From 2166834d87c267fc9194f66c56531efc82ee2276 Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Mon, 3 Aug 2020 20:36:40 +0100 Subject: [PATCH] Timeliner: Actually make use of the TextIoWrapper --- volatility/framework/plugins/timeliner.py | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/volatility/framework/plugins/timeliner.py b/volatility/framework/plugins/timeliner.py index aa1da4b69..527d4ee4d 100644 --- a/volatility/framework/plugins/timeliner.py +++ b/volatility/framework/plugins/timeliner.py @@ -143,14 +143,13 @@ class Timeliner(interfaces.plugins.PluginInterface): # Body format is: MD5|name|inode|mode_as_string|UID|GID|size|atime|mtime|ctime|crtime if self._any_time_present(times): - filedata.data.write( - bytes( - "|{} - {}||||||{}|{}|{}|{}\n".format( - plugin_name, self._sanitize_body_format(item), - self._text_format(times.get(TimeLinerType.ACCESSED, "")), - self._text_format(times.get(TimeLinerType.MODIFIED, "")), - self._text_format(times.get(TimeLinerType.CHANGED, "")), - self._text_format(times.get(TimeLinerType.CREATED, ""))), "raw_unicode_escape")) + fp.write( + "|{} - {}||||||{}|{}|{}|{}\n".format( + plugin_name, self._sanitize_body_format(item), + self._text_format(times.get(TimeLinerType.ACCESSED, "")), + self._text_format(times.get(TimeLinerType.MODIFIED, "")), + self._text_format(times.get(TimeLinerType.CHANGED, "")), + self._text_format(times.get(TimeLinerType.CREATED, "")))) self.produce_file(filedata) def _sanitize_body_format(self, value):