diff --git a/ExifParser/build.xml b/ExifParser/build.xml new file mode 100644 index 0000000000..beb3f50cb0 --- /dev/null +++ b/ExifParser/build.xml @@ -0,0 +1,8 @@ + + + + + + Builds, tests, and runs the project org.sleuthkit.autopsy.exifextract. + + \ No newline at end of file diff --git a/ExifParser/manifest.mf b/ExifParser/manifest.mf new file mode 100644 index 0000000000..1c48182980 --- /dev/null +++ b/ExifParser/manifest.mf @@ -0,0 +1,5 @@ +Manifest-Version: 1.0 +OpenIDE-Module: org.sleuthkit.autopsy.exifparser +OpenIDE-Module-Layer: org/sleuthkit/autopsy/exifparser/layer.xml +OpenIDE-Module-Localizing-Bundle: org/sleuthkit/autopsy/exifparser/Bundle.properties +OpenIDE-Module-Specification-Version: 1.0 diff --git a/ExifParser/nbproject/build-impl.xml b/ExifParser/nbproject/build-impl.xml new file mode 100644 index 0000000000..e1bcfa276c --- /dev/null +++ b/ExifParser/nbproject/build-impl.xml @@ -0,0 +1,45 @@ + + + + + + + + + + + + + You must set 'suite.dir' to point to your containing module suite + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/ExifParser/nbproject/project.properties b/ExifParser/nbproject/project.properties new file mode 100644 index 0000000000..c51692cafc --- /dev/null +++ b/ExifParser/nbproject/project.properties @@ -0,0 +1,3 @@ +javac.source=1.6 +javac.compilerargs=-Xlint -Xlint:-serial +spec.version.base=0.0 diff --git a/ExifParser/nbproject/project.xml b/ExifParser/nbproject/project.xml new file mode 100644 index 0000000000..5bd575c669 --- /dev/null +++ b/ExifParser/nbproject/project.xml @@ -0,0 +1,39 @@ + + + org.netbeans.modules.apisupport.project + + + org.sleuthkit.autopsy.exifparser + + + + org.sleuthkit.autopsy.datamodel + + + + 1 + 1.0 + + + + org.sleuthkit.autopsy.ingest + + + + 0-1 + 1.0 + + + + + + ext/xmpcore.jar + release/modules/ext/xmpcore.jar + + + ext/metadata-extractor-2.6.2.jar + release/modules/ext/metadata-extractor-2.6.2.jar + + + + diff --git a/ExifParser/nbproject/suite.properties b/ExifParser/nbproject/suite.properties new file mode 100644 index 0000000000..29d7cc9bd6 --- /dev/null +++ b/ExifParser/nbproject/suite.properties @@ -0,0 +1 @@ +suite.dir=${basedir}/.. diff --git a/ExifParser/release/modules/ext/LICENSE-2.0.txt b/ExifParser/release/modules/ext/LICENSE-2.0.txt new file mode 100644 index 0000000000..d645695673 --- /dev/null +++ b/ExifParser/release/modules/ext/LICENSE-2.0.txt @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/ExifParser/release/modules/ext/README.txt b/ExifParser/release/modules/ext/README.txt new file mode 100644 index 0000000000..bb16c380c0 --- /dev/null +++ b/ExifParser/release/modules/ext/README.txt @@ -0,0 +1,18 @@ +Copyright 2002-2012 Drew Noakes + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. + +More information about this project is available at: + + http://drewnoakes.com/code/exif/ + http://code.google.com/p/metadata-extractor/ diff --git a/ExifParser/release/modules/ext/metadata-extractor-2.6.2.jar b/ExifParser/release/modules/ext/metadata-extractor-2.6.2.jar new file mode 100644 index 0000000000..68426ac059 Binary files /dev/null and b/ExifParser/release/modules/ext/metadata-extractor-2.6.2.jar differ diff --git a/ExifParser/release/modules/ext/xmpcore.jar b/ExifParser/release/modules/ext/xmpcore.jar new file mode 100644 index 0000000000..884c2dd57f Binary files /dev/null and b/ExifParser/release/modules/ext/xmpcore.jar differ diff --git a/ExifParser/src/org/sleuthkit/autopsy/exifparser/Bundle.properties b/ExifParser/src/org/sleuthkit/autopsy/exifparser/Bundle.properties new file mode 100644 index 0000000000..aed23bb276 --- /dev/null +++ b/ExifParser/src/org/sleuthkit/autopsy/exifparser/Bundle.properties @@ -0,0 +1 @@ +OpenIDE-Module-Name=ExifParser diff --git a/ExifParser/src/org/sleuthkit/autopsy/exifparser/ExifParserFileIngestService.java b/ExifParser/src/org/sleuthkit/autopsy/exifparser/ExifParserFileIngestService.java new file mode 100644 index 0000000000..fbcf444d3b --- /dev/null +++ b/ExifParser/src/org/sleuthkit/autopsy/exifparser/ExifParserFileIngestService.java @@ -0,0 +1,254 @@ +/* + * Autopsy Forensic Browser + * + * Copyright 2011 Basis Technology Corp. + * Contact: carrier sleuthkit org + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.sleuthkit.autopsy.exifparser; + +import com.drew.imaging.ImageMetadataReader; +import com.drew.imaging.ImageProcessingException; +import com.drew.metadata.Metadata; +import com.drew.metadata.exif.ExifIFD0Directory; +import com.drew.metadata.exif.ExifSubIFDDirectory; +import com.drew.metadata.exif.GpsDirectory; +import java.io.BufferedInputStream; +import java.io.IOException; +import java.io.InputStream; +import java.util.ArrayList; +import java.util.Collection; +import java.util.Date; +import java.util.logging.Level; +import java.util.logging.Logger; +import org.sleuthkit.autopsy.ingest.IngestManagerProxy; +import org.sleuthkit.autopsy.ingest.IngestMessage; +import org.sleuthkit.autopsy.ingest.IngestMessage.MessageType; +import org.sleuthkit.autopsy.ingest.IngestServiceAbstract; +import org.sleuthkit.autopsy.ingest.IngestServiceAbstractFile; +import org.sleuthkit.datamodel.AbstractFile; +import org.sleuthkit.datamodel.BlackboardArtifact; +import org.sleuthkit.datamodel.BlackboardAttribute; +import org.sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE; +import org.sleuthkit.datamodel.FsContent; +import org.sleuthkit.datamodel.ReadContentInputStream; +import org.sleuthkit.datamodel.TskCoreException; +import org.sleuthkit.datamodel.TskData.TSK_DB_FILES_TYPE_ENUM; + +/** + * Example implementation of an image ingest service + * + */ +public final class ExifParserFileIngestService implements IngestServiceAbstractFile { + + final String MODULE_NAME = "Exif Parser"; + private static final Logger logger = Logger.getLogger(ExifParserFileIngestService.class.getName()); + private static ExifParserFileIngestService defaultInstance = null; + private IngestManagerProxy managerProxy; + private static int messageId = 0; + + //public constructor is required + //as multiple instances are created for processing multiple images simultenously + public ExifParserFileIngestService() { + } + + //default instance used for service registration + public static synchronized ExifParserFileIngestService getDefault() { + if (defaultInstance == null) { + defaultInstance = new ExifParserFileIngestService(); + } + return defaultInstance; + } + + @Override + public IngestServiceAbstractFile.ProcessResult process(AbstractFile content) { + if(content.getType().equals(TSK_DB_FILES_TYPE_ENUM.FS)) { + FsContent fsContent = (FsContent) content; + if(fsContent.isFile()) { + if(parsableFormat(fsContent)) { + return processFile(fsContent); + } + } + } + + return IngestServiceAbstractFile.ProcessResult.UNKNOWN; + } + + public IngestServiceAbstractFile.ProcessResult processFile(FsContent f) { + InputStream in = null; + BufferedInputStream bin = null; + + try { + in = new ReadContentInputStream(f); + bin = new BufferedInputStream(in); + + Collection attributes = new ArrayList(); + Metadata metadata = ImageMetadataReader.readMetadata(bin, true); + + // Date + ExifSubIFDDirectory exifDir = metadata.getDirectory(ExifSubIFDDirectory.class); + if(exifDir != null) { + Date date = exifDir.getDate(ExifSubIFDDirectory.TAG_DATETIME_ORIGINAL); + + if(date != null) { + attributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME.getTypeID(), MODULE_NAME, "", date.toString())); + } + } + + // GPS Stuff + GpsDirectory gpsDir = metadata.getDirectory(GpsDirectory.class); + if(gpsDir != null) { + String latitude = gpsDir.getString(GpsDirectory.TAG_GPS_LATITUDE); + String latRef = gpsDir.getString(GpsDirectory.TAG_GPS_LATITUDE_REF); + String longitude = gpsDir.getString(GpsDirectory.TAG_GPS_LONGITUDE); + String longRef = gpsDir.getString(GpsDirectory.TAG_GPS_LONGITUDE_REF); + String altitude = gpsDir.getString(GpsDirectory.TAG_GPS_ALTITUDE); + + if(latitude!= null && latRef!=null) { + attributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_GEO_LATITUDE.getTypeID(), MODULE_NAME, "", latitude + " " + latRef)); + } if(longitude!=null && longRef!=null) { + attributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_GEO_LONGITUDE.getTypeID(), MODULE_NAME, "", longitude + " " + longRef)); + } if(altitude!=null) { + attributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_GEO_ALTITUDE.getTypeID(), MODULE_NAME, "", altitude)); + } + } + + // Device info + ExifIFD0Directory devDir = metadata.getDirectory(ExifIFD0Directory.class); + if(devDir != null) { + String model = devDir.getString(ExifIFD0Directory.TAG_MODEL); + String make = devDir.getString(ExifIFD0Directory.TAG_MAKE); + + if(model!=null) { + attributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DEVICE_MODEL.getTypeID(), MODULE_NAME, "", model)); + } if(make!=null) { + attributes.add(new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DEVICE_MAKE.getTypeID(), MODULE_NAME, "", make)); + } + } + + // Add the attributes, if there are any, to a new artifact + if(!attributes.isEmpty()) { + BlackboardArtifact bba = f.newArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_GEN_INFO); + bba.addAttributes(attributes); + } + + return IngestServiceAbstractFile.ProcessResult.OK; + + } catch (TskCoreException ex) { + Logger.getLogger(ExifParserFileIngestService.class.getName()).log(Level.SEVERE, null, ex); + } catch (ImageProcessingException ex) { + System.out.println("ImageProcessingException: " + ex); + } catch (IOException ex) { + logger.log(Level.WARNING, "IOException when parsing image file.", ex); + } finally { + try { + if(in!=null) { in.close(); } + if(bin!=null) { bin.close(); } + } catch (IOException ex) { + logger.log(Level.WARNING, "Failed to close InputStream.", ex); + } + } + + // If we got here, there was an error + return IngestServiceAbstractFile.ProcessResult.ERROR; + } + + private boolean parsableFormat(FsContent f) { + // Get the name, extension + String name = f.getName(); + int dotIndex = name.lastIndexOf("."); + if (dotIndex == -1) { + return false; + } + String ext = name.substring(dotIndex).toLowerCase(); + if(ext.equals(".jpeg") || ext.equals(".jpg")) { + return true; + } + + return false; + } + + @Override + public void complete() { + logger.log(Level.INFO, "completed exif parsing " + this.toString()); + + final IngestMessage msg = IngestMessage.createMessage(++messageId, MessageType.INFO, this, "Complete"); + managerProxy.postMessage(msg); + + //service specific cleanup due to completion here + } + + @Override + public String getName() { + return "Exif Image Parser"; + } + + @Override + public String getDescription() { + return "Ingests all image files and retrieves their metadata."; + } + + @Override + public void init(IngestManagerProxy managerProxy) { + logger.log(Level.INFO, "init() " + this.toString()); + this.managerProxy = managerProxy; + + } + + @Override + public void stop() { + logger.log(Level.INFO, "stop()"); + managerProxy.postMessage(IngestMessage.createMessage(++messageId, MessageType.INFO, this, "Stopped")); + + //service specific cleanup due to interruption here + } + + @Override + public IngestServiceAbstract.ServiceType getType() { + return IngestServiceAbstract.ServiceType.AbstractFile; + } + + @Override + public boolean hasSimpleConfiguration() { + return false; + } + + @Override + public boolean hasAdvancedConfiguration() { + return false; + } + + @Override + public javax.swing.JPanel getSimpleConfiguration() { + return null; + } + + @Override + public javax.swing.JPanel getAdvancedConfiguration() { + return null; + } + + @Override + public boolean hasBackgroundJobsRunning() { + return false; + } + + @Override + public void saveAdvancedConfiguration() { + } + + @Override + public void saveSimpleConfiguration() { + } +} \ No newline at end of file diff --git a/ExifParser/src/org/sleuthkit/autopsy/exifparser/layer.xml b/ExifParser/src/org/sleuthkit/autopsy/exifparser/layer.xml new file mode 100644 index 0000000000..67b03b3564 --- /dev/null +++ b/ExifParser/src/org/sleuthkit/autopsy/exifparser/layer.xml @@ -0,0 +1,11 @@ + + + + + + + + + + + \ No newline at end of file diff --git a/nbproject/project.properties b/nbproject/project.properties index abdda11faf..3025014582 100644 --- a/nbproject/project.properties +++ b/nbproject/project.properties @@ -30,7 +30,8 @@ modules=\ ${project.org.sleuthkit.autopsy.recentactivity}:\ ${project.org.sleuthkit.autopsy.report}:\ ${project.org.sleuthkit.autopsy.testing}:\ - ${project.org.sleuthkit.autopsy.thunderbirdparser} + ${project.org.sleuthkit.autopsy.thunderbirdparser}:\ + ${project.org.sleuthkit.autopsy.exifparser} project.org.sleuthkit.autopsy.casemodule=Case project.org.sleuthkit.autopsy.corecomponentinterfaces=CoreComponentInterfaces project.org.sleuthkit.autopsy.corecomponents=CoreComponents @@ -45,5 +46,5 @@ project.org.sleuthkit.autopsy.datamodel=DataModel project.org.sleuthkit.autopsy.recentactivity=RecentActivity project.org.sleuthkit.autopsy.report=Report project.org.sleuthkit.autopsy.testing=Testing - project.org.sleuthkit.autopsy.thunderbirdparser=thunderbirdparser +project.org.sleuthkit.autopsy.exifparser=exifparser