source: trunk/src/reglookup.c @ 182

Last change on this file since 182 was 182, checked in by tim, 14 years ago

redesigned regfi logging API to utilize thread-local storage

  • Property svn:keywords set to Id
File size: 17.2 KB
Line 
1/*
2 * A utility to read a Windows NT and later registry files.
3 *
4 * Copyright (C) 2005-2010 Timothy D. Morgan
5 * Copyright (C) 2010 Tobias Mueller (portions of '-i' code)
6 * Copyright (C) 2002 Richard Sharpe, rsharpe@richardsharpe.com
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; version 3 of the License.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, write to the Free Software
19 * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. 
20 *
21 * $Id: reglookup.c 182 2010-03-17 06:41:17Z tim $
22 */
23
24
25#include <stdlib.h>
26#include <stdio.h>
27#include <string.h>
28#include <strings.h>
29#include <time.h>
30#include "regfi.h"
31#include "void_stack.h"
32
33/* Globals, influenced by command line parameters */
34bool print_value_mtime = false;
35bool print_verbose = false;
36bool print_security = false;
37bool print_header = true;
38bool path_filter_enabled = false;
39bool type_filter_enabled = false;
40char* path_filter = NULL;
41int type_filter;
42const char* registry_file = NULL;
43
44/* Other globals */
45REGFI_FILE* f;
46
47
48/* XXX: A hack to share some functions with reglookup-recover.c.
49 *      Should move these into a proper library at some point.
50 */
51#include "common.c"
52
53
54void printValue(REGFI_ITERATOR* iter, const REGFI_VK_REC* vk, char* prefix)
55{
56  REGFI_DATA* data;
57  char* quoted_value = NULL;
58  char* quoted_name = NULL;
59  char* conv_error = NULL;
60  const char* str_type = NULL;
61  char mtime[20];
62  time_t tmp_time[1];
63  struct tm* tmp_time_s = NULL;
64
65  quoted_name = get_quoted_valuename(vk);
66  if (quoted_name == NULL)
67  { /* Value names are NULL when we're looking at the "(default)" value.
68     * Currently we just return a 0-length string to try an eliminate
69     * ambiguity with a literal "(default)" value.  The data type of a line
70     * in the output allows one to differentiate between the parent key and
71     * this value.
72     */
73    quoted_name = malloc(1*sizeof(char));
74    if(quoted_name == NULL)
75      bailOut(REGLOOKUP_EXIT_OSERR, "ERROR: Could not allocate sufficient memory.\n");
76    quoted_name[0] = '\0';
77  }
78 
79  data = regfi_iterator_fetch_data(iter, vk);
80
81  printMsgs(iter->f);
82  if(data != NULL)
83  {
84    quoted_value = data_to_ascii(data, &conv_error);
85    if(quoted_value == NULL)
86    {
87      if(conv_error == NULL)
88        fprintf(stderr, "WARN: Could not quote value for '%s/%s'.  "
89                "Memory allocation failure likely.\n", prefix, quoted_name);
90      else
91        fprintf(stderr, "WARN: Could not quote value for '%s/%s'.  "
92                "Returned error: %s\n", prefix, quoted_name, conv_error);
93    }
94    else if(conv_error != NULL)
95      fprintf(stderr, "WARN: While quoting value for '%s/%s', "
96              "warning returned: %s\n", prefix, quoted_name, conv_error);
97    regfi_free_data(data);
98  }
99
100  if(print_value_mtime)
101  {
102    *tmp_time = regfi_nt2unix_time(&iter->cur_key->mtime);
103    tmp_time_s = gmtime(tmp_time);
104    strftime(mtime, sizeof(mtime), "%Y-%m-%d %H:%M:%S", tmp_time_s);
105  }
106  else
107    mtime[0] = '\0';
108
109  str_type = regfi_type_val2str(vk->type);
110  if(print_security)
111  {
112    if(str_type == NULL)
113      printf("%s/%s,0x%.8X,%s,%s,,,,\n", prefix, quoted_name,
114             vk->type, quoted_value, mtime);
115    else
116      printf("%s/%s,%s,%s,%s,,,,\n", prefix, quoted_name,
117             str_type, quoted_value, mtime);
118  }
119  else
120  {
121    if(str_type == NULL)
122      printf("%s/%s,0x%.8X,%s,%s\n", prefix, quoted_name,
123             vk->type, quoted_value, mtime);
124    else
125      printf("%s/%s,%s,%s,%s\n", prefix, quoted_name,
126             str_type, quoted_value, mtime);
127  }
128
129  if(quoted_value != NULL)
130    free(quoted_value);
131  if(quoted_name != NULL)
132    free(quoted_name);
133  if(conv_error != NULL)
134    free(conv_error);
135}
136
137
138char** splitPath(const char* s)
139{
140  char** ret_val;
141  const char* cur = s;
142  char* next = NULL;
143  char* copy;
144  uint32_t ret_cur = 0;
145
146  ret_val = (char**)malloc((REGFI_MAX_DEPTH+1+1)*sizeof(char**));
147  if (ret_val == NULL)
148    return NULL;
149  ret_val[0] = NULL;
150
151  /* We return a well-formed, 0-length, path even when input is icky. */
152  if (s == NULL)
153    return ret_val;
154 
155  while((next = strchr(cur, '/')) != NULL)
156  {
157    if ((next-cur) > 0)
158    {
159      copy = (char*)malloc((next-cur+1)*sizeof(char));
160      if(copy == NULL)
161        bailOut(REGLOOKUP_EXIT_OSERR, "ERROR: Memory allocation problem.\n");
162         
163      memcpy(copy, cur, next-cur);
164      copy[next-cur] = '\0';
165      ret_val[ret_cur++] = copy;
166      if(ret_cur < (REGFI_MAX_DEPTH+1+1))
167        ret_val[ret_cur] = NULL;
168      else
169        bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: Registry maximum depth exceeded.\n");
170    }
171    cur = next+1;
172  }
173
174  /* Grab last element, if path doesn't end in '/'. */
175  if(strlen(cur) > 0)
176  {
177    copy = strdup(cur);
178    ret_val[ret_cur++] = copy;
179    if(ret_cur < (REGFI_MAX_DEPTH+1+1))
180      ret_val[ret_cur] = NULL;
181    else
182      bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: Registry maximum depth exceeded.\n");
183  }
184
185  return ret_val;
186}
187
188
189void freePath(char** path)
190{
191  uint32_t i;
192
193  if(path == NULL)
194    return;
195
196  for(i=0; path[i] != NULL; i++)
197    free(path[i]);
198
199  free(path);
200}
201
202
203/* Returns a quoted path from an iterator's stack */
204char* iter2Path(REGFI_ITERATOR* i)
205{
206  const REGFI_ITER_POSITION* cur;
207  const REGFI_NK_REC* tmp_key;
208  uint32_t buf_left = 127;
209  uint32_t buf_len = buf_left+1;
210  uint32_t name_len = 0;
211  uint32_t grow_amt;
212  char* buf;
213  char* new_buf;
214  char* name;
215  void_stack_iterator* iter;
216 
217  buf = (char*)malloc((buf_len)*sizeof(char));
218  if (buf == NULL)
219    return NULL;
220  buf[0] = '\0';
221
222  iter = void_stack_iterator_new(i->key_positions);
223  if (iter == NULL)
224  {
225    free(buf);
226    return NULL;
227  }
228
229  /* skip root element */
230  if(void_stack_size(i->key_positions) < 1)
231  {
232    buf[0] = '/';
233    buf[1] = '\0';
234    return buf;
235  }
236  cur = void_stack_iterator_next(iter);
237
238  do
239  {
240    cur = void_stack_iterator_next(iter);
241    if (cur == NULL)
242      tmp_key = i->cur_key;
243    else
244      tmp_key = cur->nk;
245
246    name = get_quoted_keyname(tmp_key);
247
248    buf[buf_len-buf_left-1] = '/';
249    buf_left -= 1;
250    name_len = strlen(name);
251    if(name_len+1 > buf_left)
252    {
253      grow_amt = (uint32_t)(buf_len/2);
254      buf_len += name_len+1+grow_amt-buf_left;
255      if((new_buf = realloc(buf, buf_len)) == NULL)
256      {
257        free(name);
258        free(buf);
259        free(iter);
260        return NULL;
261      }
262      buf = new_buf;
263      buf_left = grow_amt + name_len + 1;
264    }
265    strncpy(buf+(buf_len-buf_left-1), name, name_len);
266    buf_left -= name_len;
267    buf[buf_len-buf_left-1] = '\0';
268    free(name);
269  } while(cur != NULL);
270
271  return buf;
272}
273
274
275void printValueList(REGFI_ITERATOR* iter, char* prefix)
276{
277  REGFI_VK_REC* value;
278
279  value = regfi_iterator_first_value(iter);
280  while(value != NULL)
281  {
282    if(!type_filter_enabled || (value->type == type_filter))
283      printValue(iter, value, prefix);
284    regfi_free_value(value);
285    value = regfi_iterator_next_value(iter);
286    printMsgs(iter->f);
287  }
288}
289
290
291void printKey(REGFI_ITERATOR* iter, char* full_path)
292{
293  static char empty_str[1] = "";
294  char* owner = NULL;
295  char* group = NULL;
296  char* sacl = NULL;
297  char* dacl = NULL;
298  char mtime[24];
299  char* quoted_classname;
300  const REGFI_SK_REC* sk;
301  const REGFI_NK_REC* k = regfi_iterator_cur_key(iter);
302  REGFI_CLASSNAME* classname;
303
304  formatTime(&k->mtime, mtime);
305
306  if(print_security && (sk=regfi_iterator_cur_sk(iter)))
307  {
308    owner = regfi_get_owner(sk->sec_desc);
309    group = regfi_get_group(sk->sec_desc);
310    sacl = regfi_get_sacl(sk->sec_desc);
311    dacl = regfi_get_dacl(sk->sec_desc);
312    if(owner == NULL)
313      owner = empty_str;
314    if(group == NULL)
315      group = empty_str;
316    if(sacl == NULL)
317      sacl = empty_str;
318    if(dacl == NULL)
319      dacl = empty_str;
320
321    classname = regfi_iterator_fetch_classname(iter, k);
322    printMsgs(iter->f);
323    if(classname != NULL)
324    {
325      if(classname->interpreted == NULL)
326      {
327        fprintf(stderr, "WARN: Could not convert class name"
328                " charset for key '%s'.  Quoting raw...\n", full_path);
329        quoted_classname = quote_buffer(classname->raw, classname->size,
330                                        key_special_chars);
331      }
332      else
333        quoted_classname = quote_string(classname->interpreted, 
334                                        key_special_chars);
335
336      if(quoted_classname == NULL)
337      {
338        fprintf(stderr, "ERROR: Could not quote classname"
339                " for key '%s' due to unknown error.\n", full_path);
340        quoted_classname = empty_str;
341      }
342    }
343    else
344      quoted_classname = empty_str;
345    regfi_free_classname(classname);
346
347    printMsgs(iter->f);
348    printf("%s,KEY,,%s,%s,%s,%s,%s,%s\n", full_path, mtime, 
349           owner, group, sacl, dacl, quoted_classname);
350
351    if(owner != empty_str)
352      free(owner);
353    if(group != empty_str)
354      free(group);
355    if(sacl != empty_str)
356      free(sacl);
357    if(dacl != empty_str)
358      free(dacl);
359    if(quoted_classname != empty_str)
360      free(quoted_classname);
361  }
362  else
363    printf("%s,KEY,,%s\n", full_path, mtime);
364}
365
366
367void printKeyTree(REGFI_ITERATOR* iter)
368{
369  const REGFI_NK_REC* root = NULL;
370  const REGFI_NK_REC* cur = NULL;
371  REGFI_NK_REC* sub = NULL;
372  char* path = NULL;
373  int key_type = regfi_type_str2val("KEY");
374  bool print_this = true;
375
376  root = cur = regfi_iterator_cur_key(iter);
377  sub = regfi_iterator_first_subkey(iter);
378  printMsgs(iter->f);
379
380  if(root == NULL)
381    bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: root cannot be NULL.\n");
382 
383  do
384  {
385    if(print_this)
386    {
387      path = iter2Path(iter);
388      if(path == NULL)
389        bailOut(REGLOOKUP_EXIT_OSERR, "ERROR: Could not construct iterator's path.\n");
390
391      if(!type_filter_enabled || (key_type == type_filter))
392        printKey(iter, path);
393      if(!type_filter_enabled || (key_type != type_filter))
394        printValueList(iter, path);
395     
396      free(path);
397    }
398   
399    if(sub == NULL)
400    {
401      if(cur != root)
402      {
403        /* We're done with this sub-tree, going up and hitting other branches. */
404        if(!regfi_iterator_up(iter))
405        {
406          printMsgs(iter->f);
407          bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: could not traverse iterator upward.\n");
408        }
409
410        cur = regfi_iterator_cur_key(iter);
411        if(cur == NULL)
412        {
413          printMsgs(iter->f);
414          bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: unexpected NULL for key.\n");
415        }
416       
417        sub = regfi_iterator_next_subkey(iter);
418      }
419      print_this = false;
420    }
421    else
422    { /* We have unexplored sub-keys. 
423       * Let's move down and print this first sub-tree out.
424       */
425      if(!regfi_iterator_down(iter))
426      {
427        printMsgs(iter->f);
428        bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: could not traverse iterator downward.\n");
429      }
430
431      cur = regfi_iterator_cur_key(iter);
432      regfi_free_key(sub);
433      sub = regfi_iterator_first_subkey(iter);
434      print_this = true;
435    }
436    printMsgs(iter->f);
437  } while(!((cur == root) && (sub == NULL)));
438
439  if(print_verbose)
440    fprintf(stderr, "INFO: Finished printing key tree.\n");
441}
442
443
444/* XXX: What if there is BOTH a value AND a key with that name??
445 *      What if there are multiple keys/values with the same name??
446 */
447/*
448 * Returns 0 if path was not found.
449 * Returns 1 if path was found as value.
450 * Returns 2 if path was found as key.
451 * Returns less than 0 on other error.
452 */
453int retrievePath(REGFI_ITERATOR* iter, char** path)
454{
455  REGFI_VK_REC* value;
456  char* tmp_path_joined;
457  const char** tmp_path;
458  uint32_t i;
459 
460  if(path == NULL)
461    return -1;
462
463  /* One extra for any value at the end, and one more for NULL */
464  tmp_path = (const char**)malloc(sizeof(const char**)*(REGFI_MAX_DEPTH+1+1));
465  if(tmp_path == NULL)
466    return -2;
467
468  /* Strip any potential value name at end of path */
469  for(i=0; 
470      (path[i] != NULL) && (path[i+1] != NULL) && (i < REGFI_MAX_DEPTH+1);
471      i++)
472  { tmp_path[i] = path[i]; }
473  tmp_path[i] = NULL;
474
475  if(print_verbose)
476    fprintf(stderr, "INFO: Attempting to retrieve specified path: %s\n",
477            path_filter);
478
479  /* Special check for '/' path filter */
480  if(path[0] == NULL)
481  {
482    if(print_verbose)
483      fprintf(stderr, "INFO: Found final path element as root key.\n");
484    free(tmp_path);
485    return 2;
486  }
487
488  if(!regfi_iterator_walk_path(iter, tmp_path))
489  {
490    printMsgs(iter->f);
491    free(tmp_path);
492    return 0;
493  }
494
495  if(regfi_iterator_find_value(iter, path[i]))
496  {
497    if(print_verbose)
498      fprintf(stderr, "INFO: Found final path element as value.\n");
499
500    value = regfi_iterator_cur_value(iter);
501    printMsgs(iter->f);
502    tmp_path_joined = iter2Path(iter);
503
504    if((value == NULL) || (tmp_path_joined == NULL))
505      bailOut(REGLOOKUP_EXIT_OSERR, "ERROR: Unexpected error before printValue.\n");
506
507    if(!type_filter_enabled || (value->type == type_filter))
508      printValue(iter, value, tmp_path_joined);
509
510    regfi_free_value(value);
511    free(tmp_path);
512    free(tmp_path_joined);
513    return 1;
514  }
515  else if(regfi_iterator_find_subkey(iter, path[i]))
516  {
517    printMsgs(iter->f);
518    if(print_verbose)
519      fprintf(stderr, "INFO: Found final path element as key.\n");
520
521    if(!regfi_iterator_down(iter))
522    {
523      printMsgs(iter->f);
524      bailOut(REGLOOKUP_EXIT_DATAERR, "ERROR: Unexpected error on traversing path filter key.\n");
525    }
526
527    return 2;
528  }
529  printMsgs(iter->f);
530
531  if(print_verbose)
532    fprintf(stderr, "INFO: Could not find last element of path.\n");
533
534  return 0;
535}
536
537
538static void usage(void)
539{
540  fprintf(stderr, "Usage: reglookup [-v] [-s]"
541          " [-p <PATH_FILTER>] [-t <TYPE_FILTER>]"
542          " <REGISTRY_FILE>\n");
543  fprintf(stderr, "Version: %s\n", REGLOOKUP_VERSION);
544  fprintf(stderr, "Options:\n");
545  fprintf(stderr, "\t-v\t sets verbose mode.\n");
546  fprintf(stderr, "\t-h\t enables header row. (default)\n");
547  fprintf(stderr, "\t-H\t disables header row.\n");
548  fprintf(stderr, "\t-s\t enables security descriptor output.\n");
549  fprintf(stderr, "\t-S\t disables security descriptor output. (default)\n");
550  fprintf(stderr, "\t-p\t restrict output to elements below this path.\n");
551  fprintf(stderr, "\t-t\t restrict results to this specific data type.\n");
552  fprintf(stderr, "\t-i\t includes parent key modification times with child values.\n");
553  fprintf(stderr, "\n");
554}
555
556
557int main(int argc, char** argv)
558{
559  char** path = NULL;
560  REGFI_ITERATOR* iter;
561  int retr_path_ret, fd;
562  uint32_t argi, arge;
563
564  /* Process command line arguments */
565  if(argc < 2)
566  {
567    usage();
568    bailOut(REGLOOKUP_EXIT_USAGE, "ERROR: Requires at least one argument.\n");
569  }
570 
571  arge = argc-1;
572  for(argi = 1; argi < arge; argi++)
573  {
574    if (strcmp("-p", argv[argi]) == 0)
575    {
576      if(++argi >= arge)
577      {
578        usage();
579        bailOut(REGLOOKUP_EXIT_USAGE, "ERROR: '-p' option requires parameter.\n");
580      }
581      if((path_filter = strdup(argv[argi])) == NULL)
582        bailOut(REGLOOKUP_EXIT_OSERR, "ERROR: Memory allocation problem.\n");
583
584      path_filter_enabled = true;
585    }
586    else if (strcmp("-t", argv[argi]) == 0)
587    {
588      if(++argi >= arge)
589      {
590        usage();
591        bailOut(REGLOOKUP_EXIT_USAGE, "ERROR: '-t' option requires parameter.\n");
592      }
593      if((type_filter = regfi_type_str2val(argv[argi])) < 0)
594      {
595        fprintf(stderr, "ERROR: Invalid type specified: %s.\n", argv[argi]);
596        bailOut(REGLOOKUP_EXIT_USAGE, "");
597      }
598      type_filter_enabled = true;
599    }
600    else if (strcmp("-h", argv[argi]) == 0)
601      print_header = true;
602    else if (strcmp("-H", argv[argi]) == 0)
603      print_header = false;
604    else if (strcmp("-s", argv[argi]) == 0)
605      print_security = true;
606    else if (strcmp("-S", argv[argi]) == 0)
607      print_security = false;
608    else if (strcmp("-v", argv[argi]) == 0)
609      print_verbose = true;
610    else if (strcmp("-i", argv[argi]) == 0)
611      print_value_mtime = true;
612    else
613    {
614      usage();
615      fprintf(stderr, "ERROR: Unrecognized option: %s\n", argv[argi]);
616      bailOut(REGLOOKUP_EXIT_USAGE, "");
617    }
618  }
619  registry_file = argv[argi];
620
621  if(print_verbose)
622    regfi_log_start(REGFI_LOG_INFO|REGFI_LOG_WARN|REGFI_LOG_ERROR);
623  else
624    regfi_log_start(REGFI_LOG_ERROR|REGFI_LOG_WARN);
625
626  fd = openHive(registry_file);
627  if(fd < 0)
628  {
629    fprintf(stderr, "ERROR: Couldn't open registry file: %s\n", registry_file);
630    bailOut(REGLOOKUP_EXIT_NOINPUT, "");
631  }
632   
633  f = regfi_alloc(fd);
634  if(f == NULL)
635  {
636    close(fd);
637    bailOut(REGLOOKUP_EXIT_NOINPUT, "ERROR: Failed to create REGFI_FILE structure.\n");
638  }
639
640
641  /* XXX: add command line option to choose output encoding */
642  iter = regfi_iterator_new(f, REGFI_ENCODING_ASCII);
643  if(iter == NULL)
644  {
645    printMsgs(f);
646    bailOut(REGLOOKUP_EXIT_OSERR, "ERROR: Couldn't create registry iterator.\n");
647  }
648
649  if(print_header)
650  {
651    if(print_security)
652      printf("PATH,TYPE,VALUE,MTIME,OWNER,GROUP,SACL,DACL,CLASS\n");
653    else
654      printf("PATH,TYPE,VALUE,MTIME\n");
655  }
656
657  if(path_filter_enabled && path_filter != NULL)
658    path = splitPath(path_filter);
659
660  if(path != NULL)
661  {
662    retr_path_ret = retrievePath(iter, path);
663    printMsgs(iter->f);
664    freePath(path);
665
666    if(retr_path_ret == 0)
667      fprintf(stderr, "WARN: Specified path '%s' not found.\n", path_filter);
668    else if (retr_path_ret == 2)
669      printKeyTree(iter);
670    else if(retr_path_ret < 0)
671    {
672      fprintf(stderr, "ERROR: retrievePath() returned %d.\n", 
673              retr_path_ret);
674      bailOut(REGLOOKUP_EXIT_DATAERR,
675              "ERROR: Unknown error occurred in retrieving path.\n");
676    }
677  }
678  else
679    printKeyTree(iter);
680
681  regfi_iterator_free(iter);
682  regfi_free(f);
683  regfi_log_stop();
684  close(fd);
685
686  return 0;
687}
Note: See TracBrowser for help on using the repository browser.