SeSecurityDescriptorChangedAuditAlarm
VOID __stdcall SeSecurityDescriptorChangedAuditAlarm(
VOID *Object,
_UNICODE_STRING *ObjectTypeName,
VOID *HandleId,
UINT64 DesiredAccess,
UINT64 ChangedSecurityInfo,
VOID *OldSecurityDescriptorDaclOwner,
VOID *OldSecurityDescriptorAudit,
VOID *OldSecurityDescriptorAttribute,
VOID *OldSecurityDescriptorScope,
VOID *NewSecurityDescriptor){
int v10;
int v11;
char *v12;
void *PrimaryToken;
UINT8 v15;
VOID *v16;
unsigned int v17;
_WORD *v18;
__int16 v19;
__int64 v20;
char *v21;
unsigned int *v22;
char *v23;
__int16 v24;
char *v25;
char *v26;
__int16 v27;
__int64 v28;
_WORD *v29;
__int16 v30;
unsigned __int16 *v31;
unsigned __int16 *v32;
__int16 v33;
_WORD *v34;
unsigned __int16 *v35;
__int16 v36;
unsigned int v37;
int v38;
__int64 v39;
__int16 v40;
__int64 v41;
_ACL *v42;
__int16 v43;
__int64 v44;
__int16 v45;
__int64 v46;
__int16 v47;
__int16 v48;
_SIZE_T *v49;
_SIZE_T *v50;
_SIZE_T *v51;
_SIZE_T *v52;
_SIZE_T *v53;
_SIZE_T *v54;
bool v55;
_SIZE_T *v56;
_SIZE_T *v57;
int v58;
__int64 v59;
char *v60;
__int64 v61;
char *v62;
__int64 v63;
char *v64;
__int64 v65;
char *v66;
__int16 v67;
__int64 v68;
_ACL *v69;
__int16 v70;
__int64 v71;
_ACL *v72;
_OBJECT_NAME_INFORMATION *v73;
VOID *UserSid;
_UNICODE_STRING *v75;
unsigned int v76;
VOID *OldSecurityDescriptor;
UINT64 SecurityInformation;
unsigned __int16 *v79;
char *v80;
int v81;
UINT64 pAuditMask;
_UNICODE_STRING *ObjectTypeNamea;
unsigned int v84;
VOID *Token;
_OBJECT_NAME_INFORMATION *ObjectNameInfo;
_UNICODE_STRING *TypeName;
VOID *v88;
VOID *Source2;
_OBJECT_NAME_INFORMATION *v90;
_SECURITY_SUBJECT_CONTEXT SubjectContext;
__int16 v92;
__int16 v94;
__int16 OldSecurityDescriptorDaclOwnera;
_WORD *v96;
_WORD *v97;
_WORD *v98;
pAuditMask = 0i64;
memset(&SubjectContext, 0, sizeof(SubjectContext));
v10 = 0;
ObjectNameInfo = 0i64;
TypeName = 0i64;
v11 = 0;
v90 = 0i64;
v12 = 0i64;
ObjectTypeNamea = 0i64;
v84 = 0;
v81 = 0;
v88 = 0i64;
v92 = 0;
v79 = 0i64;
v94 = 0;
Source2 = 0i64;
OldSecurityDescriptorDaclOwnera = 0;
SeCaptureSubjectContext((INT64)&SubjectContext);
PrimaryToken = SubjectContext.PrimaryToken;
if( SubjectContext.ClientToken )
PrimaryToken = SubjectContext.ClientToken;
Token = PrimaryToken;
if( !PrimaryToken )
{
SepAuditFailed(3221225596i64);
return;
}
v15 = SepAdtAuditThisEventWithContext(0x8Dui64, 1u, 0, &SubjectContext);
if( v15 && v96 )
v11 = (unsigned __int8)OldSecurityDescriptorAttribute & 0x20;
if( ((unsigned int)OldSecurityDescriptorAudit & 0x1000000) != 0 )
{
if( SepAdtAuditThisEventWithContext(0x8Bui64, 1u, 0, &SubjectContext) )
v11 |= (unsigned __int8)OldSecurityDescriptorAttribute & 8;
if( v15 && v97 )
v11 |= (unsigned __int8)OldSecurityDescriptorAttribute & 0x40;
}
if( !HandleId || !*(_WORD *)HandleId )
{
if( !ObjectTypeName )
{
HandleId = 0i64;
goto LABEL_9;
}
HIDWORD(pAuditMask) = SepQueryTypeString(ObjectTypeName, &TypeName);
if( (pAuditMask & 0x8000000000000000ui64) != 0i64 )
goto LABEL_210;
HandleId = 0i64;
if( TypeName )
HandleId = TypeName;
}
ObjectTypeNamea = (_UNICODE_STRING *)HandleId;
LABEL_9:
v16 = NewSecurityDescriptor;
v17 = (unsigned int)OldSecurityDescriptorAudit & 0xFEFFFFFF;
if( ((unsigned int)OldSecurityDescriptorAudit & 0xFEFFFFFF) == 0 )
goto LABEL_10;
v40 = *((_WORD *)NewSecurityDescriptor + 1);
if( (v40 & 0x10) == 0 )
goto LABEL_87;
if( v40 >= 0 )
{
v42 = (_ACL *)*((_QWORD *)NewSecurityDescriptor + 3);
goto LABEL_89;
}
v41 = *((unsigned int *)NewSecurityDescriptor + 3);
if( (_DWORD)v41 )
v42 = (_ACL *)((char *)NewSecurityDescriptor + v41);
else
LABEL_87:
v42 = 0i64;
LABEL_89:
SeMaximumAuditMask(v42, v17, Token, &pAuditMask);
SeMaximumAuditMaskFromGlobalSacl((_UNICODE_STRING *)HandleId, v17, Token, &pAuditMask);
if( (pAuditMask & 0x80000) != 0 && v15 )
v11 |= (unsigned __int8)OldSecurityDescriptorAttribute & 0x10;
LABEL_10:
v18 = v98;
v19 = v98[1];
if( (v19 & 0x10) == 0 )
{
LABEL_69:
v21 = 0i64;
goto LABEL_14;
}
if( v19 < 0 )
{
v20 = *((unsigned int *)v98 + 3);
if( (_DWORD)v20 )
{
v21 = (char *)v98 + v20;
goto LABEL_14;
}
goto LABEL_69;
}
v21 = (char *)*((_QWORD *)v98 + 3);
LABEL_14:
v80 = v21;
if( !NewSecurityDescriptor )
goto LABEL_15;
v27 = *((_WORD *)NewSecurityDescriptor + 1);
if( (v27 & 0x10) == 0 )
{
LABEL_44:
v12 = 0i64;
goto LABEL_15;
}
if( v27 < 0 )
{
v28 = *((unsigned int *)NewSecurityDescriptor + 3);
if( (_DWORD)v28 )
{
v12 = (char *)NewSecurityDescriptor + v28;
goto LABEL_15;
}
goto LABEL_44;
}
v12 = (char *)*((_QWORD *)NewSecurityDescriptor + 3);
LABEL_15:
v22 = (unsigned int *)OldSecurityDescriptorScope;
if( !OldSecurityDescriptorScope )
{
v23 = 0i64;
goto LABEL_17;
}
v43 = *((_WORD *)OldSecurityDescriptorScope + 1);
if( (v43 & 0x10) == 0 )
{
LABEL_98:
v23 = 0i64;
goto LABEL_17;
}
if( v43 < 0 )
{
v44 = *((unsigned int *)OldSecurityDescriptorScope + 3);
if( (_DWORD)v44 )
{
v23 = (char *)OldSecurityDescriptorScope + v44;
goto LABEL_17;
}
goto LABEL_98;
}
v23 = (char *)*((_QWORD *)OldSecurityDescriptorScope + 3);
LABEL_17:
if( v96 )
{
v24 = v96[1];
if( (v24 & 0x10) == 0 )
{
LABEL_19:
v25 = 0i64;
goto LABEL_20;
}
if( v24 >= 0 )
{
v25 = (char *)*((_QWORD *)v96 + 3);
}
else
{
v39 = *((unsigned int *)v96 + 3);
if( !(_DWORD)v39 )
goto LABEL_19;
v25 = (char *)v96 + v39;
}
}
else
{
v25 = 0i64;
}
LABEL_20:
if( !v97 )
{
v26 = 0i64;
goto LABEL_22;
}
v45 = v97[1];
if( (v45 & 0x10) == 0 )
{
LABEL_105:
v26 = 0i64;
goto LABEL_22;
}
if( v45 < 0 )
{
v46 = *((unsigned int *)v97 + 3);
if( (_DWORD)v46 )
{
v26 = (char *)v97 + v46;
goto LABEL_22;
}
goto LABEL_105;
}
v26 = (char *)*((_QWORD *)v97 + 3);
LABEL_22:
if( !v21 || !*((_WORD *)v21 + 2) )
{
if( v12 && *((_WORD *)v12 + 2) )
v10 = v11 & 8;
if( v23 && *((_WORD *)v23 + 2) )
v10 |= v11 & 0x10;
if( v25 && *((_WORD *)v25 + 2) )
v10 |= v11 & 0x20;
if( v26 && *((_WORD *)v26 + 2) )
{
v38 = v11 & 0x40;
LABEL_152:
v10 |= v38;
}
goto LABEL_28;
}
if( !v11 )
goto LABEL_28;
v29 = v21 + 8;
if( v12 && (v47 = *((_WORD *)v12 + 2)) != 0 )
{
v31 = (unsigned __int16 *)(v12 + 8);
v92 = v47;
v30 = v47;
}
else
{
v30 = 0;
v31 = 0i64;
}
if( v23 && *((_WORD *)v23 + 2) )
{
v81 = *((unsigned __int16 *)v23 + 2);
v88 = v23 + 8;
}
if( v25 && *((_WORD *)v25 + 2) )
{
v32 = (unsigned __int16 *)(v25 + 8);
v94 = *((_WORD *)v25 + 2);
v79 = (unsigned __int16 *)(v25 + 8);
}
else
{
v32 = 0i64;
}
if( v26 && (v48 = *((_WORD *)v26 + 2)) != 0 )
{
OldSecurityDescriptorDaclOwnera = *((_WORD *)v26 + 2);
Source2 = v26 + 8;
v33 = v48;
}
else
{
v33 = 0;
}
v34 = v88;
v35 = (unsigned __int16 *)Source2;
do
{
if( *(_BYTE *)v29 != 17 )
{
if( *(_BYTE *)v29 == 18 )
{
if( (v11 & 0x20) == 0 )
goto LABEL_56;
if( v32 && v29[1] == v32[1] )
{
v53 = (_SIZE_T *)v32[1];
v54 = RtlCompareMemory(v29, v32, v32[1]);
v21 = v80;
if( v54 == v53 )
{
v36 = v94 - 1;
v30 = v92;
v33 = OldSecurityDescriptorDaclOwnera;
v55 = v94-- != 1;
v32 = (unsigned __int16 *)(((__int64)v79 + (_QWORD)v53) & -(__int64)v55);
v79 = v32;
goto LABEL_57;
}
v32 = v79;
}
v10 |= 0x20u;
v11 &= ~0x20u;
goto LABEL_128;
}
if( *(_BYTE *)v29 == 19 )
{
if( (v11 & 0x40) == 0 )
goto LABEL_56;
if( v35 )
{
if( v29[1] == v35[1] )
{
v51 = (_SIZE_T *)v35[1];
v52 = RtlCompareMemory(v29, v35, v35[1]);
v21 = v80;
if( v52 == v51 )
{
v32 = v79;
v30 = v92;
v33 = --OldSecurityDescriptorDaclOwnera;
v35 = (unsigned __int16 *)(((__int64)v35 + (_QWORD)v51) & -(__int64)(OldSecurityDescriptorDaclOwnera != 0));
goto LABEL_56;
}
}
}
v10 |= 0x40u;
v11 &= ~0x40u;
}
else
{
if( (v11 & 8) == 0 )
goto LABEL_56;
if( v31 )
{
if( *(_BYTE *)v31 == *(_BYTE *)v29 && v29[1] == v31[1] )
{
v49 = (_SIZE_T *)v31[1];
v50 = RtlCompareMemory(v29, v31, v31[1]);
v21 = v80;
if( v50 == v49 )
{
v30 = --v92;
v31 = (unsigned __int16 *)(((__int64)v31 + (_QWORD)v49) & -(__int64)(v92 != 0));
LABEL_144:
v32 = v79;
goto LABEL_145;
}
}
}
v10 |= 8u;
v11 &= ~8u;
}
LABEL_125:
v32 = v79;
LABEL_128:
v30 = v92;
LABEL_145:
v33 = OldSecurityDescriptorDaclOwnera;
goto LABEL_56;
}
if( (v11 & 0x10) != 0 )
{
if( !v34
|| v29[1] != v34[1]
|| (v56 = (_SIZE_T *)(unsigned __int16)v34[1],
v57 = RtlCompareMemory(v29, v34, (unsigned __int16)v34[1]),
v21 = v80,
v57 != v56) )
{
v30 = v92;
v10 |= 0x10u;
v11 &= ~0x10u;
goto LABEL_144;
}
v34 = (_WORD *)(((__int64)v34 + (_QWORD)v56) & -(__int64)(--v81 != 0));
goto LABEL_125;
}
LABEL_56:
v36 = v94;
LABEL_57:
v29 = (_WORD *)((char *)v29 + (unsigned __int16)v29[1]);
v37 = *((unsigned __int16 *)v21 + 2);
++v84;
}
while( v84 < v37 && v11 );
v22 = (unsigned int *)OldSecurityDescriptorScope;
v18 = v98;
if( v30 )
v10 |= v11 & 8;
if( v36 )
v10 |= v11 & 0x20;
if( v33 )
v10 |= v11 & 0x40;
v16 = NewSecurityDescriptor;
if( v81 )
{
v38 = v11 & 0x10;
goto LABEL_152;
}
LABEL_28:
if( v22 )
{
v58 = pAuditMask;
if( (pAuditMask & 0x80000) != 0 )
{
if( ((unsigned __int8)OldSecurityDescriptorAttribute & 1) != 0 )
{
if( (__int16)v18[1] >= 0 )
{
v60 = (char *)*((_QWORD *)v18 + 1);
}
else
{
v59 = *((unsigned int *)v18 + 1);
v60 = (_DWORD)v59 ? (char *)v18 + v59 : 0i64;
}
if( *((__int16 *)v22 + 1) >= 0 )
{
v62 = (char *)*((_QWORD *)v22 + 1);
}
else
{
v61 = v22[1];
v62 = (_DWORD)v61 ? (char *)v22 + v61 : 0i64;
}
if( !SepIsSidEqual(v62, v60) )
v10 |= 1u;
}
if( ((unsigned __int8)OldSecurityDescriptorAttribute & 2) != 0 )
{
if( (__int16)v18[1] >= 0 )
{
v64 = (char *)*((_QWORD *)v18 + 2);
}
else
{
v63 = *((unsigned int *)v18 + 2);
v64 = (_DWORD)v63 ? (char *)v18 + v63 : 0i64;
}
if( *((__int16 *)v22 + 1) >= 0 )
{
v66 = (char *)*((_QWORD *)v22 + 2);
}
else
{
v65 = v22[2];
v66 = (_DWORD)v65 ? (char *)v22 + v65 : 0i64;
}
if( !SepIsSidEqual(v66, v64) )
v10 |= 2u;
}
}
if( (v58 & 0x40000) != 0 )
{
v67 = v18[1];
if( (v67 & 4) == 0 )
goto LABEL_185;
if( v67 >= 0 )
{
v69 = (_ACL *)*((_QWORD *)v18 + 4);
}
else
{
v68 = *((unsigned int *)v18 + 4);
if( (_DWORD)v68 )
{
v69 = (_ACL *)((char *)v18 + v68);
goto LABEL_187;
}
LABEL_185:
v69 = 0i64;
}
LABEL_187:
v70 = *((_WORD *)v22 + 1);
if( (v70 & 4) == 0 )
goto LABEL_191;
if( v70 >= 0 )
{
v72 = (_ACL *)*((_QWORD *)v22 + 4);
goto LABEL_193;
}
v71 = v22[4];
if( (_DWORD)v71 )
v72 = (_ACL *)((char *)v22 + v71);
else
LABEL_191:
v72 = 0i64;
LABEL_193:
if( !SepIsAclEqual(v72, v69) )
v10 |= 4u;
}
}
if( v10 )
{
if( !ObjectTypeName )
{
v73 = v90;
LABEL_201:
UserSid = (VOID *)**((_QWORD **)Token + 19);
if( (v10 & 8) != 0 )
{
LODWORD(SecurityInformation) = 8;
OldSecurityDescriptor = v16;
v75 = ObjectTypeNamea;
SepAdtSecurityDescriptorChangedAuditAlarm(
&SubjectContext,
(_UNICODE_STRING *)&SeSubsystemName,
ObjectTypeNamea,
(_UNICODE_STRING *)v73,
(VOID *)ChangedSecurityInfo,
UserSid,
OldSecurityDescriptor,
SecurityInformation,
v18);
}
else
{
v75 = ObjectTypeNamea;
}
if( (v10 & 0x20) != 0 )
{
LODWORD(SecurityInformation) = 32;
SepAdtSecurityDescriptorChangedAuditAlarm(
&SubjectContext,
(_UNICODE_STRING *)&SeSubsystemName,
v75,
(_UNICODE_STRING *)v73,
(VOID *)ChangedSecurityInfo,
UserSid,
v96,
SecurityInformation,
v18);
}
if( (v10 & 0x40) != 0 )
{
LODWORD(SecurityInformation) = 64;
SepAdtSecurityDescriptorChangedAuditAlarm(
&SubjectContext,
(_UNICODE_STRING *)&SeSubsystemName,
v75,
(_UNICODE_STRING *)v73,
(VOID *)ChangedSecurityInfo,
UserSid,
v97,
SecurityInformation,
v18);
}
v76 = v10 & 0xFFFFFF97;
if( v76 )
{
LODWORD(SecurityInformation) = v76;
SepAdtSecurityDescriptorChangedAuditAlarm(
&SubjectContext,
(_UNICODE_STRING *)&SeSubsystemName,
v75,
(_UNICODE_STRING *)v73,
(VOID *)ChangedSecurityInfo,
UserSid,
v22,
SecurityInformation,
v18);
}
goto LABEL_210;
}
HIDWORD(pAuditMask) = SepQueryNameString(ObjectTypeName, (PVOID *)&ObjectNameInfo);
if( (pAuditMask & 0x8000000000000000ui64) == 0i64 )
{
v73 = v90;
if( ObjectNameInfo )
v73 = ObjectNameInfo;
goto LABEL_201;
}
LABEL_210:
if( ObjectNameInfo )
ExFreePoolWithTag(ObjectNameInfo, 0);
if( TypeName )
ExFreePoolWithTag(TypeName, 0);
}
if( (pAuditMask & 0x8000000000000000ui64) != 0i64 )
SepAuditFailed(HIDWORD(pAuditMask));
SeReleaseSubjectContext(&SubjectContext);
}Referenced by:
NtSetSecurityObject