PspWriteTebImpersonationInfo
NTSTATUS __stdcall PspWriteTebImpersonationInfo(_ETHREAD *Thread, _ETHREAD *CurrentThread){
_DWORD *Teb;
_EPROCESS *Process;
unsigned int v6;
bool v7;
_BOOL8 v8;
_EWOW64PROCESS *WoW64Process;
unsigned __int16 Machine;
int v12[8];
char v13;
bool v14;
_DWORD *v15;
_EPROCESS *v16;
_ETHREAD *v17;
_KAPC_STATE ApcState;
v17 = Thread;
memset(&ApcState, 0, sizeof(ApcState));
Teb = Thread->Tcb.Teb;
v15 = Teb;
if( Teb && (Thread->Tcb._bf_0 & 0x400) == 0 )
{
Process = Thread->Tcb.Process;
v16 = Process;
if( CurrentThread->Tcb.ApcState.Process == Process )
{
v13 = 0;
}
else
{
KiStackAttachProcess(Process, 0i64, &ApcState);
v13 = 1;
}
if( Thread == CurrentThread || ExAcquireRundownProtection(&Thread->RundownProtect) )
{
do
{
v6 = Thread->CrossThreadFlags & 8;
v7 = v6 != 0;
v14 = v6 != 0;
v8 = v6 != 0;
Teb[1511] = v8;
Teb[1530] = 0;
WoW64Process = Process->WoW64Process;
if( WoW64Process )
{
Machine = WoW64Process->Machine;
if( Machine == 332 || Machine == 452 )
{
Teb[3047] = v8;
Teb[3057] = 0;
}
}
_InterlockedOr(v12, 0);
}
while( v7 != ((Thread->CrossThreadFlags & 8) != 0) );
if( Thread != CurrentThread )
ExReleaseRundownProtection(&Thread->RundownProtect);
}
if( v13 )
KiUnstackDetachProcess(&ApcState, 0i64);
}
return 0;
}Referenced by:
PsImpersonateClient
PsRestoreImpersonation