Windows жүйесіндегі Winlogon компоненті – қауіпсіз кіру, пайдаланушы профилінің жүктелуі, жұмыс үстелінің құрылуына жауапты. Жаңа өзгерістер туралы біліңіз!
Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Мазмұны
Кіріспе
Microsoft Windows операциялық жүйелерінің құрамы
Component of Microsoft Windows operating systems
Winlogon (Windows Logon) – Microsoft Windows операциялық жүйелерінің қауіпсіз назар тізбегін басқаруға, пайдаланушы профилін кірген кезде жүктеуге, терезе станциясы үшін жұмыс үстелін құруға және экран сақтағышы іске қосылғанда компьютерді қосымша құлыптауға (қосымша аутентификация қадамын талап етуге) жауапты құрамы. Windows Vista және одан кейінгі операциялық жүйелерде Winlogon-ның міндеттері мен жауапкершілігі айтарлықтай өзгерді.
Winlogon (Windows Logon) is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, creates the desktops for the window station, and optionally locking the computer when a screensaver is running (requiring another authentication step). In Windows Vista and later operating systems, the roles and responsibilities of Winlogon have changed significantly.
Шолу
Winlogon Windows NT жүктеу процесінің бір бөлігі ретінде сеанс менеджері жүйесімен іске қосылады. Windows Vista-дан бұрын Winlogon қызмет басқарушысын және жергілікті қауіпсіздік органының ішкі жүйе қызметін іске қосуға жауапты болды, бірақ Vista-дан бастап бұл функциялар Windows Startup Application (wininit. exe) арқылы орындалады. Winlogon жүйеге кіру процесінің алғашқы қадамы – пайдаланушыға кіру экранын көрсету процесін бастау. Windows Vista-дан бұрын бұл GINA бағдарламасымен жасалса, Vista-дан бастап LogonUI бағдарламасы орындайды. Бұл бағдарламалар пайдаланушының кіру деректерін алып, оларды пайдаланушыны куәландыратын жергілікті қауіпсіздік органының ішкі жүйе қызметіне жіберуге жауапты. Winlogon-ға басқару қайтарылғаннан кейін, ол WinSta0 интерактивті терезе станциясын құрып, ашады және Winlogon, Default және ScreenSaver атты үш жұмыс үстелін жасайды. Winlogon, қабық пайдаланушыға бірдеңе көрсетуге дайын екенін хабарлағанда немесе отыз секунд ішінде, егер бұл оқиға одан бұрын орын алса, Winlogon жұмыс үстелінен Default жұмыс үстеліне ауысады. Егер пайдаланушы Control+Alt+Delete пернелерін басса немесе Пайдаланушы есебін басқару сұрауы көрсетілсе, жүйе Winlogon жұмыс үстеліне қайта оралады.
Winlogon is launched by the Session Manager Subsystem as a part of the booting process of Windows NT. Before Windows Vista, Winlogon was responsible for starting the Service Control Manager and the Local Security Authority Subsystem Service, but since Vista these have been launched by the Windows Startup Application (wininit. exe). The first part of the logon process Winlogon conducts is starting the process that shows the user the logon screen. Before Windows Vista this was done by GINA, but starting with Vista this is done by LogonUI. These programs are responsible for getting user credential and passing them to the Local Security Authority Subsystem Service, which authenticates the user. After control is given back to Winlogon, it creates and opens an interactive window station, WinSta0, and creates three desktops, Winlogon, Default and ScreenSaver. Winlogon switches from the Winlogon desktop to the Default desktop when the shell indicates that it is ready to display something for the user, or after thirty seconds, whichever comes first. The system switches back to the Winlogon desktop if the user presses Control Alt Delete or when a User Account Control prompt is shown.
Қауіпті жерлер
Winlogon – оның функциясын және жадты пайдалануын өзгерте алатын бірнеше қауіптің жалпы нысанасы. Winlogon плагиндерді қолдайды, олар жүктеліп, белгілі бір оқиғалар туралы хабар алады. Кейбір руткиттер Winlogon плагиндерін қосады, себебі олар кез келген пайдаланушы жүйеге кірмес бұрын жүктеледі. Кейбір тіркелім кілттері бірнеше мәнді енгізуге мүмкіндік береді, бұл қауіпті бағдарламаның заңды жүйелік файлмен бірдей уақытта іске қосылуына жағдай жасайды.
Winlogon is a common target for several threats that could modify its function and memory usage. Winlogon has support for plugins that get loaded and notified about specific events. Some rootkits bundle Winlogon plugins because they are loaded before any user logs in. Some registry keys allow multiple values to be supplied that allow a malicious program to be executed at the same time as a legitimate system file.