Commit 514dbdf
committed
Fix SDDL SID alias table missing ten aliases Windows resolves (Fixes #133)
SDDLToSID was populated from the MS-DTYP 2.5.1.1 sid-token table and was missing
three of its rows, so SDDL using them failed to parse in both ACE trustee
position and inside SID(...) in a conditional expression:
AC S-1-15-2-1 All Application Packages
UD S-1-5-84-0-0-0-0-0 User Mode Drivers
WR S-1-5-33 Write Restricted Code
AC in particular appears in the default DACL of many Windows objects, so
descriptors collected from real systems failed rather than degrading.
Seven further aliases are resolved by Windows but absent from the MS-DTYP table.
Their values were read from the 67-entry alias table in sechost.dll (Windows
Server 2025) at .data RVA 0x99f30, whose record layout is alias at +0x02, RID at
+0x18 and a SID-prefix template selector at +0x1c. The template decode was
validated against 19 aliases with independently known SIDs before being trusted
on these:
AS S-1-18-1 Authentication Authority Asserted Identity
SS S-1-18-2 Service Asserted Identity
HO S-1-5-32-584 BUILTIN\\User Mode Hardware Operators
SH S-1-5-32-585 BUILTIN\\OpenSSH Users
AP S-1-5-21-0-0-0-525 Protected Users
KA S-1-5-21-0-0-0-526 Key Admins
EK S-1-5-21-0-0-0-527 Enterprise Key Admins
Domain-relative entries follow the existing placeholder-domain convention in this
map. EK resolves against the forest root domain on Windows rather than the local
domain; that distinction is not representable while the domain is a placeholder
and is noted in the map comment.1 parent d0fb571 commit 514dbdf
2 files changed
Lines changed: 93 additions & 15 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
23 | 30 | | |
24 | 31 | | |
25 | 32 | | |
| |||
46 | 53 | | |
47 | 54 | | |
48 | 55 | | |
| 56 | + | |
| 57 | + | |
49 | 58 | | |
50 | 59 | | |
51 | 60 | | |
| |||
62 | 71 | | |
63 | 72 | | |
64 | 73 | | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
65 | 77 | | |
66 | 78 | | |
67 | 79 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
0 commit comments