Winlogon

Classic "Begin logon" dialog box on Windows XP
Windows 11 lock screen, requiring user to press Ctrl+Alt+Delete.

Winlogon (Windows Logon) is the component of Microsoft Windows operating systems that is responsible for handling the secure attention sequence, loading the user profile on logon, creates the desktops for the window station, and optionally locking the computer when a screensaver is running (requiring another authentication step). The roles and responsibilities of Winlogon have changed significantly in Windows Vista and later operating systems.

Overview

Winlogon is launched by the Session Manager Subsystem as a part of the booting process of Windows NT.

Before Windows Vista, Winlogon was responsible for starting the Service Control Manager and the Local Security Authority Subsystem Service, but since Vista these have been launched by the Windows Startup Application (wininit.exe).[1]

The first part of the logon process Winlogon conducts is starting the process that shows the user the logon screen. Before Windows Vista this was done by GINA,[2] but starting with Vista this is done by LogonUI. These programs are responsible for getting user credential and passing them to the Local Security Authority Subsystem Service, which authenticates the user.

After control is given back to Winlogon, it creates and opens an interactive window station, WinSta0,[3] and creates three desktops, Winlogon, Default and ScreenSaver. Winlogon switches from the Winlogon desktop to the Default desktop when the shell indicates that it is ready to display something for the user, or after thirty seconds, whichever comes first.[4]

The system switches back to the Winlogon desktop if the user presses Control-Alt-Delete or when a User Account Control prompt is shown.[4] Winlogon now starts the program specified in the Userinit value which defaults to userinit.exe. This value supports multiple executables.[5]

Responsibilities

Window station and desktop protection
Winlogon sets the protection of the window station and corresponding desktops to ensure that each is properly accessible. In general, this means that the local system will have full access to these objects and that an interactively logged-on user will have read access to the window station object and full access to the application desktop object.
Standard SAS recognition
Winlogon has special hooks into the User32 server that allow it to monitor Control-Alt-Delete secure attention sequence (SAS) events. Winlogon makes this SAS event information available to GINAs/credential providers to use as their SAS, or as part of their SAS. In general, GINAs should monitor SASs on their own; however, any GINA that has the standard Ctrl+Alt+Del SAS as one of the SASs it recognizes should use the Winlogon support provided for this purpose.
SAS routine dispatching
When Winlogon encounters a SAS event or when a SAS is delivered to Winlogon by the GINA, Winlogon sets the state accordingly, changes to the Winlogon desktop, and calls one of the SAS processing functions of the GINA.
User profile loading
When users log on, their user profiles are loaded into the registry. In this way, the processes of the user can use the special registry key HKEY_CURRENT_USER. Winlogon does this automatically after a successful logon but before activation of the shell for the newly logged-on user.
Assignment of security to user shell
When a user logs on, the GINA is responsible for creating one or more initial processes for that user. Winlogon provides a support function for the GINA to apply the security of the newly logged-on user to these processes. However, the preferred way to do this is for the GINA to call the Windows function CreateProcessAsUser, and let the system provide the service.
Screen saver control
Winlogon monitors keyboard and mouse activity to determine when to activate screen savers. After the screen saver is activated, Winlogon continues to monitor keyboard and mouse activity to determine when to terminate the screen saver. If the screen saver is marked as secure, Winlogon treats the workstation as locked. When there is mouse or keyboard activity, Winlogon invokes the WlxDisplayLockedNotice function of the GINA and locked workstation behavior resumes. If the screen saver is not secure, any keyboard or mouse activity terminates the screen saver without notification to the GINA.
Multiple network provider support
Multiple networks installed on a Windows system can be included in the authentication process and in password-updating operations. This inclusion lets additional networks gather identification and authentication information all at once during normal logon, using the secure desktop of Winlogon. Some of the parameters required in the Winlogon services available to GINAs explicitly support these additional network providers.

Vulnerabilities

Winlogon is a common target for several threats that could modify its function and memory usage. Winlogon has support for plugins that get loaded and notified about specific events.[6] Some rootkits bundle Winlogon plugins because they are loaded before any user logs in. Some registry keys allow multiple values to be supplied that allow a malicious program to be executed at the same time as a legitimate system file.[7]

See also

References

  1. ^ Archiveddocs. "Windows Administration: Inside the Windows Vista Kernel: Part 2". learn.microsoft.com. Retrieved 2023-05-14.
  2. ^ Russinvoich, Mark E.; Solomon, David (2005). Microsoft Windows Internals (4th ed.). Redmond, Washington: Microsoft Press. p. 81. ISBN 978-0735619173.
  3. ^ "Window Stations". MSDN. Microsoft Corporation. Retrieved 19 April 2014.
  4. ^ a b "Desktops". MSDN. Microsoft Corporation. Retrieved 19 April 2014.
  5. ^ Ionescu, Alex; Russinovich, Mark; Solomon, David A. (2012). Windows internals, Part 1 (6th ed.). Redmond, Wash.: Microsoft Press. p. 77. ISBN 978-0735648739.
  6. ^ alvinashcraft. "Winlogon Notification Events - Win32 apps". learn.microsoft.com. Retrieved 2023-05-14.
  7. ^ "Boot or Logon Autostart Execution: Winlogon Helper DLL, Sub-technique T1547.004 - Enterprise | MITRE ATT&CK®". attack.mitre.org. Retrieved 2023-05-14.
  8. ^ Warren, Tom (2020-09-25). "Windows XP source code leaks online". The Verge. Retrieved 2020-09-27.

Read other articles:

ГорзGorze   Країна  Франція Регіон Гранд-Ест  Департамент Мозель  Округ Мец Кантон Арс-сюр-Мозель Код INSEE 57254 Поштові індекси 57680 Координати 49°03′17″ пн. ш. 5°59′59″ сх. д.H G O Висота 169 - 356 м.н.р.м. Площа 17,94 км² Населення 1155 (01-2020[1]) Густота 67,61 ос./км² Розміщенн

 

This article is about International charity. For the political organization representing Humanist political parties, see Humanist International. Secular humanism advocacy organization Humanists InternationalFormation1952; 71 years ago (1952)FoundersJulian HuxleyJaap van PraagHarold BlackhamFounded atAmsterdam, NetherlandsTypeInternational non-governmental organisationLegal status501(c)(3) organizationHeadquartersLondon, United KingdomRegion served WorldwidePresidentAndrew Co...

 

Опис файлу Опис Постер до фільму «Стрибок угору» Джерело Rebound film.jpg (англ. вікі) Час створення 2005 Автор зображення Авторські права належать дистриб'ютору, видавцю фільму або художнику цього постера. Ліцензія див. нижче Обґрунтування добропорядного використання для с�...

 

Dr. StrangeloveFilm poster asli dirancang oleh Tomi UngererSutradara Stanley Kubrick Produser Stanley Kubrick Ditulis oleh Stanley Kubrick Peter George Terry Southern SkenarioStanley Kubrick Peter GeorgeTerry SouthernBerdasarkanNovel:Peter GeorgeLain-lain:Peter SellersJames B. HarrisPemeranPeter SellersGeorge C. ScottSterling HaydenKeenan WynnSlim PickensPeter BullJames Earl JonesTracy ReedPenata musikLaurie JohnsonSinematograferGilbert Taylor, BSCDistributorColumbia PicturesTanggal ril...

 

ISAW redirects here. For the food, see Isaw. The Institute for the Study of the Ancient World (ISAW) is a center for advanced scholarly research and graduate education at New York University. ISAW's mission is to cultivate comparative, connective investigations of the ancient world from the western Mediterranean to China.[1] Areas of specialty among ISAW's faculty include the Greco-Roman world, the Ancient Near East, Egypt, Central Asia and the Silk Road, East Asian art and archaeolog...

 

Neuschönau Lambang kebesaranLetak Neuschönau NegaraJermanNegara bagianBayernWilayahNiederbayernKreisFreyung-GrafenauPemerintahan • MayorHeinz Wolf (FWG)Luas • Total27,54 km2 (1,063 sq mi)Ketinggian650 m (2,130 ft)Populasi (2013-12-31)[1] • Total2.214 • Kepadatan0,80/km2 (2,1/sq mi)Zona waktuWET/WMPET (UTC+1/+2)Kode pos94556Kode area telepon08558 u. 08552 (Altschönau)Pelat kendaraanFRGSitus webwww.neu...

 

Kebun Raya BogorKolam AstridLokasi di BogorJenisKebun botaniLokasi Bogor, Jawa BaratArea87 hektare (210 ekar; 0,87 km2)Dibuat18 Mei 1817 (1817-05-18)PendiriCaspar Georg Carl ReinwardtDioperasikan olehBadan Riset dan Inovasi NasionalSitus webkebunraya.id/bogor Kebun Raya Bogor atau Kebun Botani Bogor (Sunda: ᮊᮨᮘᮧᮔ᮪ ᮛᮚ ᮘᮧᮌᮧᮁ, translit. Kebon Raya Bogor) adalah sebuah kebun botani besar yang terletak di Kota Bogor, Indonesia. Kebun ini dioperasik...

 

Fragmen Malam karya Wing Kardjo Wing Kardjo (lahir di Garut, Jawa Barat pada 23 April 1937 - meninggal di Jepang pada 19 Maret 2002) adalah seorang penyair Indonesia yang aktif pada masa pemapanan sastra Indonesia tahun 1965 hingga 1998.[1][2] Riwayat hidup Terlahir di provinsi Jawa Barat, Wing Kardjo mengenyam pendidikan tingkat SD dan SMP di Tasikmalaya, lalu pindah ke Garut untuk menempuh pendidikan SMA. Setelah lulus, Wing Kardjo pergi ke Jakarta untuk mengambil sekolah ba...

 

L-70 用途:練習機 製造者:ヴァルメト 運用者:フィンランド空軍 初飛行:1975年7月1日 生産数:30機 運用開始:1980年 表示 L-70 は、フィンランドで開発された初等練習機。ヴィンカ(Vinka、「突風」の意)という愛称がある。ミルトレイナーは、輸出用につけられた名称。 概要 フィンランドの国営航空機製作所ヴァルメトが開発した。機体は全金属製、エンジンは単発�...

 

2010 live album by KissKiss Sonic Boom Over EuropeLive album by KissReleased2010Recorded2010GenreHard rockLength(Varies)LabelSimfy LiveKiss chronology Sonic Boom(2009) Kiss Sonic Boom Over Europe(2010) Monster(2012) Kiss Sonic Boom Over Europe is a series of live albums (2 CDs, a USB stick or an MP3 download), containing a recording of the complete set from a European show on the Sonic Boom Over Europe Tour which began May 1, 2010 in Sheffield, England. The discs were recorded and dis...

 

This article may rely excessively on sources too closely associated with the subject, potentially preventing the article from being verifiable and neutral. Please help improve it by replacing them with more appropriate citations to reliable, independent, third-party sources. (February 2012) (Learn how and when to remove this template message) Henry LozanoDirector - Los Angeles CountyTeen Challenge and UrbanMinistries InitiativeIn officeAugust 10, 2011 – currentExecutive DirectorShi...

 

У Вікіпедії є статті про інших людей із прізвищем Секеч. Іштван Секеч Особисті дані Повне ім'я Іштван Йожефович Секеч Народження 3 грудня 1939(1939-12-03)   Берегове, Закарпаття Смерть 28 січня 2019(2019-01-28) (79 років)   Москва, Росія Зріст 178 см Вага 74 кг Громадянство  СРСР Ук...

 

Korean cattle breed HanwooConservation statusFAO (2007): not at riskOther namesHanuKorean BrownKorean NativeCountry of originKoreaUseformerly draught, now meatTraitsWeightMale: 466 kg[1]Female: 355 kg[1]HeightMale: 124 cm[1]Female: 117 cm[1]Coatbrown[1]Horn statushorned in both sexesNotestaurusCattleBos primigenius HanwooHangul한우Hanja韓牛Revised RomanizationHanuMcCune–ReischauerHanu The Hanwoo (Korean: 한우), also Hanu or Korean Native, is a b...

 

American football player (born 1978) American football player Kyle Vanden BoschVanden Bosch in 2023No. 93Position:Defensive endPersonal informationBorn: (1978-11-17) November 17, 1978 (age 45)Larchwood, Iowa, U.S.Height:6 ft 4 in (1.93 m)Weight:278 lb (126 kg)Career informationHigh school:West Lyon (Inwood, Iowa)College:Nebraska (1997–2000)NFL Draft:2001 / Round: 2 / Pick: 34Career history Arizona Cardinals (2001–2004) Tennessee Titans (20...

 

In this Indian name, the name IIser is a patronymic, and the person should be referred to by the given name, Sreejith. Sreejith VijayBorn28 March 1986 (1986-03-28) (age 37)Thripunithura, Kerala, IndiaOccupation(s)Actor, Model , RJ , VJYears active2011–presentSpouse Archana Gopinathan ​(m. 2018)​ Sreejith Vijay is an Indian actor who works predominantly in Malayalam films and television soap operas. Personal life Sreejith was born on 28 March 1986 ...

 

Species of spider Caribena laeta Female Male Scientific classification Domain: Eukaryota Kingdom: Animalia Phylum: Arthropoda Subphylum: Chelicerata Class: Arachnida Order: Araneae Infraorder: Mygalomorphae Family: Theraphosidae Genus: Caribena Species: C. laeta Binomial name Caribena laeta(C.L. Koch, 1842)[1] Synonyms[1] Mygale laeta C.L. Koch, 1842 Mygale caesia C.L. Koch, 1842 Typhochlaena caesia (C.L. Koch, 1842) Avicularia caesia (C.L. Koch, 1842) Avicularia laeta (C...

 

Steel roller coaster This article is about the roller coaster at Six Flags Over Georgia. For the roller coaster at West Edmonton Mall's Galaxyland, see Mindbender (Galaxyland). For the roller coaster formerly named Mayan Mindbender, formerly located at Six Flags AstroWorld, see Hornet (roller coaster). This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources...

 

This is a list of metropolitan areas by population in India. As per the Constitution of India, a metropolitan area as an area having a population of 10 lakh or more, comprised in one or more districts and consisting of two or more municipalities or panchayats or other contiguous areas, specified by the Governor by a public notification to be a Metropolitan area.[1][2] List The list is updated for cities wherever metropolitan area data available with the corresponding sources. ...

 

American actor (born 1982) Erik StocklinStocklin in 2018, as PatrickBorn (1982-09-24) September 24, 1982 (age 41)[1]Freehold, New Jersey, U.S.OccupationActorSpouse Colleen Ballinger ​(m. 2018)​Children3 Erik Flynn Stocklin[2] (born September 24, 1982) is an American actor. He is known for his recurring roles on television series such as Mistresses, Stalker and Good Trouble, and for his leading role in the Netflix original series Haters Back Of...

 

Artikel ini perlu dikembangkan agar dapat memenuhi kriteria sebagai entri Wikipedia.Bantulah untuk mengembangkan artikel ini. Jika tidak dikembangkan, artikel ini akan dihapus. Ananya Khare (Hindi: अनन्या खरे) adalah seorang aktris televisi dan film India yang terkenal karena penampilannya dalam film-film Bollywood seperti Devdas dan Chandni Bar. Dia memenangkan Penghargaan Film Nasional untuk Aktris Pendukung Terbaik untuk penampilannya di Chandni Bar.