Beispiel #1
0
def new_folder(request, case_id):
    """Load files from a local directory."""
    case = get_object_or_404(Case, pk=case_id)

    # Security check.
    if not(request.user.is_superuser or request.user in case.users.all()):
        return render_to_response("error.html",
                                  {"error": "You are not authorized to add image to this."},
                                  context_instance=RequestContext(request))

    if case.state == "C":
        return render_to_response("error.html",
                                  {"error": "You cannot add an image to a closed case."},
                                  context_instance=RequestContext(request))

    if request.method == "POST":
        form = forms.ImageFolderForm(request.POST)
        if form.is_valid():
            # Check.
            if not os.path.exists(request.POST.get("path")):
                return render_to_response("error.html",
                    {"error": "Folder does not exist."},
                    context_instance=RequestContext(request))
            elif not os.path.isdir(request.POST.get("path")):
                return render_to_response("error.html",
                    {"error": "Folder is not a directory."},
                    context_instance=RequestContext(request))
            # Add all files in directory.
            mime = magic.Magic(mime=True)
            for file in os.listdir(request.POST.get("path")):
                content_type = mime.from_file(os.path.join(request.POST.get("path"), file))
                # Check if content type is allowed.
                if not check_allowed_content(content_type):
                    # TODO: add some kind of feedback.
                    pass

                task = Analysis()
                task.owner = request.user
                task.case = case
                task.file_name = file
                task.image_id = save_file(file_path=os.path.join(request.POST.get("path"), file),
                                          content_type=content_type)
                task.thumb_id = create_thumb(os.path.join(request.POST.get("path"), file))
                task.save()

                # Auditing.
                log_activity("I",
                             "Created new analysis {0}".format(task.file_name),
                             request)
            return HttpResponseRedirect(reverse("analyses.views.show_case", args=(case.id, "list")))
    else:
        form = forms.ImageFolderForm()

    return render_to_response("analyses/images/new_folder.html",
                              {"form": form, "case": case},
                              context_instance=RequestContext(request))
Beispiel #2
0
 def clean_image(self):
     image = self.cleaned_data.get("image", False)
     if image:
         # File check.
         if image._size > settings.MAX_FILE_UPLOAD:
             raise ValidationError("Image file too large")
         # Type check.
         file_type = get_content_type_from_file(image.temporary_file_path())
         if not check_allowed_content(file_type):
             raise ValidationError("Image type not supported.")
     else:
         raise ValidationError("Image field is mandatory.")
Beispiel #3
0
 def clean_image(self):
     image = self.cleaned_data.get("image", False)
     if image:
         # File check.
         if image._size > settings.MAX_FILE_UPLOAD:
             raise ValidationError("Image file too large")
         # Type check.
         file_type = get_content_type_from_file(image.temporary_file_path())
         if not check_allowed_content(file_type):
             raise ValidationError("Image type not supported.")
     else:
         raise ValidationError("Image field is mandatory.")
Beispiel #4
0
 def _add_task(self, file, case, user):
     """Adds a new task to database.
     @param file: file path
     @param case: case id
     @param user: user id
     """
     # File type check.
     mime = magic.Magic(mime=True)
     content_type = mime.from_file(file)
     if not check_allowed_content(content_type):
         print "WARNING: Skipping %s: file type not allowed." % file
     else:
         # Add to analysis queue.
         task = Analysis()
         task.owner = user
         task.case = case
         task.file_name = os.path.basename(file)
         task.image_id = save_file(file_path=file, content_type=content_type)
         task.thumb_id = create_thumb(file)
         task.save()
Beispiel #5
0
    def add_task(file_path, file_name=None, case=None, user=None, content_type=None, image_id=None, thumb_id=None):
        """Adds a new task to database.
        @param file_path: file path
        @param file_name: file name
        @param case: case id
        @param user: user id
        @param content_type: file content type
        @param image_id: original image gridfs id
        @param thumb_id: thumbnail gridfs id
        """
        # TODO: re enable with py3 support.
        # assert isinstance(file_path, str)

        # File name.
        if not file_name:
            file_name = os.path.basename(file_path)

        # File type check.
        if not content_type:
            content_type = get_content_type_from_file(file_path)

        # If image is not already stored on gridfs.
        if not image_id:
            image_id = save_file(file_path=file_path, content_type=content_type)

        # If image thumbnail is available.
        if not thumb_id:
            thumb_id = create_thumb(file_path)

        # Check on allowed file type.
        if not check_allowed_content(content_type):
            raise GhiroValidationException("Skipping %s: file type not allowed." % file_name)
        else:
            # Add to analysis queue.
            return Analysis.objects.create(
                owner=user, case=case, file_name=file_name, image_id=image_id, thumb_id=thumb_id
            )
Beispiel #6
0
def new_url(request, case_id):
    """Upload a new image via URL."""
    case = get_object_or_404(Case, pk=case_id)

    # Security check.
    if not request.user.is_superuser and not request.user in case.users.all():
        return render_to_response("error.html",
            {"error": "You are not authorized to add image to this."},
            context_instance=RequestContext(request))

    if case.state == "C":
        return render_to_response("error.html",
            {"error": "You cannot add an image to a closed case."},
            context_instance=RequestContext(request))

    if request.method == "POST":
        form = forms.UrlForm(request.POST)

        if form.is_valid():
            # Download file.
            try:
                url = urllib2.urlopen(request.POST.get("url"), timeout=5)
            except urllib2.URLError as e:
                if hasattr(e, "reason"):
                    return render_to_response("error.html",
                        {"error": "We failed to reach a server, reason: %s" % e.reason},
                        context_instance=RequestContext(request))
                elif hasattr(e, "code"):
                    return render_to_response("error.html",
                        {"error": "The remote server couldn't fulfill the request, HTTP error code %s" % e.code},
                        context_instance=RequestContext(request))

            # Store temp file.
            url_temp = NamedTemporaryFile(delete=True)
            url_temp.write(url.read())
            url_temp.flush()

            # Convert to File object.
            url_file = File(url_temp).name

            # Check content type.
            mime = magic.Magic(mime=True)
            content_type = mime.from_file(url_file)
            if not check_allowed_content(content_type):
                return render_to_response("error.html",
                    {"error": "File type not supported"},
                    context_instance=RequestContext(request))

            # Create analysis task.
            task = Analysis()
            task.owner = request.user
            task.case = case
            task.file_name = os.path.basename(urlparse.urlparse(request.POST.get("url")).path)
            task.image_id = save_file(file_path=url_file, content_type=content_type)
            task.thumb_id = create_thumb(url_file)
            task.save()
            # Auditing.
            log_activity("I",
                "Created new analysis {0} from URL {1}".format(task.file_name, request.POST.get("url")),
                request)
            return HttpResponseRedirect(reverse("analyses.views.show_case", args=(case.id, "list")))
    else:
        # Request is not a POST.
        form = forms.UrlForm()

    return render_to_response("analyses/images/new_url.html",
        {"form": form, "case": case},
        context_instance=RequestContext(request))
Beispiel #7
0
class Command(BaseCommand):
    """Image submission via command line."""

    option_list = BaseCommand.option_list + (
        make_option("--target",
                    "-t",
                    dest="target",
                    help="Path of the file or directory to submit"),
        make_option("--case",
                    "-c",
                    dest="case",
                    help="Case ID, images will be attached to it"),
        make_option("--username", "-u", dest="username", help="Username"),
        make_option("--recurse",
                    "-r",
                    dest="recurse",
                    default=False,
                    action="store_true",
                    help="Recurse inside subdirectories"),
    )

    help = "Task submission"

    def handle(self, *args, **options):
        """Runs command."""
        # Validation.
        if not options["username"] or not options["case"] or not options[
                "target"]:
            print "Options -t (target), -c (case) and -u (user are mandatory. Exiting."
            sys.exit(1)

        # Get options.
        user = Profile.objects.get(username=options["username"].strip())
        case = Case.objects.get(pk=options["case"].strip())

        # Add directory or files.
        if os.path.isdir(options["target"]) and options["recurse"]:
            for dirname, dirnames, filenames in os.walk(options["target"]):
                for filename in filenames:
                    target = os.path.join(dirname, filename)
                    print "INFO: processing {0}".format(target)
                    self._add_task(target, case, user)
        elif os.path.isdir(options["target"]):
            for file_name in os.listdir(options["target"]):
                print "INFO: processing {0}".format(file_name)
                self._add_task(os.path.join(options["target"], file_name),
                               case, user)
        elif os.path.isfile(options["target"]):
            print "INFO: processing {0}".format(options["target"])
            self._add_task(options["target"], case, user)
        else:
            print "ERROR: target is not a file or directory"

    def _add_task(self, file, case, user):
        """Adds a new task to database.
        @param file: file path
        @param case: case id
        @param user: user id
        """
        # File type check.
        mime = magic.Magic(mime=True)
        content_type = mime.from_file(file)
        if not check_allowed_content(content_type):
            print "WARNING: Skipping %s: file type not allowed." % file
        else:
            # Add to analysis queue.
            task = Analysis()
            task.owner = user
            task.case = case
            task.file_name = os.path.basename(file)
            task.image_id = save_file(file_path=file,
                                      content_type=content_type)
            task.thumb_id = create_thumb(file)
            task.save()
Beispiel #8
0
                    },
                                              context_instance=RequestContext(
                                                  request))

            # Store temp file.
            url_temp = NamedTemporaryFile(delete=True)
            url_temp.write(url.read())
            url_temp.flush()

            # Convert to File object.
            url_file = File(url_temp).name

            # Check content type.
            mime = magic.Magic(mime=True)
            content_type = mime.from_file(url_file)
            if not check_allowed_content(content_type):
                return render_to_response(
                    "error.html", {"error": "File type not supported"},
                    context_instance=RequestContext(request))

            # Create analysis task.
            task = Analysis()
            task.owner = request.user
            task.case = case
            task.file_name = os.path.basename(
                urlparse.urlparse(request.POST.get("url")).path)
            task.image_id = save_file(file_path=url_file,
                                      content_type=content_type)
            task.thumb_id = create_thumb(url_file)
            task.save()
            # Auditing.