473,383 Members | 1,837 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,383 software developers and data experts.

WlxLoggedOnSAS called from Winlogon while WlxWkStaLockedSAS still executing

We have a cascaded GINA for 2K and XP wich provides our proprietery
Smart Card authentication. While unlocking the workstation with a
Smart Card there is an amount of data (filestructure on smartcard
etc.) that need to be read of the card. because of that in the call to
WlxWkstaLockedSAS before reading the data I call
WlxDisplayStatusMessage saying something like "please wait ..
connecting to the SC" after the heavy smartcard part is done there is
a call to WlxRemoveStatusMessage to remove that message.
The interesting part is that if while the message is displayed the
user is quick enough and hits Ctrl+Alt+Del the workstation gets
unlocked!!

I traced and I can see that right after the finishing of the call to
WlxRemoveStatusMessage (so we are still in WlxWkstaLockedSAS)
WlxLoggedOnSAS gets called. There I see an abnormall situation
(WlxLoggedOnSAS should only be called while we are logged in and have
the session not while lockedworkstation) and return
WLX_SAS_ACTION_NONE what results in user getting the active user
session.
The method WlxLoggedOnSAS should not be called from Winlogon in this
state at all, or? This is a big security problem since the user can login
without providing credentials.

If the calls to WlxRemoveStatusMessage (or WlxDisplayStatusMessage
and WlxRemoveStatusMessage) is commented out the problem is not
reproducable.

I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.

Igi
Nov 22 '05 #1
3 2106

"Igor Jovanovski" <ig************@yahoo.com> wrote in message
I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.


Sorry but your question is off-topic here. You should try asking on MS
newsgroups at msnews.microsoft.com.

Nov 22 '05 #2
What newsgroup are you referring to?
==
rlh

"Sharad Kala" <no******************@yahoo.com> wrote in message
news:2r*************@uni-berlin.de...

"Igor Jovanovski" <ig************@yahoo.com> wrote in message
I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.


Sorry but your question is off-topic here. You should try asking on MS
newsgroups at msnews.microsoft.com.

Nov 22 '05 #3
What newsgroup are you referring to?
==
rlh

"Sharad Kala" <no******************@yahoo.com> wrote in message
news:2r*************@uni-berlin.de...

"Igor Jovanovski" <ig************@yahoo.com> wrote in message
I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.


Sorry but your question is off-topic here. You should try asking on MS
newsgroups at msnews.microsoft.com.

Nov 22 '05 #4

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

2
by: Michal Wargacki | last post by:
Hi, Is it possible to call c# class methods from within my custom gina.dll (winlogon enviroment) ? Have you ever faced similar problem? Particularly, I'd like to call xml web services methods...
2
by: Igor Jovanovski | last post by:
We have a cascaded GINA for 2K and XP wich provides our proprietery Smart Card authentication. While unlocking the workstation with a Smart Card there is an amount of data (filestructure on...
0
by: Cris | last post by:
Hello All.. We are attempting to load a .Net assembly DLL from a GINA (Winlogon) DLL. This is a C# DLL, signed and GAC'ed. In Windows XP, this works fine. In Windows 2000 however, we get...
3
by: Shannon McMillan | last post by:
Hey, I want to change the name and workgroup/domain of a computer at first boot prior to winlogon. I've written code that will successfully change the computer's name and workgroup/domain, but...
0
by: Robert Scarab | last post by:
I've added a entry to the registry to recieve logon events from Winlogon. In the WLX_NOTIFICATION_INFO control block there is a member nToken which contains a handle to the newly logged in user. I...
7
by: tshad | last post by:
I thought I understood how the SaveViewState is working and was trying to use this (as per some code I found) to detect refreshes. It seemed to be working but I found that the SaveViewState was...
8
by: lovecreatesbea... | last post by:
K&R 2, sec 2.4 says: If the variable in question is not automatic, the initialization is done once only, conceptually before the program starts executing, ... . "Non-automatic variables are...
5
by: reycri | last post by:
Hi, I need to be able to do this: var func = new Function("var me = <selfRef>; alert(me.params);"); func.params = "This is a test parameter"; window.setTimeout(func, 500); Basically, I...
3
by: Kirk | last post by:
Let me start by saying that I am a complete idiot when it comes to JS. However, I need help with something that apparently can only be done this way. I am using an ASP.NET AJAX control...
0
by: =?Utf-8?B?UmFuZ2VyODAx?= | last post by:
Hi All My virus software detected a trojan horse virus in the smss.exe and winlogon.exe files that were located in my C:\Program Files\Common Files\ Since then I can no longer log onto my MS...
1
by: CloudSolutions | last post by:
Introduction: For many beginners and individual users, requiring a credit card and email registration may pose a barrier when starting to use cloud servers. However, some cloud server providers now...
0
by: Faith0G | last post by:
I am starting a new it consulting business and it's been a while since I setup a new website. Is wordpress still the best web based software for hosting a 5 page website? The webpages will be...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 3 Apr 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome former...
0
by: ryjfgjl | last post by:
In our work, we often need to import Excel data into databases (such as MySQL, SQL Server, Oracle) for data analysis and processing. Usually, we use database tools like Navicat or the Excel import...
0
by: Charles Arthur | last post by:
How do i turn on java script on a villaon, callus and itel keypad mobile phone
0
by: ryjfgjl | last post by:
If we have dozens or hundreds of excel to import into the database, if we use the excel import function provided by database editors such as navicat, it will be extremely tedious and time-consuming...
0
by: ryjfgjl | last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.