AuthzBasepCopyoutSecurityAttributes
int __fastcall AuthzBasepCopyoutSecurityAttributes(_DWORD *a1, __int64 a2, unsigned int a3, _DWORD *a4, size_t Size){
size_t v5;
unsigned int v6;
_DWORD *v10;
UINT8 *v11;
unsigned int v12;
int result;
__int64 v14;
int v15;
ULONGLONG v16;
_DWORD *v17;
UNICODE_STRING *SecurityAttribute;
UINT8 *v19;
int Buffer_high;
ULONGLONG Length;
UINT64 v22;
INT64 *v23;
INT64 v24;
_DWORD *v25;
UINT8 *v26;
ULONGLONG v27;
UINT64 v28;
ULONGLONG pullResult;
v5 = Size;
v6 = 0;
v10 = a1;
if( !a4 || !Size )
{
result = -1073741811;
goto LABEL_16;
}
v11 = (UINT8 *)a4 + Size;
if( (_DWORD *)((char *)a4 + Size) < a4 )
{
result = -1073741811;
}
else
{
memset((INT64)a4, 0i64);
pullResult = 16i64;
if( a4 + 4 > (_DWORD *)v11 )
{
result = -1073741789;
}
else
{
v12 = a3;
if( !a2 )
v12 = *v10;
result = RtlULongLongMult(0x28ui64, v12, &pullResult);
if( result >= 0 )
{
v16 = v14 + pullResult;
if( v14 + pullResult <= (unsigned __int64)v11 )
{
*a4 = 1;
a4[1] = v15;
*((_QWORD *)a4 + 1) = v14;
if( a2 )
{
if( a3 )
{
v17 = (_DWORD *)(v14 + 24);
while( 1 )
{
SecurityAttribute = AuthzBasepFindSecurityAttribute(
(__int64)v10,
(const UNICODE_STRING *)(a2 + 16i64 * v6));
if( !SecurityAttribute )
break;
*((_WORD *)v17 - 4) = SecurityAttribute[3].Length;
v19 = (UINT8 *)((v16 + 1) & 0xFFFFFFFFFFFFFFFEui64);
Buffer_high = HIDWORD(SecurityAttribute[3].Buffer);
*((_WORD *)v17 - 3) = 0;
*v17 = Buffer_high;
*(v17 - 1) = *(_DWORD *)(&SecurityAttribute[3].MaximumLength + 1);
Length = SecurityAttribute[2].Length;
pullResult = Length;
if( &v19[Length] > v11 )
goto LABEL_28;
*((_WORD *)v17 - 12) = Length;
*((_WORD *)v17 - 11) = Length;
*((_QWORD *)v17 - 2) = v19;
memmove(v19, (UINT8 *)SecurityAttribute[2].Buffer, (unsigned int)Length);
v22 = (UINT64)&v19[pullResult];
result = AuthzBasepCopyoutSecurityAttributeValues(
(INT64)SecurityAttribute,
(INT64)(v17 - 6),
v22,
(INT64)&v11[-v22],
(INT64)&pullResult);
if( result < 0 )
goto LABEL_25;
v16 = pullResult + v22;
++v6;
v10 = a1;
v17 += 10;
if( v6 >= a3 )
goto LABEL_16;
}
result = -1073741275;
goto LABEL_25;
}
LABEL_16:
if( result >= 0 )
return result;
goto LABEL_25;
}
v23 = (INT64 *)(v10 + 2);
v24 = *v23;
if( (INT64 *)*v23 == v23 )
goto LABEL_16;
v25 = (_DWORD *)(v14 + 24);
while( 1 )
{
*((_WORD *)v25 - 4) = *(_WORD *)(v24 + 48);
*v25 = *(_DWORD *)(v24 + 60);
*((_WORD *)v25 - 3) = 0;
v26 = (UINT8 *)((v16 + 1) & 0xFFFFFFFFFFFFFFFEui64);
*(v25 - 1) = *(_DWORD *)(v24 + 52);
v27 = *(unsigned __int16 *)(v24 + 32);
pullResult = v27;
if( &v26[v27] > v11 )
break;
*((_WORD *)v25 - 12) = v27;
*((_WORD *)v25 - 11) = v27;
*((_QWORD *)v25 - 2) = v26;
memmove(v26, *(UINT8 **)(v24 + 40), (unsigned int)v27);
v28 = (UINT64)&v26[pullResult];
result = AuthzBasepCopyoutSecurityAttributeValues(
v24,
(INT64)(v25 - 6),
v28,
(INT64)&v11[-v28],
(INT64)&pullResult);
if( result < 0 )
goto LABEL_25;
v16 = pullResult + v28;
v25 += 10;
v24 = *(_QWORD *)v24;
if( (INT64 *)v24 == v23 )
goto LABEL_16;
}
}
LABEL_28:
result = -2147483643;
}
}
}
LABEL_25:
if( v5 >= 0x10 )
*(_OWORD *)a4 = 0i64;
return result;
}Referenced by:
AuthzBasepQuerySecurityAttributesToken