It's Day Two of our series of Windows Server 2008 posts. Only twenty-five more days to go till the big launch. Today's topics are Startup Processes and Delayed Automatic Start for System Services.
In previous versions of Windows, during system boot, the Session Manager process (SMSS.EXE) would start the Client-Server Runtime Subsystem (CSRSS.EXE), and the logon process (WINLOGON.EXE). The Winlogon process would then launch the Local Security Authority Subsystem Service, better known as LSASS.EXE and the Service Control Manager (SERVICES.EXE). The user logged into the console would be logged into Session 0, which is the shared session used by system processes. One security risk was that if a poorly written Windows service running in Session 0 displayed a user interface on the interactive console, malware could attack the window using windows messages and possibly gain administrative privileges to the system.
|