Skip to content

Instantly share code, notes, and snippets.

{
"formats": [
{
"format": {
"id": "archives-nz-dev-signature/1",
"name": "Adobe Air",
"version": "1.0",
"mime": "application/vnd.adobe.air-application-installer-package+zip",
"extensions": [
"air"
sf -json ~/local/bench/ipres/systems-showcase-files/ | jq '.files[] | select(.errors!="" or .matches[].warning!="") | .filename, .errors, .matches[].warning'
// PREPARATORY CHANGES TO SF
1. Use existing -hash flag but change behaviour so can accept a comma separated list of hashes e.g. -hash md5,ssdeep
2. change hash.go file (under /cmd/) so that checksum var is a slice of hashes var checksum []hash.Hash
3. writer interface (cmd/writers.go) updated so writeFile method takes a slice of byte slices for checksum digests (checksum [][]byte)
And all writers (JSON, CSV, YAML etc) updated so they can accept multiple checksum digests.
4. in cmd/sf.go update the identifyRdr func so it ranges through the slice of checksums, calculating for each, and returns a slice of byte slices for checksum digests
// SQLITEANALYSIS CHANGES
5. copy the hash.go flag as hash_sqliteanalysis.go and prepend build tag
6. add spamspam as an import and update the functions in this file
func deletefromslice(n int, slice []byte) []byte {
if n >= len(slice) {
return nil
}
return slice[n:]
}
// http://blog.golang.org/go-slices-usage-and-internals - is a great read for getting your head around slices!
// if reflect.DeepEqual(needle, haystack[:nlen])
package wincommands
import (
"fmt"
"io/ioutil"
"os"
"os/exec"
"path/filepath"
"strings"
"time"
@richardlehane
richardlehane / loc.txt
Created March 14, 2016 04:54
loc magic
fdd000001
Extensions: wav
MIMEs: audio/wav, audio/wave, audio/x-pn-wav, audio/x-wav, audio/vnd.wave
Magics: Hex: 52 49 46 46 xx xx xx xx 57 41 56 45 66 6D 74 20, ASCII: RIFF....WAVEfmt
fdd000002
fdd000003
Extensions: wav
[
{
"Volume": 33,
"Issue": 1,
"Date": "2005-05-01T00:00:00Z",
"Articles": [
{
"Authors": [
"Barbara Reed"
],
ID: fdd000001
Name: WAVE Audio File Format
Long Name: WAVE. Waveform Audio File Format
Exts: wav
MIMEs: audio/wav, audio/wave, audio/x-pn-wav, audio/x-wav, audio/vnd.wave
Magics: Hex: 52 49 46 46 xx xx xx xx 57 41 56 45 66 6D 74 20, ASCII: RIFF....WAVEfmt
Others: [tag: Microsoft WAVE format registry; vals: ]
Relations: [typ: Subtype of; val: fdd000025], [typ: Has subtype; val: fdd000002], [typ: Has modified version; val: fdd000356], [typ: Has modified version; val: fdd000357], [typ: May contain; val: fdd000011], [typ: May contain; val: fdd000039], [typ: May contain; val: fdd000038], [typ: May contain; val: fdd000040], [typ: May contain; val: fdd000041]
****************
ID: fdd000002
parseable_test.go:42: Parse Droid: signatures for fmt/41 are not equal:
Reports: (F B:0 seq ffd8ffed | F P:2 seq "Photoshop 3.0\x008BIM" | WW E:0-16000 seq ffd9)
Droid: (F B:0 seq ffd8ffed | F P:2 seq "Photoshop 3.0\x008BIM" | F E:0 seq ffd9)
parseable_test.go:42: Parse Droid: signatures for fmt/279 are not equal:
Reports: (WW B:0-4 seq "fLaC\x00\x00\x00\"")
Droid: (F B:0 seq "fLaC\x00\x00\x00\"")
parseable_test.go:42: Parse Droid: signatures for fmt/385 are not equal:
Reports: (F B:0 seq "\x00\x00\x02\x00" | F P:0 r "\x01" - "\t" | F P:0 seq "\x00" | F P:3 seq "\x00" | F P:1 seq "\x00" | F P:1 seq "\x00" | F P:3 seq "\x00" | WL P seq "\x00\x00(\x00\x00\x00" | F P:2 seq "\x00\x00" | F P:2 seq "\x00\x00\x01\x00" | F P:0 r "\x01" - " " | F P:0 seq "\x00\x00\x00\x00\x00" | WW B:18-1042 seq "\x00\x00(\x00\x00\x00" | F P:2 seq "\x00\x00" | F P:2 seq "\x00\x00\x01\x00" | F P:0 r "\x01" - " " | F P:0 seq "\x00\x00\x00\x00\x00")
Droid: (F B:0 seq "\x00\x00\x02\x00" | F P:0 r "\x01" - "\t