Windows Vista UAC: 如何创建低权限令牌

  
 
#include <sddl.h>
 
void CreateLowProcess()
{
  BOOL bRet ;
  HANDLE hToken ;
  HANDLE hNewToken ;
 
  // Notepad is used as an example
  WCHAR wszProcessName [ MAX_PATH ] =
     L"C://Windows//System32//Notepad.exe";
 
  // Low integrity SID
  WCHAR wszIntegritySid [20] = L"S-1-16-4096";
  PSID pIntegritySid = NULL ;
 
 TOKEN_MANDATORY_LABEL TIL = {0};
 PROCESS_INFORMATION ProcInfo = {0};
  STARTUPINFO StartupInfo = {0};
  ULONG ExitCode = 0;
 
  if ( OpenProcessToken ( GetCurrentProcess (), MAXIMUM_ALLOWED , & hToken ))
 {
    if ( DuplicateTokenEx ( hToken , MAXIMUM_ALLOWED , NULL ,
        SecurityImpersonation, TokenPrimary, & hNewToken ))
    {
      if ( ConvertStringSidToSid ( wszIntegritySid , & pIntegritySid ))
      {
        TIL . Label . Attributes = SE_GROUP_INTEGRITY ;
        TIL . Label . Sid = pIntegritySid ;
 
        // Set the process integrity level
        if ( SetTokenInformation ( hNewToken , TokenIntegrityLevel, & TIL ,
            sizeof (TOKEN_MANDATORY_LABEL) + GetLengthSid ( pIntegritySid )))
            {
              // Create the new process at Low integrity
              bRet = CreateProcessAsUser ( hNewToken , NULL ,
                       wszProcessName , NULL , NULL , FALSE ,
                       0, NULL , NULL , & StartupInfo , & ProcInfo );
            }
 
        LocalFree ( pIntegritySid );
      }
      CloseHandle ( hNewToken );
    }
  CloseHandle ( hToken );
 }
}
 
  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值