無人登入時,系統使用哪個windows帳戶?

如果您對Windows如何在引擎蓋下執行感到好奇和了解更多,那麼您可能會發現自己在想,當沒有人登入Windows時,哪個“帳戶”活動程序正在執行。有鑑於此,今天的超級使用者問答帖子為好奇的讀者提供了答案。...

無人登入時,系統使用哪個windows帳戶?

如果您對Windows如何在引擎蓋下執行感到好奇和了解更多,那麼您可能會發現自己在想,當沒有人登入Windows時,哪個“帳戶”活動程序正在執行。有鑑於此,今天的超級使用者問答帖子為好奇的讀者提供了答案。

今天的問答環節是由SuperUser提供的,SuperUser是Stack Exchange的一個分支,是一個由社群驅動的問答網站分組。

問題

超級使用者讀者Kunal Chopra想知道無人登入時Windows使用的是哪個帳戶:

When no one is logged into Windows and the log in screen is displayed, which user account are the current processes running under (video & sound drivers, login session, any server software, accessibility controls, etc.)? It cannot be any user or the previous user because no one is logged in.

What about processes that have been started by a user but continue to run after logging off (for example, HTTP/FTP servers and other networking processes)? Do they switch over to the SYSTEM account? If a user-started process is switched over to the SYSTEM account, then that indicates a very serious vulnerability. Does such a process run by that user continue to run under that user’s account somehow after they have logged off?

Is this why the SETHC hack allows you to use CMD as SYSTEM?

沒有人登入時,Windows使用哪個帳戶?

答案

超級使用者貢獻者grawity為我們提供了答案:

When no one is logged into Windows and the log in screen is displayed, which user account are the current processes running under (video & sound drivers, login session, any server software, accessibility controls, etc.)?

Almost all drivers run in kernel mode; they do not need an account unless they start user-space processes. Those user-space drivers run under SYSTEM.

With regard to the login session, I am sure that it uses SYSTEM as well. You can see logonui.exe using Process Hacker or SysInternals Process Explorer. In fact, you can see everything that way.

As for server software, see Windows services below.

What about processes that have been started by a user but continue to run after logging off (for example, HTTP/FTP servers and other networking processes)? Do they switch over to the SYSTEM account?

There are three kinds here:

  1. Plain Old Background Processes: These run under the same account as whoever started them and do not run after logging off. The logoff process kills them all. HTTP/FTP servers and other networking processes do not run as regular background processes. They run as services.
  2. Windows Service Processes: These are not launched directly, but via the Service Manager. By default, services run as LocalSystem (which isanae says equals SYSTEM) can have dedicated accounts configured. Of course, practically nobody bothers. They just install XAMPP, WampServer, or some other software and let it run as SYSTEM (forever unpatched). On recent Windows systems, I think services can also have their own SIDs, but again I have not done much research on this yet.
  3. Scheduled Tasks: These are launched by the Task Scheduler Service in the background and always run under the account configured in the task (usually whoever created the task).

If a user-started process is switched over to the SYSTEM account, then that indicates a very serious vulnerability.

It is not a vulnerability because you must already have Administrator privileges to install a service. Having Administrator privileges already lets you do practically everything.

See Also: Various other non-vulnerabilities of the same kind.

請務必透過下面的執行緒連結閱讀此有趣討論的其餘部分!


有什麼要補充的解釋嗎?在評論中發出聲音。想從其他精通技術的Stack Exchange使用者那裡瞭解更多答案嗎?在這裡檢視完整的討論主題。

  • 發表於 2021-04-10 04:25
  • 閱讀 ( 30 )
  • 分類:網際網路

你可能感興趣的文章

如何重置丟失的windows 10密碼

...**或其他計算機上,嘗試使用您在PC上使用的Microsoft帳戶登入。請確保您在此處鍵入的電子郵件沒有錯誤。如果您仍然無法進入,請繼續重置您的Microsoft密碼。請轉到Microsoft密碼重置頁面開始;您甚至可以在秋季建立者更新的登...

  • 發佈於 2021-03-11 19:51
  • 閲讀 ( 50 )

如何安全升級到Windows10並再次降級回Windows7或8.1

...料,請單擊第一個螢幕上的下一步以使用您的帳戶。若要登入到另一個帳戶,請單擊“我不是[帳戶]”。 ...

  • 發佈於 2021-03-12 14:39
  • 閲讀 ( 51 )

重置忘記的windows管理員密碼的3種方法

...rosoft帳戶(可能您的鍵盤有卡住的鍵或類似的東西)。去登入.live.com在您的**或其他計算機上,嘗試使用您在PC上使用的Microsoft帳戶登入,確保您沒有鍵入任何錯誤。 ...

  • 發佈於 2021-03-15 03:48
  • 閲讀 ( 59 )

如何遠端訪問mac

...應用程式並登入您的TeamViewer帳戶。 查詢“無人参與訪問”標題並單擊三個檢查中的每一個,以便使您的Mac即使在您不使用時也可用。 ...

  • 發佈於 2021-03-22 09:44
  • 閲讀 ( 59 )

如何在Windows10中禁用對設定應用程式和控制面板的訪問

... 登出並重新登入或重新啟動計算機以完成更改。 ...

  • 發佈於 2021-03-22 20:27
  • 閲讀 ( 44 )

如何(不)升級到最新的windows10版本

...一個Microsoft帳戶。 請確保使用Microsoft帳戶登入Windows:轉到“開始”>“設定”>“帳戶”>“您的資訊”以更改登入方式。 註冊您的Windows 10計算機:轉到“開始”>“設定”&a...

  • 發佈於 2021-03-23 13:09
  • 閲讀 ( 52 )

連續性備選方案:5款android最佳windows程式

...料。如果你沒有看到這個選項,你需要先用你的Google帳戶登入Chrome。 ...

  • 發佈於 2021-03-26 08:25
  • 閲讀 ( 52 )

如何下載沒有geforce經驗的nvidia驅動程式

...是GeForce體驗也是一個更重的應用程式,需要您使用帳戶登入。你甚至必須用一個帳戶登入才能獲得驅動程式更新。如果你想安裝你的驅動程式的經典方式只是驅動程式本身和NVIDIA控制面板工具你可以。 如何在沒有geforce經驗的情...

  • 發佈於 2021-04-01 23:24
  • 閲讀 ( 47 )

5個免費遠端訪問工具,用於連線pc或mac

...請或授權支援人員親自訪問,遠端訪問工具的設計考慮到無人值守訪問。 這就是為什麼保護您的遠端訪問憑據並且永遠不要與其他人共享它們很重要的原因。如果其他人可以訪問您的機器,他們可以在您不知情的情況下輕鬆地...

  • 發佈於 2021-04-02 10:39
  • 閲讀 ( 44 )

windows 10 2020年5月更新的新增功能,現已提供

...密碼” Microsoft new允許您透過“設定”>“帳戶”>“登入”頁面上的新選項“使裝置無密碼”。這聽起來很棒,很有未來感,但實際上這只是一個新的設定,需要你電腦上的每個人都使用PIN或其他Windows Hello登入方法(如人臉...

  • 發佈於 2021-04-03 05:05
  • 閲讀 ( 59 )
lreg1304
lreg1304

0 篇文章

作家榜

  1. admin 0 文章
  2. 孫小欽 0 文章
  3. JVhby0 0 文章
  4. fvpvzrr 0 文章
  5. 0sus8kksc 0 文章
  6. zsfn1903 0 文章
  7. w91395898 0 文章
  8. SuperQueen123 0 文章

相關推薦