mirror of
https://git.tartarus.org/simon/putty.git
synced 2025-03-21 22:28:37 -05:00

There's now a winsecur.[ch], which centralises helper functions using the Windows security stuff in advapi.h (currently just get_user_sid), and also centralises the run-time loading of those functions and checking they're all there. [originally from svn r10082]
82 lines
2.2 KiB
C
82 lines
2.2 KiB
C
/*
|
|
* Windows support module which deals with being a named-pipe client.
|
|
*/
|
|
|
|
#include <stdio.h>
|
|
#include <assert.h>
|
|
|
|
#define DEFINE_PLUG_METHOD_MACROS
|
|
#include "tree234.h"
|
|
#include "putty.h"
|
|
#include "network.h"
|
|
#include "proxy.h"
|
|
#include "ssh.h"
|
|
|
|
#if !defined NO_SECURITY
|
|
|
|
#include "winsecur.h"
|
|
|
|
Socket make_handle_socket(HANDLE send_H, HANDLE recv_H, Plug plug,
|
|
int overlapped);
|
|
|
|
Socket new_named_pipe_client(const char *pipename, Plug plug)
|
|
{
|
|
HANDLE pipehandle;
|
|
PSID usersid, pipeowner;
|
|
PSECURITY_DESCRIPTOR psd;
|
|
char *err;
|
|
Socket ret;
|
|
|
|
assert(strncmp(pipename, "\\\\.\\pipe\\", 9) == 0);
|
|
assert(strchr(pipename + 9, '\\') == NULL);
|
|
|
|
pipehandle = CreateFile(pipename, GENERIC_READ | GENERIC_WRITE, 0, NULL,
|
|
OPEN_EXISTING, FILE_FLAG_OVERLAPPED, NULL);
|
|
|
|
if (pipehandle == INVALID_HANDLE_VALUE) {
|
|
err = dupprintf("Unable to open named pipe '%s': %s",
|
|
pipename, win_strerror(GetLastError()));
|
|
ret = new_error_socket(err, plug);
|
|
sfree(err);
|
|
return ret;
|
|
}
|
|
|
|
if ((usersid = get_user_sid()) == NULL) {
|
|
CloseHandle(pipehandle);
|
|
err = dupprintf("Unable to get user SID");
|
|
ret = new_error_socket(err, plug);
|
|
sfree(err);
|
|
return ret;
|
|
}
|
|
|
|
if (GetSecurityInfo(pipehandle, SE_KERNEL_OBJECT,
|
|
OWNER_SECURITY_INFORMATION,
|
|
&pipeowner, NULL, NULL, NULL,
|
|
&psd) != ERROR_SUCCESS) {
|
|
err = dupprintf("Unable to get named pipe security information: %s",
|
|
win_strerror(GetLastError()));
|
|
ret = new_error_socket(err, plug);
|
|
sfree(err);
|
|
CloseHandle(pipehandle);
|
|
sfree(usersid);
|
|
return ret;
|
|
}
|
|
|
|
if (!EqualSid(pipeowner, usersid)) {
|
|
err = dupprintf("Owner of named pipe '%s' is not us", pipename);
|
|
ret = new_error_socket(err, plug);
|
|
sfree(err);
|
|
CloseHandle(pipehandle);
|
|
LocalFree(psd);
|
|
sfree(usersid);
|
|
return ret;
|
|
}
|
|
|
|
LocalFree(psd);
|
|
sfree(usersid);
|
|
|
|
return make_handle_socket(pipehandle, pipehandle, plug, TRUE);
|
|
}
|
|
|
|
#endif /* !defined NO_SECURITY */
|