Skip to main content

Windows Security

Security Architecture of Windows

 There are three components of Windows Security:
 LSA (Local Security Authority)
 SAM (Security Account Manager)
 SRM (Security Reference Monitor)


LSA (Local Security Authority)

 LSA is the Central Part of NT Security. It is also known as Security Subsystem. The Local Security Authority or LSA is
a key component of the logon process in both Windows NT and Windows 2000. In Windows 2000, the LSA is
responsible for validating users for both local and remote logons. The LSA also maintains the local security policy.

 During the local logon to a machine, a person enters his name and password to the logon dialog. This information
is passed to the LSA, which then calls the appropriate authentication package. The password is sent in a nonreversible
secret key format using a one-way hash function. The LSA then queries the SAM database for the User’s
account information. If the key provided matches the one in the SAM, the SAM returns the users SID and the SIDs
of any groups the user belongs to. The LSA then uses these SIDs to generate the security access token.

SAM (Security Account Manager)

 The Security Accounts Manager is a database in the Windows operating system (OS) that contains user names and
passwords. SAM is part of the registry and can be found on the hard disk.

 This service is responsible for making the connection to the SAM database (Contains available user-accounts and
groups). The SAM database can either be placed in the local registry or in the Active Directory (If available). When
the service has made the connection it announces to the system that the SAM-database is available, so other
services can start accessing the SAM-database.

 In the SAM, each user account can be assigned a Windows password which is in encrypted form. If someone
attempts to log on to the system and the user name and associated passwords match an entry in the SAM, a
sequence of events takes place ultimately allowing that person access to the system. If the user name or
passwords do not properly match any entry in the SAM, an error message is returned requesting that the
information be entered again.

 When you make a New User Account with a Password, it gets stored in the SAM File.

 Windows Security Files are located at

             “C:\Windows\System32\Config\SAM”

 The moment operating system starts, the SAM file becomes inaccessible.

SRM (Security Reference Monitor)

 The Security Reference Monitor is a security architecture component that is used to control user requests to
access objects in the system. The SRM enforces the access validation and audit generation. Windows NT forbids
the direct access to objects. Any access to an object must first be validated by the SRM. For example, if a user
wants to access a specific file the SRM will be used to validate the request. The Security Reference Monitor
enforces access validation and audit generation policy.

 The reference monitor verifies the nature of the request against a table of allowable access types for each process
on the system. For example, Windows 3.x and 9x operating systems were not built with a reference monitor,
whereas the Windows NT line, which also includes Windows 2000 and Windows XP, was designed with an entirely
different architecture and does contain a reference monitor.

Windows user account architecture

 User account passwords are contained in the SAM in the Hexadecimal Format called Hashes.

 Once the Passwords converted in Hashes, you cannot convert back to the Clear Text.



Comments

Popular posts from this blog

How To Grab Someone's IP Address ?

In this tutorial I will you show you how to grab someone’s IP address using  PHP script.  This method can be used to grab someone Ip address on yahoo or Facebook  chat  or by sending mail to victim. So Lets get started. How To  Hack  Someone Ip Address ? 1. Copy the below codes into  Notepad  and save it as  Grab.php  (.php is must)  <?php $hostname = gethostbyaddr($_SERVER['REMOTE_ADDR']); $img_number = imagecreate(400,95); $backcolor = imagecolorallocate($img_number,10,102,153); $textcolor = imagecolorallocate($img_number,255,255,255); imagefill($img_number,0,0,$backcolor); $number0 = " This is Your IP/Proxy"; $number1 = " IP: $_SERVER[HTTP_X_FORWARDED_FOR]"; $number2 = " Host/Proxy: $hostname"; $number4 = " _________________________________"; Imagestring($img_number,10,5,5,$number0,$textcolor); Imagestring($img_number,10,5,25,$number1,$textcolor); Imagestring($img_number,10,5,45,$number2,$textcolor); Imagestring...

How to Trace Any IP Address

How to Trace the IP Address Back to the Source? In fact, tracing an IP address back to its location is a lot simpler than what many people imagine. There exists many online tools using which you can accomplish this job. One of my favorite site is  IP2Location.com . Just go to  http://www.ip2location.com/demo.aspx  and enter the IP address that you want to trace in the dialog box and click on “Find Location”‘. With just a click of a button you can find the following information for any given IP address: Country  in which the IP is located City  to which the IP address belongs to Latitude/Longitude  of the IP’s location Zip Code  of the region to which the IP belongs to Time Zone  associated with the IP Name of the ISP  to which the IP address belong to Internet Speed  of the computer associated with the IP Weather Station  associated with the region of the IP Domain name  associated with the I...

How to Prevent Your Computer from Overheating (and Why It's Important)

Keeping your computer running within safe temperatures is important, especially as the temperature rises outside. Here's how to make sure your computer's not overheating—and how to fix it if it is. The cooling system of your computer is one of the most important features of the device. Without the cooling system, the electrical components of your computer wouldn't be able to function; overheating would damage the integral parts of what makes your computer work. The heat has to be dissipated in order to keep everything working within safe operating temperatures Why an Overheated Computer Is Dangerous Simply put, if your computer becomes too hot, it is possible to destroy and shorten the lifespan of the hardware inside your computer, leading to irreparable damage and potential data loss. Besides losing your data, heat pecks away at your computer's internal organs—the motherboard, CPU, and more—significantly shortening its lifespan. Besides the most obvious rea...