



今天的問答環節是由SuperUser提供的,SuperUser是Stack Exchange的一個分支,是一個由社群驅動的問答網站分組。


超級使用者讀者Kunal Chopra想知道無人登入時Windows使用的是哪個帳戶:

When no one is logged into Windows and the log in screen is displayed, which user account are the current processes running under (video & sound drivers, login session, any server software, accessibility controls, etc.)? It cannot be any user or the previous user because no one is logged in.

What about processes that have been started by a user but continue to run after logging off (for example, HTTP/FTP servers and other networking processes)? Do they switch over to the SYSTEM account? If a user-started process is switched over to the SYSTEM account, then that indicates a very serious vulnerability. Does such a process run by that user continue to run under that user’s account somehow after they have logged off?

Is this why the SETHC hack allows you to use CMD as SYSTEM?




When no one is logged into Windows and the log in screen is displayed, which user account are the current processes running under (video & sound drivers, login session, any server software, accessibility controls, etc.)?

Almost all drivers run in kernel mode; they do not need an account unless they start user-space processes. Those user-space drivers run under SYSTEM.

With regard to the login session, I am sure that it uses SYSTEM as well. You can see logonui.exe using Process Hacker or SysInternals Process Explorer. In fact, you can see everything that way.

As for server software, see Windows services below.

What about processes that have been started by a user but continue to run after logging off (for example, HTTP/FTP servers and other networking processes)? Do they switch over to the SYSTEM account?

There are three kinds here:

  1. Plain Old Background Processes: These run under the same account as whoever started them and do not run after logging off. The logoff process kills them all. HTTP/FTP servers and other networking processes do not run as regular background processes. They run as services.
  2. Windows Service Processes: These are not launched directly, but via the Service Manager. By default, services run as LocalSystem (which isanae says equals SYSTEM) can have dedicated accounts configured. Of course, practically nobody bothers. They just install XAMPP, WampServer, or some other software and let it run as SYSTEM (forever unpatched). On recent Windows systems, I think services can also have their own SIDs, but again I have not done much research on this yet.
  3. Scheduled Tasks: These are launched by the Task Scheduler Service in the background and always run under the account configured in the task (usually whoever created the task).

If a user-started process is switched over to the SYSTEM account, then that indicates a very serious vulnerability.

It is not a vulnerability because you must already have Administrator privileges to install a service. Having Administrator privileges already lets you do practically everything.

See Also: Various other non-vulnerabilities of the same kind.


有什麼要補充的解釋嗎?在評論中發出聲音。想從其他精通技術的Stack Exchange使用者那裡瞭解更多答案嗎?在這裡檢視完整的討論主題。

  • 發表於 2021-04-10 04:25
  • 閱讀 ( 30 )
  • 分類:網際網路


如何重置丟失的windows 10密碼


  • 發佈於 2021-03-11 19:51
  • 閲讀 ( 50 )


...料,請單擊第一個螢幕上的下一步以使用您的帳戶。若要登入到另一個帳戶,請單擊“我不是[帳戶]”。 ...

  • 發佈於 2021-03-12 14:39
  • 閲讀 ( 51 )


...rosoft帳戶(可能您的鍵盤有卡住的鍵或類似的東西)。去登入.live.com在您的**或其他計算機上,嘗試使用您在PC上使用的Microsoft帳戶登入,確保您沒有鍵入任何錯誤。 ...

  • 發佈於 2021-03-15 03:48
  • 閲讀 ( 59 )


...應用程式並登入您的TeamViewer帳戶。 查詢“無人参與訪問”標題並單擊三個檢查中的每一個,以便使您的Mac即使在您不使用時也可用。 ...

  • 發佈於 2021-03-22 09:44
  • 閲讀 ( 59 )


... 登出並重新登入或重新啟動計算機以完成更改。 ...

  • 發佈於 2021-03-22 20:27
  • 閲讀 ( 44 )


...一個Microsoft帳戶。 請確保使用Microsoft帳戶登入Windows:轉到“開始”>“設定”>“帳戶”>“您的資訊”以更改登入方式。 註冊您的Windows 10計算機:轉到“開始”>“設定”&a...

  • 發佈於 2021-03-23 13:09
  • 閲讀 ( 52 )


...料。如果你沒有看到這個選項,你需要先用你的Google帳戶登入Chrome。 ...

  • 發佈於 2021-03-26 08:25
  • 閲讀 ( 52 )


...是GeForce體驗也是一個更重的應用程式,需要您使用帳戶登入。你甚至必須用一個帳戶登入才能獲得驅動程式更新。如果你想安裝你的驅動程式的經典方式只是驅動程式本身和NVIDIA控制面板工具你可以。 如何在沒有geforce經驗的情...

  • 發佈於 2021-04-01 23:24
  • 閲讀 ( 47 )


...請或授權支援人員親自訪問,遠端訪問工具的設計考慮到無人值守訪問。 這就是為什麼保護您的遠端訪問憑據並且永遠不要與其他人共享它們很重要的原因。如果其他人可以訪問您的機器,他們可以在您不知情的情況下輕鬆地...

  • 發佈於 2021-04-02 10:39
  • 閲讀 ( 44 )

windows 10 2020年5月更新的新增功能,現已提供

...密碼” Microsoft new允許您透過“設定”>“帳戶”>“登入”頁面上的新選項“使裝置無密碼”。這聽起來很棒,很有未來感,但實際上這只是一個新的設定,需要你電腦上的每個人都使用PIN或其他Windows Hello登入方法(如人臉...

  • 發佈於 2021-04-03 05:05
  • 閲讀 ( 59 )

0 篇文章


  1. admin 0 文章
  2. 孫小欽 0 文章
  3. JVhby0 0 文章
  4. fvpvzrr 0 文章
  5. 0sus8kksc 0 文章
  6. zsfn1903 0 文章
  7. w91395898 0 文章
  8. SuperQueen123 0 文章
