SepTokenIsOwner
UINT8 __stdcall SepTokenIsOwner(PVOID EffectiveToken, PVOID SecurityDescriptor, UINT8 TokenLocked){
char v3;
__int64 v5;
char *v6;
SID_AND_ATTRIBUTES *v7;
if( *((__int16 *)SecurityDescriptor + 1) >= 0 )
{
v6 = (char *)*((_QWORD *)SecurityDescriptor + 1);
}
else
{
v5 = *((unsigned int *)SecurityDescriptor + 1);
if( (_DWORD)v5 )
v6 = (char *)SecurityDescriptor + v5;
else
v6 = 0i64;
}
if( v3 && v6 && RtlEqualSid(SeAliasAdminsSid, v6) )
return 0;
v7 = RtlSidHashLookup((SID_AND_ATTRIBUTES_HASH *)((char *)EffectiveToken + 232), v6);
if( !v7
|| (v7 != *((SID_AND_ATTRIBUTES **)EffectiveToken + 30) || (v7->Attributes & 0x10) != 0)
&& (v7->Attributes & 4) == 0 )
{
return 0;
}
if( *((_DWORD *)EffectiveToken + 32) )
return SepSidInToken(EffectiveToken, 0i64, v6, 0, 1u, 0);
return 1;
}Referenced by:
SeAccessCheckByTypeWithAdminlessChecks
SeComputeCreatorDeniedRights
SepAccessCheckAndAuditAlarmWithAdminlessChecks
SepCommonAccessCheckExWithAdminlessChecks