This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+49 -49
View File
@@ -4,33 +4,33 @@ Windows Architecture
![1646408037.png](img/1646408037.png)
Note: windows has `kernel mode drivers` and `user mode drivers`
Note: Windows has `kernel mode drivers` and `user mode drivers`
### Security Subsystem
- Runs in user mode
- `Logon` processes (`winlogon`, `LogonUI`)
- Local security authority (`LSA`)
- Checks Users accounts
- Provides access token
- Responsible for auditing
- Checks users’ accounts
- Provides access token
- Responsible for auditing
- Security Account manager (`SAM`)
- Maintains user account database used by `LSA`
- Encrypts / hashes passwords
- Maintains user account database used by `LSA`
- Encrypts / hashes passwords
- Windows predominantly uses **Access Control Lists**, and has done since Windows NT
- Extends the usual read, write and execute with:
- Take ownership
- Change permissions
- Delete
- This allows finer control over files for example a user will be able to read a file but not delete it
- Take ownership
- Change permissions
- Delete
- This allows finer control over files for example a user will be able to read a file but not delete it
- 32-bit access masks (unlike Unix’s 9 bits)
- A higher degree of control, with the associated complexity increase
### Access Control Matrix
- Access rights are defined individually for each combination of subject and object
- Quite an abstract concept, bit would allow for very fine grained control
- Not practical, think of the memory required in scaling it up
- Quite an abstract concept, but would allow for very fine-grained control
- Not practical, think of the memory required in scaling it up
![1646409469.png](img/1646409469.png)
@@ -52,41 +52,41 @@ The access control list can be found by right clicking on a file -> properties -
### Access Control
- Access control in windows treats more than just files, also:
- Registry keys
- Active directory objects
- Groups
- Access control in Windows treats more than just files, also:
- Registry keys
- Active directory objects
- Groups
- Inheritance is implemented
- File can inherit ACLs from parent directories
- File can inherit ACLs from parent directories
#### Principles
#### Principals
- Principles are more broadly defined as well:
- Principals are more broadly defined as well:
- Local users
- Domain users
- Groups
- Machines
Each principles has a human readable name and security ID (`SID`)
Each principal has a human-readable name and security ID (`SID`)
```
S-1-5-21-2475811070-2421845406-3333283485-1005
S-1-5-21-1664130791-3153540899-3044996548-279530
```
These are examples of `SID` from windows, but why are they so long?
These are examples of `SID` from Windows, but why are they so long?
This is a form of future proofing. Imagine company A buys company B, you can merge the users onto one active directory without two `SID`s clashing. (also 96 bits of memory isn’t a lot in the grand scheme of things)
##### Local / Domain Principles
##### Local / Domain Principals
- LSA creates local principles
- principle = `MACHINE\principal`
- Domain principles adminstered on DC by domain admins
- principle@domain = DOMAIN\principle
- net user /domain
- net group /domain
- net localgroup /domain
- LSA creates local principals
- principal = `MACHINE\principal`
- Domain principals administered on DC by domain admins
- principal@domain = DOMAIN\principal
- net user /domain
- net group /domain
- net localgroup /domain
#### Groups
@@ -99,16 +99,16 @@ This is a form of future proofing. Imagine company A buys company B, you can mer
#### Objects
- Objects are passive entities in access operations
- In windows:
- Executive objects (processes, threads, etc)
- Private objects (files, directories)
- In Windows:
- Executive objects (processes, threads, etc)
- Private objects (files, directories)
- Securable objects have a security descriptor
- Built-in securable objects managed by the OS
- Private objects managed by the application software
- Built-in securable objects managed by the OS
- Private objects managed by the application software
### Access Tokens
- Instead of passing a number as in linux, we pass an access token
- Instead of passing a number as in Linux, we pass an access token
- It is the security credentials for a login session stored in the **access token**
- Identifies the user, the user’s groups, and the user’s privileges
@@ -116,33 +116,33 @@ This is a form of future proofing. Imagine company A buys company B, you can mer
- Windows subjects: Processes and threads
- New processes get a **copy** of the parent access token, possibly modified
- Individual access token are immutable and can live beyond policy changes
- The access token checked is the one given at login, not the current access token
- This is a TOCTTOU issue (Time-of-check to Time-of-use)
- Admins can force a user to logoff to update their access token
- Individual access tokens are immutable and can live beyond policy changes
- The access token checked is the one given at login, not the current access token
- This is a TOCTTOU issue (Time-of-check to Time-of-use)
- Admins can force a user to log off to update their access token
### User Account Control
- After Vista, administrator users do not use an administrative access token by default
- Users have two tokens, one heavily restricted and used by default
- A prompt allows a user to spawn a process with the adminstrative token, or switch a process’ token.
- Similar to `sudo`
- Can be swapped mid-execution
- A prompt allows a user to spawn a process with the administrative token, or switch a process’ token.
- Similar to `sudo`
- Can be swapped mid-execution
#### Domains
- Single sing-on for network resources
- Single sign-on for network resources
- Centralised security administration
- Domain controller (DC)
- Handles user accounts and access control
- Trusted 3rd party for authentication
- Handles user accounts and access control
- Trusted 3rd party for authentication
- Multiple DCs allow for decentralisation by design
#### Interactive Logon
- The windows interactive logon allows a user to authenticate
- The Windows interactive logon allows a user to authenticate
- Windows logon begins with the Secure Attention Sequence `Ctrl+Alt+Del`
- Can prevent spoofing - is tied directly to `winlogon`
- Can prevent spoofing - is tied directly to `winlogon`
- The logon process differs slightly for local and domain authentication
##### Local Logon
@@ -150,7 +150,7 @@ This is a form of future proofing. Imagine company A buys company B, you can mer
1. `Ctrl+Alt+Del` initiates a login prompt using `GINA`
2. These collect credentials which are passed to the `LSA`
3. The `LSA` uses `NTLM` to check the credentials against the `SAM` database
4. Successful login an access token, which is used to spawn a shell (explorer.exe)
4. Successful login produces an access token, which is used to spawn a shell (explorer.exe)
![1646411476.png](img/1646411476.png)
@@ -160,4 +160,4 @@ This is a form of future proofing. Imagine company A buys company B, you can mer
- Replaces `SAM` with an Active Directory Domain Controller
- Checks of a user are now performed on the remote `LSA`
![1646411494.png](img/1646411494.png)
![1646411494.png](img/1646411494.png)