RtlpSysVolCheckOwnerAndSecurity
INT64 __fastcall RtlpSysVolCheckOwnerAndSecurity(VOID *Handle, _ACL *StandardAcl){
unsigned int v2;
VOID *PoolWithTag;
NTSTATUS DaclSecurityDescriptor;
void *v7;
unsigned int i;
NTSTATUS v9;
_BYTE *v10;
char v11;
UINT8 *v12;
int SelfRelativeSD;
unsigned int v15;
int v16;
UINT8 *v17;
UINT8 *v18;
int v19;
UINT8 *v20;
UINT64 Length;
PACL Dacl;
PVOID Ace;
PSID Owner;
__int16 Sid2;
int v26;
__int16 v27;
int v28;
int v29;
__int16 v30;
int v31;
__int16 v32;
int v33;
v2 = 0;
LODWORD(Length) = 0;
Owner = 0i64;
BYTE4(Length) = 0;
Ace = 0i64;
Dacl = 0i64;
if( NtQuerySecurityObject(Handle, 5ui64, 0i64, 0i64, &Length) != -1073741789 )
return 0i64;
PoolWithTag = ExAllocatePoolWithTag(PagedPool, (unsigned int)Length, 0x536C6F56ui64);
if( !PoolWithTag )
return 3221225626i64;
DaclSecurityDescriptor = NtQuerySecurityObject(Handle, 5ui64, PoolWithTag, (unsigned int)Length, &Length);
v7 = PoolWithTag;
if( DaclSecurityDescriptor < 0 )
goto LABEL_24;
DaclSecurityDescriptor = RtlGetDaclSecurityDescriptor(PoolWithTag, (UINT8 *)&Length + 4, &Dacl, (UINT8 *)&Length + 5);
v7 = PoolWithTag;
if( DaclSecurityDescriptor < 0 )
goto LABEL_24;
DaclSecurityDescriptor = RtlGetOwnerSecurityDescriptor(PoolWithTag, &Owner, (UINT8 *)&Length + 5);
if( DaclSecurityDescriptor < 0 )
{
v7 = PoolWithTag;
LABEL_24:
ExFreePoolWithTag(v7, 0);
return(unsigned int)DaclSecurityDescriptor;
}
v31 = 0;
v26 = 0;
v30 = 257;
v32 = 1280;
v33 = 18;
Sid2 = 513;
v27 = 1280;
v28 = 32;
v29 = 544;
if( Owner && RtlEqualSid(Owner, &Sid2) && BYTE4(Length) && Dacl )
{
for( i = 0; ; ++i )
{
v9 = RtlGetAce(Dacl, i, &Ace);
v10 = Ace;
if( v9 < 0 )
v10 = 0i64;
Ace = v10;
if( !v10 )
break;
if( !*v10 && RtlEqualSid(v10 + 8, &v30) )
{
v11 = v10[1];
if( (v11 & 1) == 0 || (v11 & 2) == 0 )
{
v10[1] = v11 | 3;
SelfRelativeSD = NtSetSecurityObject(Handle, 4ui64, PoolWithTag);
goto LABEL_26;
}
goto LABEL_18;
}
}
}
v15 = Length;
if( (unsigned int)RtlSelfRelativeToAbsoluteSD2(PoolWithTag, &Length) != -1073741789 )
goto LABEL_30;
v16 = Length;
v17 = (UINT8 *)ExAllocatePoolWithTag(PagedPool, (unsigned int)Length, 0x536C6F56ui64);
v18 = v17;
if( !v17 )
goto LABEL_37;
memmove(v17, (UINT8 *)PoolWithTag, v15);
ExFreePoolWithTag(PoolWithTag, 0);
LODWORD(Length) = v16;
PoolWithTag = v18;
v19 = RtlSelfRelativeToAbsoluteSD2(v18, &Length);
if( v19 >= 0 )
{
LABEL_30:
SelfRelativeSD = RtlSetOwnerSecurityDescriptor(PoolWithTag, &Sid2, 0);
if( SelfRelativeSD < 0
|| (SelfRelativeSD = RtlSetDaclSecurityDescriptor(PoolWithTag, 1u, StandardAcl, 0), SelfRelativeSD < 0)
|| (LODWORD(Length) = 0,
SelfRelativeSD = RtlMakeSelfRelativeSD(PoolWithTag, 0i64, &Length),
SelfRelativeSD != -1073741789) )
{
LABEL_26:
v2 = SelfRelativeSD;
LABEL_18:
v12 = (UINT8 *)PoolWithTag;
LABEL_19:
ExFreePoolWithTag(v12, 0);
return v2;
}
v20 = (UINT8 *)ExAllocatePoolWithTag(PagedPool, (unsigned int)Length, 0x536C6F56ui64);
v18 = v20;
if( v20 )
{
v19 = RtlMakeSelfRelativeSD(PoolWithTag, v20, &Length);
ExFreePoolWithTag(PoolWithTag, 0);
if( v19 >= 0 )
{
v2 = NtSetSecurityObject(Handle, 5ui64, v18);
v12 = v18;
goto LABEL_19;
}
goto LABEL_36;
}
LABEL_37:
v2 = -1073741670;
goto LABEL_18;
}
LABEL_36:
ExFreePoolWithTag(v18, 0);
return(unsigned int)v19;
}Referenced by:
RtlCreateSystemVolumeInformationFolder