NtQuerySecurityObject
NTSTATUS __stdcall NtQuerySecurityObject(
VOID *Handle,
UINT64 SecurityInformation,
VOID *SecurityDescriptor,
UINT64 Length,
UINT64 *LengthNeeded){
KPROCESSOR_MODE v7;
UINT64 *v8;
__int64 v9;
NTSTATUS result;
struct _DMA_ADAPTER *v11;
__int64 v12;
NTSTATUS v13;
UINT64 DesiredAccess;
PVOID Object;
struct _OBJECT_HANDLE_INFORMATION HandleInformation;
UINT64 SecurityInformationa;
SIZE_T Lengtha;
LODWORD(Lengtha) = Length;
LODWORD(SecurityInformationa) = SecurityInformation;
LODWORD(DesiredAccess) = 0;
HandleInformation = 0i64;
v7 = *((_BYTE *)KeGetCurrentThread() + 562);
if( v7 )
{
v8 = LengthNeeded;
v9 = (__int64)LengthNeeded;
if( (unsigned __int64)LengthNeeded >= 0x7FFFFFFF0000i64 )
v9 = 0x7FFFFFFF0000i64;
*(_DWORD *)v9 = *(_DWORD *)v9;
ProbeForWrite(SecurityDescriptor, (unsigned int)Lengtha, 4ui64);
}
else
{
v8 = LengthNeeded;
}
SeQuerySecurityAccessMask((unsigned int)SecurityInformationa, &DesiredAccess);
Object = 0i64;
result = ObReferenceObjectByHandle(Handle, DesiredAccess, 0i64, v7, &Object, &HandleInformation);
if( result >= 0 )
{
v11 = (struct _DMA_ADAPTER *)Object;
v12 = ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ (unsigned __int8)*((char *)Object - 24) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)Object - 48) >> 8)];
v13 = (*(__int64(__fastcall **)(PVOID, __int64, UINT64 *, VOID *, SIZE_T *, char *, _DWORD, __int64, KPROCESSOR_MODE))(v12 + 152))(
Object,
1i64,
&SecurityInformationa,
SecurityDescriptor,
&Lengtha,
(char *)Object - 8,
*(_DWORD *)(v12 + 100),
v12 + 76,
v7);
*(_DWORD *)v8 = Lengtha;
HalPutDmaAdapter(v11);
return v13;
}
return result;
}Referenced by:
RtlpSysVolCheckOwnerAndSecurity