Monday, October 06, 2008   
  Search   
 
Register  Login  
Forums  
     Minimize  

Welcome to MeraWindows forums.

Thank you for being at the Microsoft Windows Community Site. You may have to register before posting in forums. It's absolutely free. After registering, you can get all the benefits available to our registered members, you can access our Downloads section, you can participate in contests, etc. You can post in forums in English as well as in Hindi, in fact we encourage you to use Hindi in your posts. If you have any problem with registration or login, please contact us.

     
  


 
  Microsoft Windows Forums  Other Windows V...  Windows XP  The Logon Process
Previous Previous
 
Next Next
New Post 7/31/2008 2:33 PM
User is offline Ritesh Kawadkar
539 posts
riteshhowto.wordpress.com
Experienced Member




The Logon Process 

The Logon Process

WinLogon

Users must log on to a Windows NT machine in order to use that NT based machine or

network. The logon process itself cannot be bypassed, it is mandatory. Once the user has

logged on, an access token is created (this token will be discussed in more detail later).

This token contains user specific security information, such as: security identifier, group

identifiers, user rights and permissions. The user, as well as all processes spawned by the

user are identified to the system with this token.

 

The first step in the WinLogon process is something we are all familiar with,

CTRL+ALT+DEL. This is NT's default Security Attention Sequence (SAS - The SAS

key combo can be changed. We will also discuss that later.). This SAS is a signal to the

operating system that someone is trying to logon. After the SAS is triggered, all user

mode applications pause until the security operation completes or is cancelled. (Note:

The SAS is not just a logon operation, this same key combination can be used for logging

on, logging off, changing a password or locking the workstation.) The pausing, or

closing, of all user mode applications during SAS is a security feature that most people

take for granted and dont understand. Due to this pausing of applications, logon related

trojan viruses are stopped, keyloggers (programs that run in memory, keeping track of

keystrokes, therefor recording someones password) are stopped as well.

 

The user name is not case sensitive but the password is.

 

After typing in your information and clicking OK (or pressing enter), the WinLogon

process supplies the information to the security subsystem, which in turn compares the

information to the Security Accounts Manager (SAM). If the information is compliant

with the information in the SAM, an access token is created for the user. The WinLogon

takes the access token and passes it onto the Win32 subsytem, which in turn starts the

operating systems shell. The shell, as well as all other spawned processes will receive a

token. This token is not only used for security, but also allows NTs auditing and logging

features to track user usage and access of network resources.

 

Note: All of the logon components are located in a file known as the Graphical

Indetification and Authentication (GINA) module, specifically MSGINA.DLL. Under

certain conditions, this file can be replaced, which is how you would change the SAS key

combination.

 

For fine tuning of the WinLogon process, you can refer to the registry. All of the options

for the WinLogon process are contained in the

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winl

ogon area. You can also fine tune the process by using the Policy Editor.

Logging on to a Domain

If an NT machine is a participant on a Domain, you would not only need to login to the

local machine, but the Domain as well. If a computer is a member of a Domain, the

WinLogon process is replaced by the NetLogon process.

 

source

The Rhino9 Team



Create your own Window Media Player Skin>
More than 100 registry TIPS n TRICKS>
 
New Post 7/31/2008 2:53 PM
User is offline Rahul Manekari
1054 posts
www.manekari.blogspot.com
MW Addict




Re: The Logon Process 

Hey .... gr8 post..

My mind contains many questions regarding logon.... And your simple post has given all the answer to the questions...


Rahul Manekari
Be live with me..Click here
 
New Post 7/31/2008 2:56 PM
User is offline Ritesh Kawadkar
539 posts
riteshhowto.wordpress.com
Experienced Member




Re: The Logon Process 

Thankz rahul



Create your own Window Media Player Skin>
More than 100 registry TIPS n TRICKS>
 
New Post 7/31/2008 5:21 PM
User is offline Hari Maurya
1153 posts
www.harimaurya.blogspot.com
MW Addict




Re: The Logon Process 

Nice article...ritesh....keep it up...


Its My World, Its Mera Windows and I proud to be a MWians
Hari Maurya
Mera Live Status, Click to Talk
 
New Post 7/31/2008 6:40 PM
User is offline Gautam
12 posts
Member


Re: The Logon Process 

dear sir

             thanks for this nice and wonderful tutorial

keep Going

Gautam

 
Previous Previous
 
Next Next
  Microsoft Windows Forums  Other Windows V...  Windows XP  The Logon Process
   Get Your Own E-Mail Account @MeraWindows.com Minimize  
New Page 1 New Page 1
Show your cool quotient with @merawindows.com email account