签名文件和设备句柄

怎样根据设备名字得到驱动句柄......我不知道要驱动句柄要干什么...不过俩个函数就可以搞定

  

NTSTATUS 
IoGetDeviceObjectPointer(
IN PUNICODE_STRING ObjectName,----->>>>>设备名字
IN ACCESS_MASK DesiredAccess,
OUT PFILE_OBJECT *FileObject,
OUT PDEVICE_OBJECT *DeviceObject
);
 
NTSTATUS
ObOpenObjectByPointer(
IN PVOID Object,
IN ULONG HandleAttributes,
IN PACCESS_STATE PassedAccessState OPTIONAL,
IN ACCESS_MASK DesiredAccess,
IN POBJECT_TYPE ObjectType,
IN KPROCESSOR_MODE AccessMode,
OUT PHANDLE Handle------------------------>>>>>句柄
);

 

  数字签名...现在很多anti-rootkit都有用到..的确可以帮我们排除一些东西...找了段代码,贴出来

  
  
BOOL CheckFileTrust( LPCWSTR lpFileName )
{
     BOOL bRet = FALSE;
     WINTRUST_DATA wd = { 0 };
     WINTRUST_FILE_INFO wfi = { 0 };
     WINTRUST_CATALOG_INFO wci = { 0 };
     CATALOG_INFO ci = { 0 };

     HCATADMIN hCatAdmin = NULL;
     if ( !CryptCATAdminAcquireContext( &hCatAdmin, NULL, 0 ) )
     {
         return FALSE;
     }

     HANDLE hFile = CreateFileW( lpFileName, GENERIC_READ, FILE_SHARE_READ,
         NULL, OPEN_EXISTING, 0, NULL );
     if ( INVALID_HANDLE_VALUE == hFile )
     {
         CryptCATAdminReleaseContext( hCatAdmin, 0 );
         return FALSE;
     }

     DWORD dwCnt = 100;
     BYTE byHash[100];
     CryptCATAdminCalcHashFromFileHandle( hFile, &dwCnt, byHash, 0 );
     CloseHandle( hFile );

     LPWSTR pszMemberTag = new WCHAR[dwCnt * 2 + 1];
     for ( DWORD dw = 0; dw < dwCnt; ++dw )
     {
         wsprintfW( &pszMemberTag[dw * 2], L"%02X", byHash[dw] );
     }

     HCATINFO hCatInfo = CryptCATAdminEnumCatalogFromHash( hCatAdmin,
         byHash, dwCnt, 0, NULL );
     if ( NULL == hCatInfo )
     {
         wfi.cbStruct        = sizeof( WINTRUST_FILE_INFO );
         wfi.pcwszFilePath   = lpFileName;
         wfi.hFile           = NULL;
         wfi.pgKnownSubject = NULL;

         wd.cbStruct             = sizeof( WINTRUST_DATA );
         wd.dwUnionChoice        = WTD_CHOICE_FILE;
         wd.pFile                = &wfi;
         wd.dwUIChoice           = WTD_UI_NONE;
         wd.fdwRevocationChecks = WTD_REVOKE_NONE;
         wd.dwStateAction        = WTD_STATEACTION_IGNORE;
         wd.dwProvFlags          = WTD_SAFER_FLAG;
         wd.hWVTStateData        = NULL;
         wd.pwszURLReference     = NULL;
     }
     else
     {
         CryptCATCatalogInfoFromContext( hCatInfo, &ci, 0 );
         wci.cbStruct              = sizeof( WINTRUST_CATALOG_INFO );
         wci.pcwszCatalogFilePath = ci.wszCatalogFile;
         wci.pcwszMemberFilePath   = lpFileName;
         wci.pcwszMemberTag        = pszMemberTag;

         wd.cbStruct             = sizeof( WINTRUST_DATA );
         wd.dwUnionChoice        = WTD_CHOICE_CATALOG;
         wd.pCatalog             = &wci;
         wd.dwUIChoice           = WTD_UI_NONE;
         wd.fdwRevocationChecks = WTD_STATEACTION_VERIFY;
         wd.dwProvFlags          = 0;
         wd.hWVTStateData        = NULL;
         wd.pwszURLReference     = NULL;
     }
     GUID action = WINTRUST_ACTION_GENERIC_VERIFY_V2;
     HRESULT hr   = WinVerifyTrust( NULL, &action, &wd );
     bRet         = SUCCEEDED( hr );

     if ( NULL != hCatInfo )
     {
         CryptCATAdminReleaseCatalogContext( hCatAdmin, hCatInfo, 0 );
     }
     CryptCATAdminReleaseContext( hCatAdmin, 0 );
    delete[] pszMemberTag;
     return bRet;
}

 
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值