Something went wrong. Try again.
Reactos
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482/* * PROJECT: ReactOS Winlogon * LICENSE: GPL-2.0-or-later (https://spdx.org/licenses/GPL-2.0-or-later) * PURPOSE: Security utility infrastructure implementation of Winlogon * COPYRIGHT: Copyright 2022 George Bișoc <george.bisoc@reactos.org> */
/* INCLUDES *****************************************************************/
#include "winlogon.h"
/* DEFINES ******************************************************************/
#define DESKTOP_ALL (DESKTOP_READOBJECTS | DESKTOP_CREATEWINDOW | \ DESKTOP_CREATEMENU | DESKTOP_HOOKCONTROL | DESKTOP_JOURNALRECORD | \ DESKTOP_JOURNALPLAYBACK | DESKTOP_ENUMERATE | DESKTOP_WRITEOBJECTS | \ DESKTOP_SWITCHDESKTOP | STANDARD_RIGHTS_REQUIRED)
#define DESKTOP_ADMINS_LIMITED (DESKTOP_WRITEOBJECTS | DESKTOP_READOBJECTS | \ DESKTOP_CREATEWINDOW | DESKTOP_CREATEMENU | DESKTOP_ENUMERATE)
#define DESKTOP_INTERACTIVE_LIMITED (STANDARD_RIGHTS_READ | DESKTOP_ENUMERATE | \ DESKTOP_READOBJECTS | DESKTOP_CREATEWINDOW)
#define DESKTOP_WINLOGON_ADMINS_LIMITED (STANDARD_RIGHTS_REQUIRED | DESKTOP_ENUMERATE)
#define WINSTA_ALL (WINSTA_ENUMDESKTOPS | WINSTA_READATTRIBUTES | \ WINSTA_ACCESSCLIPBOARD | WINSTA_CREATEDESKTOP | \ WINSTA_WRITEATTRIBUTES | WINSTA_ACCESSGLOBALATOMS | \ WINSTA_EXITWINDOWS | WINSTA_ENUMERATE | WINSTA_READSCREEN | \ STANDARD_RIGHTS_REQUIRED)
#define WINSTA_ADMINS_LIMITED (WINSTA_READATTRIBUTES | WINSTA_ENUMERATE)
#define GENERIC_ACCESS (GENERIC_READ | GENERIC_WRITE | \ GENERIC_EXECUTE | GENERIC_ALL)
/* GLOBALS ******************************************************************/
static SID_IDENTIFIER_AUTHORITY NtAuthority = {SECURITY_NT_AUTHORITY};
/* FUNCTIONS ****************************************************************/
/** * @brief * Converts an absolute security descriptor to a self-relative * format. * * @param[in] AbsoluteSd * A pointer to an absolute security descriptor to be * converted. * * @return * Returns a pointer to a converted security descriptor in * self-relative format. If the function fails, NULL is returned * otherwise. * * @remarks * The function allocates the security descriptor buffer in memory * heap, the caller is entirely responsible for freeing such buffer * from when it's no longer needed. */PSECURITY_DESCRIPTORConvertToSelfRelative( _In_ PSECURITY_DESCRIPTOR AbsoluteSd){ PSECURITY_DESCRIPTOR RelativeSd; DWORD DescriptorLength = 0;
/* Determine the size for allocating our buffer */ if (MakeSelfRelativeSD(AbsoluteSd, NULL, &DescriptorLength) || (GetLastError() != ERROR_INSUFFICIENT_BUFFER)) { ERR("ConvertToSelfRelative(): error %lu, expected ERROR_INSUFFICIENT_BUFFER\n", GetLastError()); return NULL; }
/* Allocate the buffer now */ RelativeSd = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DescriptorLength); if (RelativeSd == NULL) { ERR("ConvertToSelfRelative(): Failed to allocate buffer for relative SD\n"); return NULL; }
/* Convert the security descriptor now */ if (!MakeSelfRelativeSD(AbsoluteSd, RelativeSd, &DescriptorLength)) { ERR("ConvertToSelfRelative(): Failed to convert the security descriptor to a self relative format (error %lu)\n", GetLastError()); RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); return NULL; }
return RelativeSd;}
/** * @brief * Creates a security descriptor for the default * window station upon its creation. * * @param[out] WinstaSd * A pointer to a created security descriptor for * the window station. * * @return * Returns TRUE if the function has successfully * created the security descriptor, FALSE otherwise. */BOOLCreateWinstaSecurity( _Out_ PSECURITY_DESCRIPTOR *WinstaSd){ BOOL Success = FALSE; SECURITY_DESCRIPTOR AbsoluteSd; PSECURITY_DESCRIPTOR RelativeSd = NULL; PSID WinlogonSid = NULL, AdminsSid = NULL, NetworkServiceSid = NULL; /* NetworkServiceSid is a HACK, see the comment below for information */ DWORD DaclSize; PACL Dacl;
/* Create the Winlogon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_LOCAL_SYSTEM_RID, 0, 0, 0, 0, 0, 0, 0, &WinlogonSid)) { ERR("CreateWinstaSecurity(): Failed to create the Winlogon SID (error code %lu)\n", GetLastError()); return FALSE; }
/* Create the admins SID */ if (!AllocateAndInitializeSid(&NtAuthority, 2, SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS, 0, 0, 0, 0, 0, 0, &AdminsSid)) { ERR("CreateWinstaSecurity(): Failed to create the admins SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Create the network service SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_NETWORK_SERVICE_RID, 0, 0, 0, 0, 0, 0, 0, &NetworkServiceSid)) { ERR("CreateWinstaSecurity(): Failed to create the network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* * Build up the DACL size. This includes a number * of four ACEs of two different SIDs. The first two * ACEs give both window station and generic access * to Winlogon, the last two give limited window station * and desktop access to admins. * * ===================== !!!MUST READ!!! ===================== * * HACK -- Include in the DACL two more ACEs for network * service SID. Network services will be granted full * access to the default window station. Whilst technically * services that are either network or local ones are part * and act on behalf of the system, what we are doing here * is a hack because of two reasons: * * 1) Winlogon does not allow default window station (Winsta0) * access to network services on Windows. As a matter of fact, * network services must access their own service window station * (aka Service-0x0-3e4$) which never gets created. Why it never * gets created is explained on the second point. * * 2) Our LSASS terribly lacks in code that handles special logon * service types, NetworkService and LocalService. For this reason * whenever an access token is created for a network service process * for example, its authentication ID (aka LogonId represented as a LUID) * is a uniquely generated ID by LSASS for this process. This is wrong * on so many levels, partly because a network service is not a regular * service and network services have their own special authentication logon * ID (with its respective LUID as {0x3e4, 0x0}). On top of that, a network * service process must have an impersonation token but for whatever reason * we are creating a primary access token instead. * * FOR ANYONE WHO'S INTERESTED ON FIXING THIS, DO NOT FORGET TO REMOVE THIS * HACK!!! * * =========================== !!!END!!! ================================ */ DaclSize = sizeof(ACL) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(NetworkServiceSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(NetworkServiceSid);
/* Allocate the DACL now */ Dacl = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DaclSize); if (Dacl == NULL) { ERR("CreateWinstaSecurity(): Failed to allocate memory buffer for DACL!\n"); goto Quit; }
/* Initialize it */ if (!InitializeAcl(Dacl, DaclSize, ACL_REVISION)) { ERR("CreateWinstaSecurity(): Failed to initialize DACL (error code %lu)\n", GetLastError()); goto Quit; }
/* First ACE -- give full winsta access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ALL, WinlogonSid)) { ERR("CreateWinstaSecurity(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Second ACE -- give full generic access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, GENERIC_ACCESS, WinlogonSid)) { ERR("CreateWinstaSecurity(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Third ACE -- give limited winsta access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ADMINS_LIMITED, AdminsSid)) { ERR("CreateWinstaSecurity(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* Fourth ACE -- give limited desktop access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, DESKTOP_ADMINS_LIMITED, AdminsSid)) { ERR("CreateWinstaSecurity(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Fifth ACE -- give full access to network services */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ALL, NetworkServiceSid)) { ERR("CreateWinstaSecurity(): Failed to set ACE for network service (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Sixth ACE -- give full generic access to network services */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, GENERIC_ACCESS, NetworkServiceSid)) { ERR("CreateWinstaSecurity(): Failed to set ACE for network service (error code %lu)\n", GetLastError()); goto Quit; }
/* Initialize the security descriptor */ if (!InitializeSecurityDescriptor(&AbsoluteSd, SECURITY_DESCRIPTOR_REVISION)) { ERR("CreateWinstaSecurity(): Failed to initialize absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Set the DACL to the descriptor */ if (!SetSecurityDescriptorDacl(&AbsoluteSd, TRUE, Dacl, FALSE)) { ERR("CreateWinstaSecurity(): Failed to set up DACL to absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Convert it to self-relative format */ RelativeSd = ConvertToSelfRelative(&AbsoluteSd); if (RelativeSd == NULL) { ERR("CreateWinstaSecurity(): Failed to convert security descriptor to self relative format!\n"); goto Quit; }
/* Give the descriptor to the caller */ *WinstaSd = RelativeSd; Success = TRUE;
Quit: if (WinlogonSid != NULL) { FreeSid(WinlogonSid); }
if (AdminsSid != NULL) { FreeSid(AdminsSid); }
/* HACK */ if (NetworkServiceSid != NULL) { FreeSid(NetworkServiceSid); } /* END HACK */
if (Dacl != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, Dacl); }
if (Success == FALSE) { if (RelativeSd != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); } }
return Success;}
/** * @brief * Creates a security descriptor for the default * application desktop upon its creation. * * @param[out] ApplicationDesktopSd * A pointer to a created security descriptor for * the application desktop. * * @return * Returns TRUE if the function has successfully * created the security descriptor, FALSE otherwise. */BOOLCreateApplicationDesktopSecurity( _Out_ PSECURITY_DESCRIPTOR *ApplicationDesktopSd){ BOOL Success = FALSE; SECURITY_DESCRIPTOR AbsoluteSd; PSECURITY_DESCRIPTOR RelativeSd = NULL; PSID WinlogonSid = NULL, AdminsSid = NULL, NetworkServiceSid = NULL; /* NetworkServiceSid is a HACK, see the comment in CreateWinstaSecurity for information */ DWORD DaclSize; PACL Dacl;
/* Create the Winlogon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_LOCAL_SYSTEM_RID, 0, 0, 0, 0, 0, 0, 0, &WinlogonSid)) { ERR("CreateApplicationDesktopSecurity(): Failed to create the Winlogon SID (error code %lu)\n", GetLastError()); return FALSE; }
/* Create the admins SID */ if (!AllocateAndInitializeSid(&NtAuthority, 2, SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS, 0, 0, 0, 0, 0, 0, &AdminsSid)) { ERR("CreateApplicationDesktopSecurity(): Failed to create the admins SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Create the network service SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_NETWORK_SERVICE_RID, 0, 0, 0, 0, 0, 0, 0, &NetworkServiceSid)) { ERR("CreateApplicationDesktopSecurity(): Failed to create the network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* * Build up the DACL size. This includes a number * of two ACEs of two different SIDs. The first ACE * gives full access to Winlogon, the last one gives * limited desktop access to admins. */ DaclSize = sizeof(ACL) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(NetworkServiceSid); /* HACK */
/* Allocate the DACL now */ Dacl = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DaclSize); if (Dacl == NULL) { ERR("CreateApplicationDesktopSecurity(): Failed to allocate memory buffer for DACL!\n"); goto Quit; }
/* Initialize it */ if (!InitializeAcl(Dacl, DaclSize, ACL_REVISION)) { ERR("CreateApplicationDesktopSecurity(): Failed to initialize DACL (error code %lu)\n", GetLastError()); goto Quit; }
/* First ACE -- Give full desktop power to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, WinlogonSid)) { ERR("CreateApplicationDesktopSecurity(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Second ACE -- Give limited desktop power to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ADMINS_LIMITED, AdminsSid)) { ERR("CreateApplicationDesktopSecurity(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Third ACE -- Give full desktop power to network services */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, NetworkServiceSid)) { ERR("CreateApplicationDesktopSecurity(): Failed to set ACE for network services (error code %lu)\n", GetLastError()); goto Quit; }
/* Initialize the security descriptor */ if (!InitializeSecurityDescriptor(&AbsoluteSd, SECURITY_DESCRIPTOR_REVISION)) { ERR("CreateApplicationDesktopSecurity(): Failed to initialize absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Set the DACL to the descriptor */ if (!SetSecurityDescriptorDacl(&AbsoluteSd, TRUE, Dacl, FALSE)) { ERR("CreateApplicationDesktopSecurity(): Failed to set up DACL to absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Conver it to self-relative format */ RelativeSd = ConvertToSelfRelative(&AbsoluteSd); if (RelativeSd == NULL) { ERR("CreateApplicationDesktopSecurity(): Failed to convert security descriptor to self relative format!\n"); goto Quit; }
/* Give the descriptor to the caller */ *ApplicationDesktopSd = RelativeSd; Success = TRUE;
Quit: if (WinlogonSid != NULL) { FreeSid(WinlogonSid); }
if (AdminsSid != NULL) { FreeSid(AdminsSid); }
/* HACK */ if (NetworkServiceSid != NULL) { FreeSid(NetworkServiceSid); } /* END HACK */
if (Dacl != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, Dacl); }
if (Success == FALSE) { if (RelativeSd != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); } }
return Success;}
/** * @brief * Creates a security descriptor for the default * Winlogon desktop. This descriptor serves as a * security measure for the winlogon desktop so * that only Winlogon itself (and admins) can * interact with it. * * @param[out] WinlogonDesktopSd * A pointer to a created security descriptor for * the Winlogon desktop. * * @return * Returns TRUE if the function has successfully * created the security descriptor, FALSE otherwise. */BOOLCreateWinlogonDesktopSecurity( _Out_ PSECURITY_DESCRIPTOR *WinlogonDesktopSd){ BOOL Success = FALSE; SECURITY_DESCRIPTOR AbsoluteSd; PSECURITY_DESCRIPTOR RelativeSd = NULL; PSID WinlogonSid = NULL, AdminsSid = NULL; DWORD DaclSize; PACL Dacl;
/* Create the Winlogon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_LOCAL_SYSTEM_RID, 0, 0, 0, 0, 0, 0, 0, &WinlogonSid)) { ERR("CreateWinlogonDesktopSecurity(): Failed to create the Winlogon SID (error code %lu)\n", GetLastError()); return FALSE; }
/* Create the admins SID */ if (!AllocateAndInitializeSid(&NtAuthority, 2, SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS, 0, 0, 0, 0, 0, 0, &AdminsSid)) { ERR("CreateWinlogonDesktopSecurity(): Failed to create the admins SID (error code %lu)\n", GetLastError()); goto Quit; }
/* * Build up the DACL size. This includes a number * of two ACEs of two different SIDs. The first ACE * gives full access to Winlogon, the last one gives * limited desktop access to admins. */ DaclSize = sizeof(ACL) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid);
/* Allocate the DACL now */ Dacl = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DaclSize); if (Dacl == NULL) { ERR("CreateWinlogonDesktopSecurity(): Failed to allocate memory buffer for DACL!\n"); goto Quit; }
/* Initialize it */ if (!InitializeAcl(Dacl, DaclSize, ACL_REVISION)) { ERR("CreateWinlogonDesktopSecurity(): Failed to initialize DACL (error code %lu)\n", GetLastError()); goto Quit; }
/* First ACE -- Give full desktop access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, WinlogonSid)) { ERR("CreateWinlogonDesktopSecurity(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Second ACE -- Give limited desktop access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_WINLOGON_ADMINS_LIMITED, AdminsSid)) { ERR("CreateWinlogonDesktopSecurity(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* Initialize the security descriptor */ if (!InitializeSecurityDescriptor(&AbsoluteSd, SECURITY_DESCRIPTOR_REVISION)) { ERR("CreateWinlogonDesktopSecurity(): Failed to initialize absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Set the DACL to the descriptor */ if (!SetSecurityDescriptorDacl(&AbsoluteSd, TRUE, Dacl, FALSE)) { ERR("CreateWinlogonDesktopSecurity(): Failed to set up DACL to absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Conver it to self-relative format */ RelativeSd = ConvertToSelfRelative(&AbsoluteSd); if (RelativeSd == NULL) { ERR("CreateWinlogonDesktopSecurity(): Failed to convert security descriptor to self relative format!\n"); goto Quit; }
/* Give the descriptor to the caller */ *WinlogonDesktopSd = RelativeSd; Success = TRUE;
Quit: if (WinlogonSid != NULL) { FreeSid(WinlogonSid); }
if (AdminsSid != NULL) { FreeSid(AdminsSid); }
if (Dacl != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, Dacl); }
if (Success == FALSE) { if (RelativeSd != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); } }
return Success;}
/** * @brief * Creates a security descriptor for the screen * saver desktop. * * @param[out] ScreenSaverDesktopSd * A pointer to a created security descriptor for * the screen-saver desktop. * * @return * Returns TRUE if the function has successfully * created the security descriptor, FALSE otherwise. */BOOLCreateScreenSaverSecurity( _Out_ PSECURITY_DESCRIPTOR *ScreenSaverDesktopSd){ BOOL Success = FALSE; SECURITY_DESCRIPTOR AbsoluteSd; PSECURITY_DESCRIPTOR RelativeSd = NULL; PSID WinlogonSid = NULL, AdminsSid = NULL, InteractiveSid = NULL; DWORD DaclSize; PACL Dacl;
/* Create the Winlogon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_LOCAL_SYSTEM_RID, 0, 0, 0, 0, 0, 0, 0, &WinlogonSid)) { ERR("CreateScreenSaverSecurity(): Failed to create the Winlogon SID (error code %lu)\n", GetLastError()); return FALSE; }
/* Create the admins SID */ if (!AllocateAndInitializeSid(&NtAuthority, 2, SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS, 0, 0, 0, 0, 0, 0, &AdminsSid)) { ERR("CreateScreenSaverSecurity(): Failed to create the admins SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Create the interactive logon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_INTERACTIVE_RID, 0, 0, 0, 0, 0, 0, 0, &InteractiveSid)) { ERR("CreateScreenSaverSecurity(): Failed to create the interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* * Build up the DACL size. This includes a number * of three ACEs of three different SIDs. The first ACE * gives full access to Winlogon, the second one gives * limited desktop access to admins and the last one * gives full desktop access to users who have logged in * interactively. */ DaclSize = sizeof(ACL) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(InteractiveSid);
/* Allocate the DACL now */ Dacl = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DaclSize); if (Dacl == NULL) { ERR("CreateScreenSaverSecurity(): Failed to allocate memory buffer for DACL!\n"); goto Quit; }
/* Initialize it */ if (!InitializeAcl(Dacl, DaclSize, ACL_REVISION)) { ERR("CreateScreenSaverSecurity(): Failed to initialize DACL (error code %lu)\n", GetLastError()); goto Quit; }
/* First ACE -- Give full desktop access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, WinlogonSid)) { ERR("CreateScreenSaverSecurity(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Second ACE -- Give limited desktop access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, DESKTOP_ADMINS_LIMITED, AdminsSid)) { ERR("CreateScreenSaverSecurity(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* Third ACE -- Give full desktop access to interactive logon users */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, DESKTOP_INTERACTIVE_LIMITED, InteractiveSid)) { ERR("CreateScreenSaverSecurity(): Failed to set ACE for interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Initialize the security descriptor */ if (!InitializeSecurityDescriptor(&AbsoluteSd, SECURITY_DESCRIPTOR_REVISION)) { ERR("CreateScreenSaverSecurity(): Failed to initialize absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Set the DACL to the descriptor */ if (!SetSecurityDescriptorDacl(&AbsoluteSd, TRUE, Dacl, FALSE)) { ERR("CreateScreenSaverSecurity(): Failed to set up DACL to absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Conver it to self-relative format */ RelativeSd = ConvertToSelfRelative(&AbsoluteSd); if (RelativeSd == NULL) { ERR("CreateScreenSaverSecurity(): Failed to convert security descriptor to self relative format!\n"); goto Quit; }
/* Give the descriptor to the caller */ *ScreenSaverDesktopSd = RelativeSd; Success = TRUE;
Quit: if (WinlogonSid != NULL) { FreeSid(WinlogonSid); }
if (AdminsSid != NULL) { FreeSid(AdminsSid); }
if (InteractiveSid != NULL) { FreeSid(InteractiveSid); }
if (Dacl != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, Dacl); }
if (Success == FALSE) { if (RelativeSd != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); } }
return Success;}
/** * @brief * Assigns access to the specific logon user to * the default window station. Such access is * given to the user when it has logged in. * * @param[in] WinSta * A handle to a window station where the * user is given access to it. * * @param[in] LogonSid * A pointer to a logon SID that represents * the logged in user in question. * * @return * Returns TRUE if the function has successfully * assigned access to the user, FALSE otherwise. */BOOLAllowWinstaAccessToUser( _In_ HWINSTA WinSta, _In_ PSID LogonSid){ BOOL Success = FALSE; SECURITY_DESCRIPTOR AbsoluteSd; PSECURITY_DESCRIPTOR RelativeSd = NULL; PSID WinlogonSid = NULL, AdminsSid = NULL, InteractiveSid = NULL, NetworkServiceSid = NULL; /* NetworkServiceSid is a HACK, see the comment in CreateWinstaSecurity for information */ SECURITY_INFORMATION SecurityInformation; DWORD DaclSize; PACL Dacl;
/* Create the Winlogon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_LOCAL_SYSTEM_RID, 0, 0, 0, 0, 0, 0, 0, &WinlogonSid)) { ERR("AllowWinstaAccessToUser(): Failed to create the Winlogon SID (error code %lu)\n", GetLastError()); return FALSE; }
/* Create the admins SID */ if (!AllocateAndInitializeSid(&NtAuthority, 2, SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS, 0, 0, 0, 0, 0, 0, &AdminsSid)) { ERR("AllowWinstaAccessToUser(): Failed to create the admins SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Create the interactive logon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_INTERACTIVE_RID, 0, 0, 0, 0, 0, 0, 0, &InteractiveSid)) { ERR("AllowWinstaAccessToUser(): Failed to create the interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Create the network service SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_NETWORK_SERVICE_RID, 0, 0, 0, 0, 0, 0, 0, &NetworkServiceSid)) { ERR("AllowWinstaAccessToUser(): Failed to create the network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* * Build up the DACL size. This includes a number * of eight ACEs of four different SIDs. The first ACE * gives full winsta access to Winlogon, the second one gives * generic access to Winlogon. Such approach is the same * for both interactive logon users and logon user as well. * Only admins are given limited powers. */ DaclSize = sizeof(ACL) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(InteractiveSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(InteractiveSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(LogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(LogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(NetworkServiceSid) + /* HACK */ sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(NetworkServiceSid);
/* Allocate the DACL now */ Dacl = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DaclSize); if (Dacl == NULL) { ERR("AllowWinstaAccessToUser(): Failed to allocate memory buffer for DACL!\n"); goto Quit; }
/* Initialize it */ if (!InitializeAcl(Dacl, DaclSize, ACL_REVISION)) { ERR("AllowWinstaAccessToUser(): Failed to initialize DACL (error code %lu)\n", GetLastError()); goto Quit; }
/* First ACE -- Give full winsta access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ALL, WinlogonSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Second ACE -- Give generic access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, GENERIC_ACCESS, WinlogonSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Third ACE -- Give limited winsta access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ADMINS_LIMITED, AdminsSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* Fourth ACE -- Give limited desktop access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, DESKTOP_ADMINS_LIMITED, AdminsSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* Fifth ACE -- Give full winsta access to interactive logon users */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ALL, InteractiveSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Sixth ACE -- Give generic access to interactive logon users */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, GENERIC_ACCESS, InteractiveSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Seventh ACE -- Give full winsta access to logon user */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ALL, LogonSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for logon user SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Eighth ACE -- Give generic access to logon user */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, GENERIC_ACCESS, LogonSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for logon user SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK : Ninenth ACE -- Give full winsta access to network services */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, NO_PROPAGATE_INHERIT_ACE, WINSTA_ALL, NetworkServiceSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for logon network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Tenth ACE -- Give generic access to network services */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, INHERIT_ONLY_ACE | OBJECT_INHERIT_ACE | CONTAINER_INHERIT_ACE, GENERIC_ACCESS, NetworkServiceSid)) { ERR("AllowWinstaAccessToUser(): Failed to set ACE for network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Initialize the security descriptor */ if (!InitializeSecurityDescriptor(&AbsoluteSd, SECURITY_DESCRIPTOR_REVISION)) { ERR("AllowWinstaAccessToUser(): Failed to initialize absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Set the DACL to descriptor */ if (!SetSecurityDescriptorDacl(&AbsoluteSd, TRUE, Dacl, FALSE)) { ERR("AllowWinstaAccessToUser(): Failed to set up DACL to absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Convert it to self-relative format */ RelativeSd = ConvertToSelfRelative(&AbsoluteSd); if (RelativeSd == NULL) { ERR("AllowWinstaAccessToUser(): Failed to convert security descriptor to self relative format!\n"); goto Quit; }
/* Set new winsta security based on this descriptor */ SecurityInformation = DACL_SECURITY_INFORMATION; if (!SetUserObjectSecurity(WinSta, &SecurityInformation, RelativeSd)) { ERR("AllowWinstaAccessToUser(): Failed to set window station security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
Success = TRUE;
Quit: if (WinlogonSid != NULL) { FreeSid(WinlogonSid); }
if (AdminsSid != NULL) { FreeSid(AdminsSid); }
if (InteractiveSid != NULL) { FreeSid(InteractiveSid); }
/* HACK */ if (NetworkServiceSid != NULL) { FreeSid(NetworkServiceSid); } /* END HACK */
if (Dacl != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, Dacl); }
if (RelativeSd != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); }
return Success;}
/** * @brief * Assigns access to the specific logon user to * the default desktop. Such access is given to * the user when it has logged in. * * @param[in] Desktop * A handle to a desktop where the user * is given access to it. * * @param[in] LogonSid * A pointer to a logon SID that represents * the logged in user in question. * * @return * Returns TRUE if the function has successfully * assigned access to the user, FALSE otherwise. */BOOLAllowDesktopAccessToUser( _In_ HDESK Desktop, _In_ PSID LogonSid){ BOOL Success = FALSE; SECURITY_DESCRIPTOR AbsoluteSd; PSECURITY_DESCRIPTOR RelativeSd = NULL; PSID WinlogonSid = NULL, AdminsSid = NULL, InteractiveSid = NULL, NetworkServiceSid = NULL; /* NetworkServiceSid is a HACK, see the comment in CreateWinstaSecurity for information */ SECURITY_INFORMATION SecurityInformation; DWORD DaclSize; PACL Dacl;
/* Create the Winlogon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_LOCAL_SYSTEM_RID, 0, 0, 0, 0, 0, 0, 0, &WinlogonSid)) { ERR("AllowDesktopAccessToUser(): Failed to create the Winlogon SID (error code %lu)\n", GetLastError()); return FALSE; }
/* Create the admins SID */ if (!AllocateAndInitializeSid(&NtAuthority, 2, SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS, 0, 0, 0, 0, 0, 0, &AdminsSid)) { ERR("AllowDesktopAccessToUser(): Failed to create the admins SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Create the interactive logon SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_INTERACTIVE_RID, 0, 0, 0, 0, 0, 0, 0, &InteractiveSid)) { ERR("AllowDesktopAccessToUser(): Failed to create the interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Create the network service SID */ if (!AllocateAndInitializeSid(&NtAuthority, 1, SECURITY_NETWORK_SERVICE_RID, 0, 0, 0, 0, 0, 0, 0, &NetworkServiceSid)) { ERR("AllowDesktopAccessToUser(): Failed to create the network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* * Build up the DACL size. This includes a number * of four ACEs of four different SIDs. The first ACE * gives full desktop access to Winlogon, the second one gives * generic limited desktop access to admins. The last two give * full power to both interactive logon users and logon user as * well. */ DaclSize = sizeof(ACL) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(WinlogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(AdminsSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(InteractiveSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(LogonSid) + sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD) + GetLengthSid(NetworkServiceSid); /* HACK */
/* Allocate the DACL now */ Dacl = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, DaclSize); if (Dacl == NULL) { ERR("AllowDesktopAccessToUser(): Failed to allocate memory buffer for DACL!\n"); goto Quit; }
/* Initialize it */ if (!InitializeAcl(Dacl, DaclSize, ACL_REVISION)) { ERR("AllowDesktopAccessToUser(): Failed to initialize DACL (error code %lu)\n", GetLastError()); goto Quit; }
/* First ACE -- Give full desktop access to Winlogon */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, WinlogonSid)) { ERR("AllowDesktopAccessToUser(): Failed to set ACE for Winlogon (error code %lu)\n", GetLastError()); goto Quit; }
/* Second ACE -- Give limited desktop access to admins */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ADMINS_LIMITED, AdminsSid)) { ERR("AllowDesktopAccessToUser(): Failed to set ACE for admins (error code %lu)\n", GetLastError()); goto Quit; }
/* Third ACE -- Give full desktop access to interactive logon users */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, InteractiveSid)) { ERR("AllowDesktopAccessToUser(): Failed to set ACE for interactive SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Fourth ACE -- Give full desktop access to logon user */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, LogonSid)) { ERR("AllowDesktopAccessToUser(): Failed to set ACE for logon user SID (error code %lu)\n", GetLastError()); goto Quit; }
/* HACK: Fifth ACE -- Give full desktop to network services */ if (!AddAccessAllowedAceEx(Dacl, ACL_REVISION, 0, DESKTOP_ALL, NetworkServiceSid)) { ERR("AllowDesktopAccessToUser(): Failed to set ACE for network service SID (error code %lu)\n", GetLastError()); goto Quit; }
/* Initialize the security descriptor */ if (!InitializeSecurityDescriptor(&AbsoluteSd, SECURITY_DESCRIPTOR_REVISION)) { ERR("AllowDesktopAccessToUser(): Failed to initialize absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Set the DACL to the descriptor */ if (!SetSecurityDescriptorDacl(&AbsoluteSd, TRUE, Dacl, FALSE)) { ERR("AllowDesktopAccessToUser(): Failed to set up DACL to absolute security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
/* Conver it to self-relative format */ RelativeSd = ConvertToSelfRelative(&AbsoluteSd); if (RelativeSd == NULL) { ERR("AllowDesktopAccessToUser(): Failed to convert security descriptor to self relative format!\n"); goto Quit; }
/* Assign new security to desktop based on this descriptor */ SecurityInformation = DACL_SECURITY_INFORMATION; if (!SetUserObjectSecurity(Desktop, &SecurityInformation, RelativeSd)) { ERR("AllowDesktopAccessToUser(): Failed to set desktop security descriptor (error code %lu)\n", GetLastError()); goto Quit; }
Success = TRUE;
Quit: if (WinlogonSid != NULL) { FreeSid(WinlogonSid); }
if (AdminsSid != NULL) { FreeSid(AdminsSid); }
if (InteractiveSid != NULL) { FreeSid(InteractiveSid); }
/* HACK */ if (NetworkServiceSid != NULL) { FreeSid(NetworkServiceSid); } /* END HACK */
if (Dacl != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, Dacl); }
if (RelativeSd != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, RelativeSd); }
return Success;}
/** * @brief * Assigns both window station and desktop access * to the specific session currently active on the * system. * * @param[in] Session * A pointer to an active session. * * @return * Returns TRUE if the function has successfully * assigned access to the current session, FALSE otherwise. */BOOLAllowAccessOnSession( _In_ PWLSESSION Session){ BOOL Success = FALSE; DWORD Index, SidLength, GroupsLength = 0; PTOKEN_GROUPS TokenGroup = NULL; PSID LogonSid;
/* Get required buffer size and allocate the TOKEN_GROUPS buffer */ if (!GetTokenInformation(Session->UserToken, TokenGroups, TokenGroup, 0, &GroupsLength)) { if (GetLastError() != ERROR_INSUFFICIENT_BUFFER) { ERR("AllowAccessOnSession(): Unexpected error code returned, must be ERROR_INSUFFICIENT_BUFFER (error code %lu)\n", GetLastError()); return FALSE; }
TokenGroup = RtlAllocateHeap(RtlGetProcessHeap(), HEAP_ZERO_MEMORY, GroupsLength); if (TokenGroup == NULL) { ERR("AllowAccessOnSession(): Failed to allocate memory buffer for token group!\n"); return FALSE; } }
/* Get the token group information from the access token */ if (!GetTokenInformation(Session->UserToken, TokenGroups, TokenGroup, GroupsLength, &GroupsLength)) { ERR("AllowAccessOnSession(): Failed to retrieve the token group information (error code %lu)\n", GetLastError()); goto Quit; }
/* Loop through the groups to find the logon SID */ for (Index = 0; Index < TokenGroup->GroupCount; Index++) { if ((TokenGroup->Groups[Index].Attributes & SE_GROUP_LOGON_ID) == SE_GROUP_LOGON_ID) { LogonSid = TokenGroup->Groups[Index].Sid; break; } }
/* Allow window station access to this user within this session */ if (!AllowWinstaAccessToUser(Session->InteractiveWindowStation, LogonSid)) { ERR("AllowAccessOnSession(): Failed to allow winsta access to the logon user!\n"); goto Quit; }
/* Allow application desktop access to this user within this session */ if (!AllowDesktopAccessToUser(Session->ApplicationDesktop, LogonSid)) { ERR("AllowAccessOnSession(): Failed to allow application desktop access to the logon user!\n"); goto Quit; }
/* Get the length of this logon SID */ SidLength = GetLengthSid(LogonSid);
/* Assign the window station to this logged in user */ if (!SetWindowStationUser(Session->InteractiveWindowStation, &Session->LogonId, LogonSid, SidLength)) { ERR("AllowAccessOnSession(): Failed to assign the window station to the logon user!\n"); goto Quit; }
Success = TRUE;
Quit: if (TokenGroup != NULL) { RtlFreeHeap(RtlGetProcessHeap(), 0, TokenGroup); }
return Success;}
/* EOF */