SepVerifyDesktopAppxPackageName
INT64 __fastcall SepVerifyDesktopAppxPackageName(_TOKEN *Token, VOID *SecurityDescriptor, UINT8 *PackageNameVerified){
int v5;
UNICODE_STRING *v7;
__int128 *PoolWithTag;
INT64 v9;
_DWORD *v10;
_DWORD *v11;
__int16 v12;
__int64 v13;
ACL *v14;
__int64 v15;
__int64 v16;
int v18;
UINT64 BufferLength;
UINT64 BufferLengtha;
SIZE_T NumberOfBytes;
int v22;
int v23;
struct _UNICODE_STRING DestinationString;
__int128 P[32];
v23 = 2;
v22 = 0;
NumberOfBytes = 0i64;
*PackageNameVerified = 0;
v5 = 0;
DestinationString = 0i64;
RtlInitUnicodeString(&DestinationString, L"WIN:
if( !SeSecurityAttributePresent(Token, &DestinationString, v7) )
return(unsigned int)v5;
LODWORD(BufferLength) = 512;
PoolWithTag = P;
v5 = SeQuerySecurityAttributesToken(Token, &DestinationString, 1ui64, P, BufferLength, &NumberOfBytes);
if( v5 == -1073741789 )
{
v18 = NumberOfBytes;
PoolWithTag = (__int128 *)ExAllocatePoolWithTag(PagedPool, (unsigned int)NumberOfBytes, 0x20206553ui64);
if( !PoolWithTag )
return(unsigned int)-1073741801;
LODWORD(BufferLengtha) = v18;
v5 = SeQuerySecurityAttributesToken(Token, &DestinationString, 1ui64, PoolWithTag, BufferLengtha, &NumberOfBytes);
}
if( v5 < 0 )
goto LABEL_16;
if( !PoolWithTag )
return(unsigned int)-1073739509;
AuthzBasepAllocateSecurityAttributesList(v9);
v11 = v10;
if( !v10 )
{
v5 = -1073741670;
goto LABEL_16;
}
v5 = AuthzBasepSetSecurityAttributesToken(v10, &v23, (__int64)PoolWithTag);
if( v5 < 0 )
goto LABEL_15;
do
{
v12 = *((_WORD *)SecurityDescriptor + 1);
if( (v12 & 4) == 0 )
goto LABEL_27;
if( v12 >= 0 )
{
v14 = (ACL *)*((_QWORD *)SecurityDescriptor + 4);
goto LABEL_11;
}
v13 = *((unsigned int *)SecurityDescriptor + 4);
if( (_DWORD)v13 )
v14 = (ACL *)((char *)SecurityDescriptor + v13);
else
LABEL_27:
v14 = 0i64;
LABEL_11:
LODWORD(v15) = RtlFindAceByType(v14, 9ui64, (SIZE_T *)((char *)&NumberOfBytes + 4));
v16 = v15;
if( v15 )
{
v5 = AuthzBasepEvaluateAceCondition(
(__int64)Token,
(__int64)v11,
0i64,
0i64,
0i64,
0i64,
0i64,
(char *)(v15 + 4 * (unsigned int)*(unsigned __int8 *)(v15 + 9) + 8 + 8i64),
*(unsigned __int16 *)(v15 + 2) - (4 * (unsigned int)*(unsigned __int8 *)(v15 + 9) + 8) - 8,
0,
0,
&v22);
if( v5 < 0 )
break;
if( v22 == 1 )
goto LABEL_14;
}
++HIDWORD(NumberOfBytes);
}
while( v16 );
if( v22 == 1 )
LABEL_14:
*PackageNameVerified = 1;
LABEL_15:
AuthzBasepFreeSecurityAttributesList(v11);
LABEL_16:
if( PoolWithTag && PoolWithTag != P )
ExFreePoolWithTag(PoolWithTag, 0);
return(unsigned int)v5;
}Referenced by:
SepVerifyDesktopAppxImage