1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
|
#!/usr/bin/env python
'''
Metadata anonymisation toolkit library
'''
import sys
import os
import subprocess
import hachoir_core.cmd_line
import hachoir_parser
import hachoir_editor
import images
import audio
import misc
import archive
__version__ = "0.1"
__author__ = "jvoisin"
strippers = {
hachoir_parser.image.JpegFile: images.JpegStripper,
hachoir_parser.image.PngFile: images.PngStripper,
hachoir_parser.audio.MpegAudioFile: audio.MpegAudioStripper,
hachoir_parser.misc.PDFDocument: misc.PdfStripper,
hachoir_parser.archive.TarFile: archive.TarStripper,
hachoir_parser.archive.gzip_parser.GzipParser: archive.GzipStripper,
hachoir_parser.archive.bzip2_parser.Bzip2Parser: archive.Bzip2Stripper,
}
def secure_remove(filename):
'''
securely remove the file
'''
#FIXME : Vulnerable to shell injection ?
try:
subprocess.call('shred --remove %s' % filename, shell=True)
except:
print('Unable to remove %s' % filename)
def is_secure(filename):
'''
Prevent shell injection
'''
if not(os.path.isfile(filename)): #check if the file exist
print("Error: %s is not a valid file" % filename)
sys.exit(1)
def create_class_file(name, backup):
'''
return a $FILETYPEStripper() class,
corresponding to the filetype of the given file
'''
is_secure(name)
filename = ""
realname = name
filename = hachoir_core.cmd_line.unicodeFilename(name)
parser = hachoir_parser.createParser(filename)
if not parser:
print("Unable to parse the file %s with hachoir-parser." % filename)
sys.exit(1)
editor = hachoir_editor.createEditor(parser)
try:
'''this part is a little tricky :
stripper_class will receice the name of the class $FILETYPEStripper,
(which herits from the "file" class), based on the editor
of given file (name)
'''
stripper_class = strippers[editor.input.__class__]
except KeyError:
#Place for another lib than hachoir
print("Don't have stripper for file type: %s" % editor.description)
sys.exit(1)
if editor.input.__class__ == hachoir_parser.misc.PDFDocument:
return stripper_class(filename, backup)
return stripper_class(realname, filename, parser, editor, backup)
|