NtQuerySection

NTSTATUS __stdcall NtQuerySection(
        VOID *SectionHandle,
        _SECTION_INFORMATION_CLASS SectionInformationClass,
        VOID *SectionInformation,
        UINT64 SectionInformationLength,
        UINT64 *ReturnLength){
  char PreviousMode; 
  __int64 v10; 
  UINT64 v11; 
  int v12; 
  _SECTION_INFORMATION_CLASS v13; 
  _ADAPTER_OBJECT *v14; 
  PVOID SectionObject; 

  PreviousMode = KeGetCurrentThread()->PreviousMode;
  if( PreviousMode )
  {
    ProbeForWrite((UINT64)SectionInformation, SectionInformationLength, 4i64);
    if( ReturnLength )
    {
      v10 = 0x7FFFFFFF0000i64;
      if( (unsigned __int64)ReturnLength < 0x7FFFFFFF0000i64 )
        v10 = (__int64)ReturnLength;
      *(_QWORD *)v10 = *(_QWORD *)v10;
    }
  }
  if( SectionInformationClass )
  {
    if( SectionInformationClass == SectionImageInformation )
    {
      v11 = 64i64;
    }
    else
    {
      if( SectionInformationClass != SectionRelocationInformation
        && SectionInformationClass != SectionOriginalBaseInformation )
      {
        return -1073741821;
      }
      v11 = 8i64;
    }
  }
  else
  {
    v11 = 24i64;
  }
  if( SectionInformationLength < v11 )
    return -1073741820;
  SectionObject = 0i64;
  v12 = ObReferenceObjectByHandle(SectionHandle, 1ui64, MmSectionObjectType, PreviousMode, &SectionObject, 0i64);
  if( v12 >= 0 )
  {
    v13 = SectionInformationClass;
    v14 = (_ADAPTER_OBJECT *)SectionObject;
    v12 = MmGetSectionInformation(SectionObject, v13, SectionInformation);
    if( v12 >= 0 )
    {
      if( ReturnLength )
        *ReturnLength = v11;
    }
    HalPutDmaAdapter(v14);
  }
  return v12;
}

Referenced by:

No references.