Сравнивайте с английским: нажмите на абзац — оригинал откроется в окне. Кнопка EN под абзацем показывает его прямо в тексте.
Содержание
Введение
Компонент операционных систем Microsoft Windows
Component of Microsoft Windows operating systems
Winlogon (Windows Logon) — это компонент операционных систем Microsoft Windows, отвечающий за обработку последовательности безопасного внимания, загрузку профиля пользователя при входе в систему, создание рабочих столов для оконных станций и, опционально, блокировку компьютера при запуске заставки экрана (которая требует дополнительного шага аутентификации). В Windows Vista и последующих версиях операционных систем роли и обязанности Winlogon значительно изменились.
Winlogon (Windows Logon) is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, creates the desktops for the window station, and optionally locking the computer when a screensaver is running (requiring another authentication step). In Windows Vista and later operating systems, the roles and responsibilities of Winlogon have changed significantly.
Обзор
Winlogon запускается подсистемой управления сеансами в процессе загрузки Windows NT. До Windows Vista Winlogon отвечал за запуск диспетчера управления службами и подсистемы локального органа безопасности, но начиная с Vista эти задачи выполняются приложением Windows Startup Application (wininit.exe). Первым этапом процесса входа в систему, выполняемым Winlogon, является запуск процесса, отображающего пользователю экран входа. До Windows Vista это делалось GINA, но начиная с Vista – LogonUI. Эти программы отвечают за получение учетных данных пользователя и передачу их в подсистему локального органа безопасности для аутентификации. После возврата управления Winlogon, он создает и открывает интерактивную оконную станцию WinSta0 и три рабочих стола: Winlogon, Default и ScreenSaver. Winlogon переключается с рабочего стола Winlogon на рабочий стол Default, когда оболочка сообщает о готовности отображать что-либо для пользователя, или по истечении тридцати секунд, в зависимости от того, что произойдет раньше. Система возвращается на рабочий стол Winlogon, если пользователь нажимает Control+Alt+Delete или когда появляется запрос контроля учетной записи пользователя.
Winlogon is launched by the Session Manager Subsystem as a part of the booting process of Windows NT. Before Windows Vista, Winlogon was responsible for starting the Service Control Manager and the Local Security Authority Subsystem Service, but since Vista these have been launched by the Windows Startup Application (wininit. exe). The first part of the logon process Winlogon conducts is starting the process that shows the user the logon screen. Before Windows Vista this was done by GINA, but starting with Vista this is done by LogonUI. These programs are responsible for getting user credential and passing them to the Local Security Authority Subsystem Service, which authenticates the user. After control is given back to Winlogon, it creates and opens an interactive window station, WinSta0, and creates three desktops, Winlogon, Default and ScreenSaver. Winlogon switches from the Winlogon desktop to the Default desktop when the shell indicates that it is ready to display something for the user, or after thirty seconds, whichever comes first. The system switches back to the Winlogon desktop if the user presses Control Alt Delete or when a User Account Control prompt is shown.
Уязвимости
Winlogon является распространенной целью для ряда угроз, способных изменять его функциональность и использование памяти. Winlogon поддерживает плагины, которые загружаются и получают уведомления о определенных событиях. Некоторые руткиты поставляются с плагинами Winlogon, поскольку они загружаются до входа в систему любого пользователя. Определенные ключи реестра допускают указание нескольких значений, позволяющих вредоносной программе выполняться одновременно с легитимным системным файлом.
Winlogon is a common target for several threats that could modify its function and memory usage. Winlogon has support for plugins that get loaded and notified about specific events. Some rootkits bundle Winlogon plugins because they are loaded before any user logs in. Some registry keys allow multiple values to be supplied that allow a malicious program to be executed at the same time as a legitimate system file.