Repository navigation
Expand file tree
/
Copy pathauditor.h
More file actions
310 lines (253 loc) · 9.93 KB
/
Copy pathauditor.h
File metadata and controls
310 lines (253 loc) · 9.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
#pragma once
//
// auditor.h
// Signature inspection functions for PE files.
// IsFileSigned - returns the count of signatures on a file (0 = unsigned)
// HasTestSignature - returns true if the file is signed but with an untrusted-root (test) cert
// IsSignedBy - returns true if the file has a valid signature from a given company
//
#ifndef UNICODE
#define UNICODE
#endif
#ifndef _UNICODE
#define _UNICODE
#endif
#ifndef WIN32_LEAN_AND_MEAN
#define WIN32_LEAN_AND_MEAN
#endif
#include <windows.h>
#include <softpub.h>
#include <wintrust.h>
#include <wincrypt.h>
#include <filesystem>
#include <string>
#include <vector>
#pragma comment(lib, "Wintrust.lib")
#pragma comment(lib, "Crypt32.lib")
namespace fs = std::filesystem;
// OID for nested (dual) signatures stored as unauthenticated attributes
static constexpr char kNestedSigOID[] = "1.3.6.1.4.1.311.2.4.1";
// ---------------------------------------------------------------------------
// Internal helpers
// ---------------------------------------------------------------------------
// Extracts the leaf signer display names from an already-opened HCERTSTORE /
// HCRYPTMSG pair. Appends results into 'out'.
static void CollectSignerNames(HCERTSTORE hStore, HCRYPTMSG hMsg,
std::vector<std::string>& out)
{
DWORD signerCount = 0;
DWORD paramSize = sizeof(signerCount);
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_COUNT_PARAM, 0,
&signerCount, ¶mSize))
return;
for (DWORD i = 0; i < signerCount; ++i)
{
// --- primary signer name ---
DWORD siSize = 0;
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_INFO_PARAM, i, nullptr, &siSize))
continue;
std::vector<BYTE> buf(siSize);
auto* si = reinterpret_cast<CMSG_SIGNER_INFO*>(buf.data());
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_INFO_PARAM, i, si, &siSize))
continue;
CERT_INFO ci = {};
ci.Issuer = si->Issuer;
ci.SerialNumber = si->SerialNumber;
PCCERT_CONTEXT pCert = CertFindCertificateInStore(
hStore,
X509_ASN_ENCODING | PKCS_7_ASN_ENCODING,
0, CERT_FIND_SUBJECT_CERT, &ci, nullptr);
if (pCert)
{
char name[512] = {};
CertGetNameStringA(pCert, CERT_NAME_SIMPLE_DISPLAY_TYPE,
0, nullptr, name, sizeof(name));
out.emplace_back(name);
CertFreeCertificateContext(pCert);
}
// --- nested signature signer names ---
for (DWORD j = 0; j < si->UnauthAttrs.cAttr; ++j)
{
if (strcmp(si->UnauthAttrs.rgAttr[j].pszObjId, kNestedSigOID) != 0)
continue;
for (DWORD k = 0; k < si->UnauthAttrs.rgAttr[j].cValue; ++k)
{
CRYPT_DATA_BLOB blob = {
si->UnauthAttrs.rgAttr[j].rgValue[k].cbData,
si->UnauthAttrs.rgAttr[j].rgValue[k].pbData
};
HCERTSTORE nestedStore = nullptr;
HCRYPTMSG nestedMsg = nullptr;
if (CryptQueryObject(
CERT_QUERY_OBJECT_BLOB, &blob,
CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED,
CERT_QUERY_FORMAT_FLAG_BINARY,
0, nullptr, nullptr, nullptr,
&nestedStore, &nestedMsg, nullptr))
{
CollectSignerNames(nestedStore, nestedMsg, out);
CryptMsgClose(nestedMsg);
CertCloseStore(nestedStore, 0);
}
}
}
}
}
// ---------------------------------------------------------------------------
// Public API
// ---------------------------------------------------------------------------
// Returns the total number of signatures on a PE file (primary + nested).
// Returns 0 if the file has no embedded signature at all.
inline int IsFileSigned(const fs::path& filePath)
{
std::wstring wpath = filePath.wstring();
HCERTSTORE hStore = nullptr;
HCRYPTMSG hMsg = nullptr;
if (!CryptQueryObject(
CERT_QUERY_OBJECT_FILE, wpath.c_str(),
CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED,
CERT_QUERY_FORMAT_FLAG_BINARY,
0, nullptr, nullptr, nullptr,
&hStore, &hMsg, nullptr))
{
return 0;
}
DWORD signerCount = 0;
DWORD paramSize = sizeof(signerCount);
CryptMsgGetParam(hMsg, CMSG_SIGNER_COUNT_PARAM, 0, &signerCount, ¶mSize);
int total = static_cast<int>(signerCount);
// Count nested signatures stored as unauthenticated attributes
for (DWORD i = 0; i < signerCount; ++i)
{
DWORD siSize = 0;
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_INFO_PARAM, i, nullptr, &siSize))
continue;
std::vector<BYTE> buf(siSize);
auto* si = reinterpret_cast<CMSG_SIGNER_INFO*>(buf.data());
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_INFO_PARAM, i, si, &siSize))
continue;
for (DWORD j = 0; j < si->UnauthAttrs.cAttr; ++j)
{
if (strcmp(si->UnauthAttrs.rgAttr[j].pszObjId, kNestedSigOID) == 0)
total += static_cast<int>(si->UnauthAttrs.rgAttr[j].cValue);
}
}
CryptMsgClose(hMsg);
CertCloseStore(hStore, 0);
return total;
}
// Returns true if the file has an embedded signature whose signer certificate
// chain ends in an untrusted root — i.e. a test / self-signed certificate that
// has not been installed in the machine's Trusted Root CA store.
// Returns false if the file is unsigned, or if every signer chains to a
// trusted root (production signature).
inline bool HasTestSignature(const fs::path& filePath)
{
std::wstring wpath = filePath.wstring();
// Must have an embedded signature blob at all.
HCERTSTORE hStore = nullptr;
HCRYPTMSG hMsg = nullptr;
if (!CryptQueryObject(
CERT_QUERY_OBJECT_FILE, wpath.c_str(),
CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED,
CERT_QUERY_FORMAT_FLAG_BINARY,
0, nullptr, nullptr, nullptr,
&hStore, &hMsg, nullptr))
{
return false; // unsigned — no signature at all
}
DWORD signerCount = 0;
DWORD paramSize = sizeof(signerCount);
CryptMsgGetParam(hMsg, CMSG_SIGNER_COUNT_PARAM, 0, &signerCount, ¶mSize);
bool foundTestCert = false;
for (DWORD i = 0; i < signerCount && !foundTestCert; ++i)
{
DWORD siSize = 0;
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_INFO_PARAM, i, nullptr, &siSize))
continue;
std::vector<BYTE> buf(siSize);
auto* si = reinterpret_cast<CMSG_SIGNER_INFO*>(buf.data());
if (!CryptMsgGetParam(hMsg, CMSG_SIGNER_INFO_PARAM, i, si, &siSize))
continue;
CERT_INFO ci = {};
ci.Issuer = si->Issuer;
ci.SerialNumber = si->SerialNumber;
PCCERT_CONTEXT pLeaf = CertFindCertificateInStore(
hStore,
X509_ASN_ENCODING | PKCS_7_ASN_ENCODING,
0, CERT_FIND_SUBJECT_CERT, &ci, nullptr);
if (!pLeaf)
continue;
// Build the chain and inspect trust errors.
CERT_CHAIN_PARA chainPara = {};
chainPara.cbSize = sizeof(chainPara);
PCCERT_CHAIN_CONTEXT pChain = nullptr;
if (CertGetCertificateChain(
nullptr, // default chain engine
pLeaf,
nullptr, // current time
hStore,
&chainPara,
CERT_CHAIN_REVOCATION_CHECK_CACHE_ONLY,
nullptr,
&pChain))
{
// CERT_TRUST_IS_UNTRUSTED_ROOT means the root CA is not present in
// the machine's Trusted Root Certification Authorities store —
// the hallmark of a test / development certificate.
if (pChain->TrustStatus.dwErrorStatus & CERT_TRUST_IS_UNTRUSTED_ROOT)
foundTestCert = true;
CertFreeCertificateChain(pChain);
}
CertFreeCertificateContext(pLeaf);
}
CryptMsgClose(hMsg);
CertCloseStore(hStore, 0);
return foundTestCert;
}
// Returns true if the file has a cryptographically valid signature AND at least
// one signer's subject display name contains 'companyName'.
// Example: IsSignedBy(path, "Microsoft")
inline bool IsSignedBy(const fs::path& filePath, const std::string& companyName)
{
// Verify signature is actually valid first
std::wstring wpath = filePath.wstring();
WINTRUST_FILE_INFO fileInfo = {};
fileInfo.cbStruct = sizeof(WINTRUST_FILE_INFO);
fileInfo.pcwszFilePath = wpath.c_str();
GUID policyGuid = WINTRUST_ACTION_GENERIC_VERIFY_V2;
WINTRUST_DATA trustData = {};
trustData.cbStruct = sizeof(WINTRUST_DATA);
trustData.dwUIChoice = WTD_UI_NONE;
trustData.fdwRevocationChecks = WTD_REVOKE_NONE;
trustData.dwUnionChoice = WTD_CHOICE_FILE;
trustData.pFile = &fileInfo;
trustData.dwStateAction = WTD_STATEACTION_VERIFY;
trustData.dwProvFlags = WTD_SAFER_FLAG | WTD_CACHE_ONLY_URL_RETRIEVAL;
LONG status = WinVerifyTrust(
static_cast<HWND>(INVALID_HANDLE_VALUE), &policyGuid, &trustData);
trustData.dwStateAction = WTD_STATEACTION_CLOSE;
WinVerifyTrust(static_cast<HWND>(INVALID_HANDLE_VALUE), &policyGuid, &trustData);
if (status != ERROR_SUCCESS)
return false;
// Collect all signer names (primary + nested) and check for companyName
HCERTSTORE hStore = nullptr;
HCRYPTMSG hMsg = nullptr;
if (!CryptQueryObject(
CERT_QUERY_OBJECT_FILE, wpath.c_str(),
CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED,
CERT_QUERY_FORMAT_FLAG_BINARY,
0, nullptr, nullptr, nullptr,
&hStore, &hMsg, nullptr))
{
return false;
}
std::vector<std::string> names;
CollectSignerNames(hStore, hMsg, names);
CryptMsgClose(hMsg);
CertCloseStore(hStore, 0);
for (const auto& name : names)
if (name.find(companyName) != std::string::npos)
return true;
return false;
}