1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
|
/* Copyright (C) 2002-2005 RealVNC Ltd. All Rights Reserved.
*
* This is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This software is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this software; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307,
* USA.
*/
// -=- Currentuser.cxx
#ifdef HAVE_CONFIG_H
#include <config.h>
#endif
#include <stdlib.h>
#include <rfb/LogWriter.h>
#include <rfb_win32/CurrentUser.h>
#include <rfb_win32/Service.h>
#include <lmcons.h>
#include <wtsapi32.h>
using namespace rfb;
using namespace win32;
static LogWriter vlog("CurrentUser");
const char* shellIconClass = "Shell_TrayWnd";
BOOL CALLBACK enumWindows(HWND hwnd, LPARAM lParam) {
char className[16];
if (GetClassName(hwnd, className, sizeof(className)) &&
(strcmp(className, shellIconClass) == 0)) {
vlog.debug("located tray icon window (%s)", className);
DWORD processId = 0;
GetWindowThreadProcessId(hwnd, &processId);
if (!processId)
return TRUE;
Handle process = OpenProcess(MAXIMUM_ALLOWED, FALSE, processId);
if (!process.h)
return TRUE;
if (!OpenProcessToken(process, MAXIMUM_ALLOWED, (HANDLE*)lParam))
return TRUE;
vlog.debug("obtained user token");
return FALSE;
}
return TRUE;
}
BOOL CALLBACK enumDesktops(LPTSTR lpszDesktop, LPARAM lParam) {
HDESK desktop = OpenDesktop(lpszDesktop, 0, FALSE, DESKTOP_ENUMERATE);
vlog.debug("opening \"%s\"", lpszDesktop);
if (!desktop) {
vlog.info("desktop \"%s\" inaccessible", lpszDesktop);
return TRUE;
}
BOOL result = EnumDesktopWindows(desktop, enumWindows, lParam);
if (!CloseDesktop(desktop))
vlog.info("unable to close desktop: %ld", GetLastError());
return result;
}
CurrentUserToken::CurrentUserToken() {
if (isServiceProcess()) {
// Try to get the user token using the Terminal Services APIs
WTSQueryUserToken(-1, &h);
} else {
// Try to open the security token for the User-Mode process
if (!OpenProcessToken(GetCurrentProcess(), GENERIC_ALL, &h)) {
DWORD err = GetLastError();
if (err != ERROR_CALL_NOT_IMPLEMENTED)
throw rdr::Win32Exception("OpenProcessToken failed", err);
h = INVALID_HANDLE_VALUE;
}
}
}
ImpersonateCurrentUser::ImpersonateCurrentUser() {
RegCloseKey(HKEY_CURRENT_USER);
if (!isServiceProcess())
return;
if (!token.canImpersonate())
throw rdr::Exception("Cannot impersonate unsafe or null token");
if (!ImpersonateLoggedOnUser(token)) {
DWORD err = GetLastError();
if (err != ERROR_CALL_NOT_IMPLEMENTED)
throw rdr::Win32Exception("Failed to impersonate user", GetLastError());
}
}
ImpersonateCurrentUser::~ImpersonateCurrentUser() {
if (!RevertToSelf()) {
DWORD err = GetLastError();
if (err != ERROR_CALL_NOT_IMPLEMENTED)
exit(err);
}
RegCloseKey(HKEY_CURRENT_USER);
}
UserName::UserName() {
char buf[UNLEN+1];
DWORD len = UNLEN+1;
if (!GetUserName(buf, &len))
throw rdr::Win32Exception("GetUserName failed", GetLastError());
assign(buf);
}
UserSID::UserSID() {
CurrentUserToken token;
if (!token.canImpersonate())
return;
setSID(Sid::FromToken(token.h));
}
|