WinStationSwitchToServicesSession

Accessing Session 0 on demand via the command line (Interactive Services Detection)

Windows Vista introduced us to the concept of Session 0 Isolation. This was in response to the need to isolate highly privileged service applications from malicious applications running in user space. These malicious applications would attempt to inject arbitrary code via into the service application via the application’s message loop. These attacks are classified as shatter attacks. The net effect of this is that interactive Windows services are only available on Session o (or the Console session). When you log on to your Vista, 2008 or Windows 7 machine you now no longer login to Session 0 but into Session 1.

Session 0 Isolation becomes problematic when attempting to run applications under FireDaemon as the interactive component (ie. the application’s “visible” GUI) is no longer visible on the currently logged on session. Luckily Microsoft supplies the Interactive Services Detection Service on Windows Vista, 2008 and 7 to allow you access to Session 0 so you can interact with any interactive services (including FireDaemon ones) running on that session. › Continue reading

Tags: , , , , , , , ,

Monday, August 10th, 2009 FireDaemon Tips & Tricks 2 Comments

Translate

EnglishFrenchGermanItalianPortugueseRussianSpanish

Find us on Facebook