C++Talk.NET Forum Index C++Talk.NET
C++ language newsgroups
 
Archives   FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

WlxLoggedOnSAS called from Winlogon while WlxWkStaLockedSAS

 
Post new topic   Reply to topic    C++Talk.NET Forum Index -> C++ language (comp.lang.c++)
View previous topic :: View next topic  
Author Message
Igor Jovanovski
Guest





PostPosted: Thu Sep 23, 2004 8:23 am    Post subject: WlxLoggedOnSAS called from Winlogon while WlxWkStaLockedSAS Reply with quote



We have a cascaded GINA for 2K and XP wich provides our proprietery
Smart Card authentication. While unlocking the workstation with a
Smart Card there is an amount of data (filestructure on smartcard
etc.) that need to be read of the card. because of that in the call to
WlxWkstaLockedSAS before reading the data I call
WlxDisplayStatusMessage saying something like "please wait ..
connecting to the SC" after the heavy smartcard part is done there is
a call to WlxRemoveStatusMessage to remove that message.
The interesting part is that if while the message is displayed the
user is quick enough and hits Ctrl+Alt+Del the workstation gets
unlocked!!

I traced and I can see that right after the finishing of the call to
WlxRemoveStatusMessage (so we are still in WlxWkstaLockedSAS)
WlxLoggedOnSAS gets called. There I see an abnormall situation
(WlxLoggedOnSAS should only be called while we are logged in and have
the session not while lockedworkstation) and return
WLX_SAS_ACTION_NONE what results in user getting the active user
session.
The method WlxLoggedOnSAS should not be called from Winlogon in this
state at all, or? This is a big security problem since the user can login
without providing credentials.

If the calls to WlxRemoveStatusMessage (or WlxDisplayStatusMessage
and WlxRemoveStatusMessage) is commented out the problem is not
reproducable.

I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.

Igi
Back to top
Sharad Kala
Guest





PostPosted: Thu Sep 23, 2004 8:27 am    Post subject: Re: WlxLoggedOnSAS called from Winlogon while WlxWkStaLocked Reply with quote




"Igor Jovanovski" <igorjovanovski (AT) yahoo (DOT) com> wrote in message

Quote:
I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.

Sorry but your question is off-topic here. You should try asking on MS
newsgroups at msnews.microsoft.com.




Back to top
Richard Lewis Haggard
Guest





PostPosted: Fri Nov 12, 2004 1:41 am    Post subject: Re: WlxLoggedOnSAS called from Winlogon while WlxWkStaLocked Reply with quote



What newsgroup are you referring to?
==
rlh

"Sharad Kala" <no__spam.sharadk_ind (AT) yahoo (DOT) com> wrote

Quote:

"Igor Jovanovski" <igorjovanovski (AT) yahoo (DOT) com> wrote in message

I hope I have done something wrong but this code has worked perfect
for several years until one very quick user reported this. What can be
the reason for this call from Winlogon to WlxLoggedOnSAS at this stage
(WlxWkstaLockedSAS )? Any help will be appreciated.

Sorry but your question is off-topic here. You should try asking on MS
newsgroups at msnews.microsoft.com.






Back to top
Display posts from previous:   
Post new topic   Reply to topic    C++Talk.NET Forum Index -> C++ language (comp.lang.c++) All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2006 phpBB Group
SEO toolkit © 2004-2006 webmedic.