/* * Process Hacker - * LSA account handle * * Copyright (C) 2009 wj32 * * This file is part of Process Hacker. * * Process Hacker is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation, either version 3 of the License, or * (at your option) any later version. * * Process Hacker is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with Process Hacker. If not, see . */ using System; using ProcessHacker.Native.Api; using ProcessHacker.Native.Security; namespace ProcessHacker.Native.Objects { /// /// Represents a handle to a LSA account. /// public sealed class LsaAccountHandle : LsaHandle { public static LsaAccountHandle Create(LsaAccountAccess access, LsaPolicyHandle policyHandle, Sid sid) { IntPtr handle; Win32.LsaCreateAccount( policyHandle, sid, access, out handle ).ThrowIf(); return new LsaAccountHandle(handle, true); } private LsaAccountHandle(IntPtr handle, bool owned) : base(handle, owned) { } /// /// Opens a LSA account. /// /// A handle to a LSA policy. /// The SID of the account to open. /// The desired access to the account. public LsaAccountHandle(LsaPolicyHandle policyHandle, Sid sid, LsaAccountAccess access) { IntPtr handle; Win32.LsaOpenAccount( policyHandle, sid, access, out handle ).ThrowIf(); this.Handle = handle; } public void AddPrivilege(Privilege privilege) { this.AddPrivileges(new PrivilegeSet { privilege }); } public void AddPrivileges(PrivilegeSet privileges) { using (MemoryAlloc privilegeSetMemory = privileges.ToMemory()) { Win32.LsaAddPrivilegesToAccount( this, privilegeSetMemory ).ThrowIf(); } } public PrivilegeSet Privileges { get { IntPtr privileges; Win32.LsaEnumeratePrivilegesOfAccount( this, out privileges ).ThrowIf(); using (LsaMemoryAlloc privilegesAlloc = new LsaMemoryAlloc(privileges)) { return new PrivilegeSet(privilegesAlloc); } } } public QuotaLimits Quotas { get { QuotaLimits quotas; Win32.LsaGetQuotasForAccount( this, out quotas ).ThrowIf(); return quotas; } } public SecuritySystemAccess SystemAccess { get { SecuritySystemAccess access; Win32.LsaGetSystemAccessAccount( this, out access ).ThrowIf(); return access; } } public void RemovePrivilege(Privilege privilege) { this.RemovePrivileges(new PrivilegeSet { privilege }); } public void RemovePrivileges() { Win32.LsaRemovePrivilegesFromAccount( this, true, IntPtr.Zero ).ThrowIf(); } public void RemovePrivileges(PrivilegeSet privileges) { using (MemoryAlloc privilegeSetMemory = privileges.ToMemory()) { Win32.LsaRemovePrivilegesFromAccount( this, false, privilegeSetMemory ).ThrowIf(); } } public void SetQuotas(QuotaLimits quotas) { Win32.LsaSetQuotasForAccount( this, ref quotas ).ThrowIf(); } public void SetSystemAccess(SecuritySystemAccess access) { Win32.LsaSetSystemAccessAccount( this, access ).ThrowIf(); } } }