-
Notifications
You must be signed in to change notification settings - Fork 121
/
GetProcessAuthority.cpp
45 lines (43 loc) · 1.23 KB
/
GetProcessAuthority.cpp
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
#include <windows.h>
#include <TlHelp32.h>
BOOL IsRunasAdmin(HANDLE hProcess)
{
BOOL bElevated = FALSE;
HANDLE hToken = NULL;
if (!OpenProcessToken(hProcess,TOKEN_QUERY,&hToken))
return FALSE;
TOKEN_ELEVATION tokenEle;
DWORD dwRetLen = 0;
if ( GetTokenInformation(hToken,TokenElevation,&tokenEle,sizeof(tokenEle),&dwRetLen))
{
if (dwRetLen == sizeof(tokenEle))
{
bElevated = tokenEle.TokenIsElevated;
}
}
CloseHandle(hToken);
return bElevated;
}
int main()
{
PROCESSENTRY32 pinfo;
HANDLE hProcess,hModule;
BOOL bRunAsAdmin;
hModule = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
BOOL report = Process32First(hModule, &pinfo);
printf("\n%-20s PID Run as Admin\n","Process");
printf("==================== ==== ============\n");
while(report)
{
printf("%-20s %4d ",pinfo.szExeFile,pinfo.th32ProcessID);
hProcess = ::OpenProcess(PROCESS_QUERY_INFORMATION,FALSE,pinfo.th32ProcessID);
bRunAsAdmin = IsRunasAdmin(hProcess);
if (bRunAsAdmin)
printf("%-12s\n","Yes");
else
printf("\n");
report=Process32Next(hModule, &pinfo);
}
CloseHandle(hModule);
return 0;
}