无人登录时,系统使用哪个windows帐户?

如果您对Windows如何在引擎盖下运行感到好奇和了解更多,那么您可能会发现自己在想,当没有人登录Windows时,哪个“帐户”活动进程正在运行。有鉴于此,今天的超级用户问答帖子为好奇的读者提供了答案。...

无人登录时,系统使用哪个windows帐户?

如果您对Windows如何在引擎盖下运行感到好奇和了解更多,那么您可能会发现自己在想,当没有人登录Windows时,哪个“帐户”活动进程正在运行。有鉴于此,今天的超级用户问答帖子为好奇的读者提供了答案。

今天的问答环节是由SuperUser提供的,SuperUser是Stack Exchange的一个分支,是一个由社区驱动的问答网站分组。

问题

超级用户读者Kunal Chopra想知道无人登录时Windows使用的是哪个帐户:

When no one is logged into Windows and the log in screen is displayed, which user account are the current processes running under (video & sound drivers, login session, any server software, accessibility controls, etc.)? It cannot be any user or the previous user because no one is logged in.

What about processes that have been started by a user but continue to run after logging off (for example, HTTP/FTP servers and other networking processes)? Do they switch over to the SYSTEM account? If a user-started process is switched over to the SYSTEM account, then that indicates a very serious vulnerability. Does such a process run by that user continue to run under that user’s account somehow after they have logged off?

Is this why the SETHC hack allows you to use CMD as SYSTEM?

没有人登录时,Windows使用哪个帐户?

答案

超级用户贡献者grawity为我们提供了答案:

When no one is logged into Windows and the log in screen is displayed, which user account are the current processes running under (video & sound drivers, login session, any server software, accessibility controls, etc.)?

Almost all drivers run in kernel mode; they do not need an account unless they start user-space processes. Those user-space drivers run under SYSTEM.

With regard to the login session, I am sure that it uses SYSTEM as well. You can see logonui.exe using Process Hacker or SysInternals Process Explorer. In fact, you can see everything that way.

As for server software, see Windows services below.

What about processes that have been started by a user but continue to run after logging off (for example, HTTP/FTP servers and other networking processes)? Do they switch over to the SYSTEM account?

There are three kinds here:

  1. Plain Old Background Processes: These run under the same account as whoever started them and do not run after logging off. The logoff process kills them all. HTTP/FTP servers and other networking processes do not run as regular background processes. They run as services.
  2. Windows Service Processes: These are not launched directly, but via the Service Manager. By default, services run as LocalSystem (which isanae says equals SYSTEM) can have dedicated accounts configured. Of course, practically nobody bothers. They just install XAMPP, WampServer, or some other software and let it run as SYSTEM (forever unpatched). On recent Windows systems, I think services can also have their own SIDs, but again I have not done much research on this yet.
  3. Scheduled Tasks: These are launched by the Task Scheduler Service in the background and always run under the account configured in the task (usually whoever created the task).

If a user-started process is switched over to the SYSTEM account, then that indicates a very serious vulnerability.

It is not a vulnerability because you must already have Administrator privileges to install a service. Having Administrator privileges already lets you do practically everything.

See Also: Various other non-vulnerabilities of the same kind.

请务必通过下面的线程链接阅读此有趣讨论的其余部分!


有什么要补充的解释吗?在评论中发出声音。想从其他精通技术的Stack Exchange用户那里了解更多答案吗?在这里查看完整的讨论主题。

  • 发表于 2021-04-10 04:25
  • 阅读 ( 175 )
  • 分类:互联网

你可能感兴趣的文章

如何重置丢失的windows 10密码

...**或其他计算机上,尝试使用您在PC上使用的Microsoft帐户登录。请确保您在此处键入的电子邮件没有错误。如果您仍然无法进入,请继续重置您的Microsoft密码。请转到Microsoft密码重置页面开始;您甚至可以在秋季创建者更新的登...

  • 发布于 2021-03-11 19:51
  • 阅读 ( 330 )

如何安全升级到Windows10并再次降级回Windows7或8.1

...据,请单击第一个屏幕上的下一步以使用您的帐户。若要登录到另一个帐户,请单击“我不是[帐户]”。 ...

  • 发布于 2021-03-12 14:39
  • 阅读 ( 237 )

如何对windows10进行密码保护

...rosoft帐户的另一个好处是设置同步。您的个人设置将在您登录的所有设备上同步,从而节省在每个设备上的时间。 ...

  • 发布于 2021-03-14 23:11
  • 阅读 ( 195 )

重置忘记的windows管理员密码的3种方法

...rosoft帐户(可能您的键盘有卡住的键或类似的东西)。去登录.live.com在您的**或其他计算机上,尝试使用您在PC上使用的Microsoft帐户登录,确保您没有键入任何错误。 ...

  • 发布于 2021-03-15 03:48
  • 阅读 ( 841 )

如何远程访问mac

...应用程序并登录您的TeamViewer帐户。 查找“无人参与访问”标题并单击三个检查中的每一个,以便使您的Mac即使在您不使用时也可用。 ...

  • 发布于 2021-03-22 09:44
  • 阅读 ( 267 )

连续性备选方案:5款android最佳windows程序

...据。如果你没有看到这个选项,你需要先用你的Google帐户登录Chrome。 ...

  • 发布于 2021-03-26 08:25
  • 阅读 ( 282 )

如何在Windows10上切换到本地用户帐户

Windows 10的安装过程现在强制您使用Microsoft帐户登录。如果你想使用本地用户帐户,微软说你应该在以后从微软转到本地用户帐户。下面是方法。 你需要知道的 有一种方法可以在不使用Microsoft帐户的情况下设置Windows 10。如果...

  • 发布于 2021-04-02 19:57
  • 阅读 ( 176 )

你为什么要登录你的家用电脑呢?

每次打开计算机时,都必须选择一个用户帐户并登录。在Windows、macOS、Linux甚至Chrome操作系统上都是如此。这就是为什么这对个人电脑是必要的,而不是iPhone、iPad和Android。 它们是为多个用户设计的 现代操作系统是为多个用户...

  • 发布于 2021-04-03 04:54
  • 阅读 ( 193 )

如何从linux shell创建和安装ssh密钥

...选项的复选框,但这会降低您的安全性。如果您的计算机无人看管,任何人都可以连接到具有您的公钥的远程计算机。 输入密码后,您就可以连接到远程计算机。 要再次端到端验证该过程,请使用exit命令断开连接,然后从同...

  • 发布于 2021-04-03 11:45
  • 阅读 ( 239 )

windows任务管理器:完整指南

...应用程序(Win32应用程序) 启动:启动程序的列表,当你登录到你的用户帐户时,Windows会自动启动这些程序。您可以从这里禁用启动程序,不过也可以从“设置”>“应用程序”>“启动”中禁用。 用户:当前登录到你电脑...

  • 发布于 2021-04-03 17:57
  • 阅读 ( 208 )
lreg1304
lreg1304

0 篇文章

相关推荐