instance) {
73  instance = new CustomFileTypesManager();
74  try {
75  instance.loadUserDefinedFileTypes();
76  instance.createAutopsyDefinedFileTypes();
77  } catch (CustomFileTypesException ex) {
78  instance = null;
79  throw ex;
80  }
81  }
82  return instance;
83  }
84 
89  private CustomFileTypesManager() {
90  }
91 
97  synchronized List<FileType> getFileTypes() {
102  List<FileType> customTypes = new ArrayList<>(userDefinedFileTypes);
103  customTypes.addAll(autopsyDefinedFileTypes);
104  return customTypes;
105  }
106 
112  synchronized List<FileType> getAutopsyDefinedFileTypes() {
117  return new ArrayList<>(autopsyDefinedFileTypes);
118  }
119 
125  synchronized List<FileType> getUserDefinedFileTypes() {
130  return new ArrayList<>(userDefinedFileTypes);
131  }
132 
141  synchronized void setUserDefinedFileTypes(List<FileType> newFileTypes) throws CustomFileTypesException {
142  String filePath = getFileTypeDefinitionsFilePath(SERIALIZED_SETTINGS_FILE);
143  writeSerializedFileTypes(newFileTypes, filePath);
144  userDefinedFileTypes = newFileTypes;
145  }
146 
153  private void createAutopsyDefinedFileTypes() throws CustomFileTypesException {
154  byte[] byteArray;
155  FileType fileType;
156  try {
157  /*
158  * Add type for xml.
159  */
160  List<Signature> signatureList;
161  signatureList = new ArrayList<>();
162  signatureList.add(new Signature("<?xml", 0L)); //NON-NLS
163  fileType = new FileType("text/xml", signatureList); //NON-NLS
164  autopsyDefinedFileTypes.add(fileType);
165 
166  /*
167  * Add type for gzip.
168  */
169  byteArray = DatatypeConverter.parseHexBinary("1F8B"); //NON-NLS
170  signatureList.clear();
171  signatureList.add(new Signature(byteArray, 0L));
172  fileType = new FileType("application/x-gzip", signatureList); //NON-NLS
173  autopsyDefinedFileTypes.add(fileType);
174 
175  /*
176  * Add type for wk1.
177  */
178  byteArray = DatatypeConverter.parseHexBinary("0000020006040600080000000000"); //NON-NLS
179  signatureList.clear();
180  signatureList.add(new Signature(byteArray, 0L));
181  fileType = new FileType("application/x-123", signatureList); //NON-NLS
182  autopsyDefinedFileTypes.add(fileType);
183 
184  /*
185  * Add type for Radiance images.
186  */
187  byteArray = DatatypeConverter.parseHexBinary("233F52414449414E43450A");//NON-NLS
188  signatureList.clear();
189  signatureList.add(new Signature(byteArray, 0L));
190  fileType = new FileType("image/vnd.radiance", signatureList); //NON-NLS
191  autopsyDefinedFileTypes.add(fileType);
192 
193  /*
194  * Add type for dcx images.
195  */
196  byteArray = DatatypeConverter.parseHexBinary("B168DE3A"); //NON-NLS
197  signatureList.clear();
198  signatureList.add(new Signature(byteArray, 0L));
199  fileType = new FileType("image/x-dcx", signatureList); //NON-NLS
200  autopsyDefinedFileTypes.add(fileType);
201 
202  /*
203  * Add type for ics images.
204  */
205  signatureList.clear();
206  signatureList.add(new Signature("icns", 0L)); //NON-NLS
207  fileType = new FileType("image/x-icns", signatureList); //NON-NLS
208  autopsyDefinedFileTypes.add(fileType);
209 
210  /*
211  * Add type for pict images.
212  */
213  byteArray = DatatypeConverter.parseHexBinary("001102FF"); //NON-NLS
214  signatureList.clear();
215  signatureList.add(new Signature(byteArray, 522L));
216  fileType = new FileType("image/x-pict", signatureList); //NON-NLS
217  autopsyDefinedFileTypes.add(fileType);
218 
219  /* NOTE: see JIRA-4269. This MIME type seems to match a lot of random file types,
220  including ZIP archives. As a result those files get assigned this MIME type instead
221  of having their MIME type detected by Tika.
222  byteArray = DatatypeConverter.parseHexBinary("1100"); //NON-NLS
223  signatureList.clear();
224  signatureList.add(new Signature(byteArray, 522L));
225  fileType = new FileType("image/x-pict", signatureList); //NON-NLS
226  autopsyDefinedFileTypes.add(fileType);*/
227 
228  /*
229  * Add type for pam.
230  */
231  signatureList.clear();
232  signatureList.add(new Signature("P7", 0L)); //NON-NLS
233  fileType = new FileType("image/x-portable-arbitrarymap", signatureList); //NON-NLS
234  autopsyDefinedFileTypes.add(fileType);
235 
236  /*
237  * Add type for pfm.
238  */
239  signatureList.clear();
240  signatureList.add(new Signature("PF", 0L)); //NON-NLS
241  fileType = new FileType("image/x-portable-floatmap", signatureList); //NON-NLS
242  autopsyDefinedFileTypes.add(fileType);
243  signatureList.clear();
244  signatureList.add(new Signature("Pf", 0L)); //NON-NLS
245  fileType = new FileType("image/x-portable-floatmap", signatureList); //NON-NLS
246  autopsyDefinedFileTypes.add(fileType);
247 
248  /*
249  * Add type for tga.
250  */
251  byteArray = DatatypeConverter.parseHexBinary("54525545564953494F4E2D5846494C452E00"); //NON-NLS
252  signatureList.clear();
253  signatureList.add(new Signature(byteArray, 17, false));
254  fileType = new FileType("image/x-tga", signatureList); //NON-NLS
255  autopsyDefinedFileTypes.add(fileType);
256 
257  /*
258  * Add type for ilbm.
259  */
260  signatureList.clear();
261  signatureList.add(new Signature("FORM", 0L)); //NON-NLS
262  signatureList.add(new Signature("ILBM", 8L)); //NON-NLS
263  fileType = new FileType("image/x-ilbm", signatureList); //NON-NLS
264  autopsyDefinedFileTypes.add(fileType);
265  signatureList.clear();
266  signatureList.add(new Signature("FORM", 0L)); //NON-NLS
267  signatureList.add(new Signature("PBM", 8L)); //NON-NLS
268  fileType = new FileType("image/x-ilbm", signatureList); //NON-NLS
269  autopsyDefinedFileTypes.add(fileType);
270 
271  /*
272  * Add type for webp.
273  */
274  signatureList.clear();
275  signatureList.add(new Signature("RIFF", 0L)); //NON-NLS
276  signatureList.add(new Signature("WEBP", 8L)); //NON-NLS
277  fileType = new FileType("image/webp", signatureList); //NON-NLS
278  autopsyDefinedFileTypes.add(fileType);
279 
280  /*
281  * Add type for aiff.
282  */
283  signatureList.clear();
284  signatureList.add(new Signature("FORM", 0L)); //NON-NLS
285  signatureList.add(new Signature("AIFF", 8L)); //NON-NLS
286  fileType = new FileType("audio/aiff", signatureList); //NON-NLS
287  autopsyDefinedFileTypes.add(fileType);
288  signatureList.clear();
289  signatureList.add(new Signature("FORM", 0L)); //NON-NLS
290  signatureList.add(new Signature("AIFC", 8L)); //NON-NLS
291  fileType = new FileType("audio/aiff", signatureList); //NON-NLS
292  autopsyDefinedFileTypes.add(fileType);
293  signatureList.clear();
294  signatureList.add(new Signature("FORM", 0L)); //NON-NLS
295  signatureList.add(new Signature("8SVX", 8L)); //NON-NLS
296  fileType = new FileType("audio/aiff", signatureList); //NON-NLS
297  autopsyDefinedFileTypes.add(fileType);
298 
299  /*
300  * Add type for iff.
301  */
302  signatureList.clear();
303  signatureList.add(new Signature("FORM", 0L)); //NON-NLS
304  fileType = new FileType("application/x-iff", signatureList); //NON-NLS
305  autopsyDefinedFileTypes.add(fileType);
306 
307  /*
308  * Add type for .tec files with leading End Of Image marker (JFIF JPEG)
309  */
310  byteArray = DatatypeConverter.parseHexBinary("FFD9FFD8"); //NON-NLS
311  signatureList.clear();
312  signatureList.add(new Signature(byteArray, 0L));
313  fileType = new FileType("image/jpeg", signatureList); //NON-NLS
314  autopsyDefinedFileTypes.add(fileType);
315 
316  } catch (IllegalArgumentException ex) {
317  /*
318  * parseHexBinary() throws this if the argument passed in is not hex
319  */
320  throw new CustomFileTypesException("Error creating Autopsy defined custom file types", ex); //NON-NLS
321  }
322  }
323 
330  private void loadUserDefinedFileTypes() throws CustomFileTypesException {
331  userDefinedFileTypes.clear();
332  String filePath = getFileTypeDefinitionsFilePath(SERIALIZED_SETTINGS_FILE);
333  if (new File(filePath).exists()) {
334  userDefinedFileTypes = readSerializedFileTypes(filePath);
335  } else {
336  filePath = getFileTypeDefinitionsFilePath(XML_SETTINGS_FILE);
337  if (new File(filePath).exists()) {
338  userDefinedFileTypes = readFileTypesXML(filePath);
339  }
340  }
341  }
342 
352  private static void writeSerializedFileTypes(List<FileType> fileTypes, String filePath) throws CustomFileTypesException {
353  try (NbObjectOutputStream out = new NbObjectOutputStream(new FileOutputStream(filePath))) {
354  UserDefinedFileTypesSettings settings = new UserDefinedFileTypesSettings(fileTypes);
355  out.writeObject(settings);
356  } catch (IOException ex) {
357  throw new CustomFileTypesException(String.format("Failed to write settings to %s", filePath), ex); //NON-NLS
358  }
359  }
360 
371  private static List<FileType> readSerializedFileTypes(String filePath) throws CustomFileTypesException {
372  File serializedDefs = new File(filePath);
373  try {
374  try (NbObjectInputStream in = new NbObjectInputStream(new FileInputStream(serializedDefs))) {
375  UserDefinedFileTypesSettings filesSetsSettings = (UserDefinedFileTypesSettings) in.readObject();
376  return filesSetsSettings.getUserDefinedFileTypes();
377  }
378  } catch (IOException | ClassNotFoundException ex) {
379  throw new CustomFileTypesException(String.format("Failed to read settings from %s", filePath), ex); //NON-NLS
380  }
381  }
382 
397  private static List<FileType> readFileTypesXML(String filePath) throws CustomFileTypesException {
398  try {
399  List<FileType> fileTypes = new ArrayList<>();
400  Document doc = XMLUtil.loadDocument(filePath);
401  if (doc != null) {
402  Element fileTypesElem = doc.getDocumentElement();
403  if (fileTypesElem != null && fileTypesElem.getNodeName().equals(FILE_TYPES_TAG_NAME)) {
404  NodeList fileTypeElems = fileTypesElem.getElementsByTagName(FILE_TYPE_TAG_NAME);
405  for (int i = 0; i < fileTypeElems.getLength(); ++i) {
406  Element fileTypeElem = (Element) fileTypeElems.item(i);
407  FileType fileType = parseFileType(fileTypeElem);
408  fileTypes.add(fileType);
409  }
410  }
411  }
412  return fileTypes;
413  } catch (IOException | ParserConfigurationException | SAXException ex) {
414  throw new CustomFileTypesException(String.format("Failed to read ssettings from %s", filePath), ex); //NON-NLS
415  }
416  }
417 
430  private static FileType parseFileType(Element fileTypeElem) throws IllegalArgumentException, NumberFormatException {
431  String mimeType = parseMimeType(fileTypeElem);
432  Signature signature = parseSignature(fileTypeElem);
433  // File type definitions in the XML file were written prior to the
434  // implementation of multiple signatures per type.
435  List<Signature> sigList = new ArrayList<>();
436  sigList.add(signature);
437  return new FileType(mimeType, sigList);
438  }
439 
447  private static String parseMimeType(Element fileTypeElem) {
448  return getChildElementTextContent(fileTypeElem, MIME_TYPE_TAG_NAME);
449  }
450 
458  private static Signature parseSignature(Element fileTypeElem) throws IllegalArgumentException, NumberFormatException {
459  NodeList signatureElems = fileTypeElem.getElementsByTagName(SIGNATURE_TAG_NAME);
460  Element signatureElem = (Element) signatureElems.item(0);
461 
462  String sigTypeAttribute = signatureElem.getAttribute(SIGNATURE_TYPE_ATTRIBUTE);
463  Signature.Type signatureType = Signature.Type.valueOf(sigTypeAttribute);
464 
465  String sigBytesString = getChildElementTextContent(signatureElem, BYTES_TAG_NAME);
466  byte[] signatureBytes = DatatypeConverter.parseHexBinary(sigBytesString);
467 
468  Element offsetElem = (Element) signatureElem.getElementsByTagName(OFFSET_TAG_NAME).item(0);
469  String offsetString = offsetElem.getTextContent();
470  long offset = DatatypeConverter.parseLong(offsetString);
471 
472  boolean isRelativeToStart;
473  String relativeString = offsetElem.getAttribute(RELATIVE_ATTRIBUTE);
474  if (null == relativeString || relativeString.equals("")) {
475  isRelativeToStart = true;
476  } else {
477  isRelativeToStart = DatatypeConverter.parseBoolean(relativeString);
478  }
479 
480  return new Signature(signatureBytes, offset, signatureType, isRelativeToStart);
481  }
482 
491  private static String getChildElementTextContent(Element elem, String tagName) {
492  NodeList childElems = elem.getElementsByTagName(tagName);
493  Node childNode = childElems.item(0);
494  if (childNode == null) {
495  return null;
496  }
497  Element childElem = (Element) childNode;
498  return childElem.getTextContent();
499  }
500 
508  private static String getFileTypeDefinitionsFilePath(String fileName) {
509  Path filePath = Paths.get(PlatformUtil.getUserConfigDirectory(), fileName);
510  return filePath.toAbsolutePath().toString();
511  }
512 
516  static class CustomFileTypesException extends Exception {
517 
518  private static final long serialVersionUID = 1L;
519 
520  CustomFileTypesException(String message) {
521  super(message);
522  }
523 
524  CustomFileTypesException(String message, Throwable throwable) {
525  super(message, throwable);
526  }
527  }
528 
529 }

Copyright © 2012-2018 Basis Technology. Generated on: Fri Mar 22 2019
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.