Text File (TXT)

From ForensicsWiki
Revision as of 02:59, 24 May 2007 by Johnp9 (Talk | contribs)

Jump to: navigation, search

Text file formats usually have the .txt extension.

These files contain 8 or 16 bit bytes that use printable characters along with some control data such as tabs and line feeds. [1] Text files are split into several major types:

  • DOS/Windows format ends each line using Carriage Return (CR) or char(13) and a Line Feed (LF) char(10) byte sequence,
  • Unix format includes only the Carriage Return (CR) or char (13) at the end of the line.
  • Unicode includes an optional encoding in the first two bytes Byte Order Mark (BOM) that identifies the unicode encoding. This is mainly used to identify little endian or big endian byte order.
  • EBCIDIC used char(15) for a new line. [2]

They are usually ASCII encoded, although other encodings are possible to allow various language scripts to be used. Other encodings include EBCIDIC from the old IBM mainframe. Text files can have the MIME type "text/plain", often with suffixes indicating an encoding (e.g. "text/plain;charset=UTF-8".) Any basic text reader can be used to view the contents of a simple text file, however some (notably Notepad) have issues with certain less popular encodings. Wordpad is included with windows and may display the files properly.

Translation of a DOS/Windows text file to Unix is performed by removing the Carriage Return from the end of the line. The reverse is simply the addition of the Carriage Return to the Line Feed. Files that have double spaces between the lines may have been improperly translated from one system to another.