2.2 KiB
2.2 KiB
title, type, permalink, stable_id, scope, memory_type, project_id, usage_profile_id, status, revision, request_id, created_at, updated_at
| title | type | permalink | stable_id | scope | memory_type | project_id | usage_profile_id | status | revision | request_id | created_at | updated_at |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| forum-winlogon(Gitee lieranhuasha/winlogon)Rust Credential Provider 原型验证结论 | experience | main/projects/ea207d36-693c-4349-b3c8-7c40c8c889f5/forum-winlogon-gitee-lieranhuasha-winlogon-rust-credential-provider-原型验证结论 | 67499b3a-97a6-4982-9c16-4afaa59d45f3 | project | experience | ea207d36-693c-4349-b3c8-7c40c8c889f5 | 7aee455b-24cc-4008-bdaf-443721e6f939 | active | 1 | winunlock-exp-forumwinlogon-20260819a | 2026-08-19T09:45:16.705852+00:00 | 2026-08-19T09:45:16.705852+00:00 |
来源:吾爱破解帖 52pojie thread-2083713;Gitee git clone https://gitee.com/lieranhuasha/winlogon.git。本地参考副本在 C:\Users\Administrator\AppData\Local\Temp\winunlock-research\forum-winlogon(同目录另有 hodor(C++工程化参考)、rust-cp-sample)。
验证结论(用 rustc/cargo 1.94.1 + x86_64-pc-windows-msvc 实测):
- 能编译,产出 winlogon.dll(~256KB)。dumpbin /exports 确认正确导出 DllGetClassObject / DllCanUnloadNow / DllMain —— 因为 Rust cdylib 会自动导出 #[no_mangle] pub extern 函数。
- Cargo.toml 里写的 [target.x86_64-pc-windows-msvc] rustflags = /DEF:exports.def 是无效键(cargo 明确警告 unused manifest key,rustflags 应放 .cargo/config.toml),但因 cdylib 自动导出,不影响结果;说明作者构建理解有偏差。
- 缺陷1:DllMain 硬编码日志路径 D:\log\winlogon.log 且用 .expect(),D:\log 不存在时 DLL 被 LogonUI 加载即 panic。
- 缺陷2:README 全是 Gitee 模板占位符;命名不规范、有死代码。定性=可行的教学原型,验证了『命名管道 + Credential Provider + CredPackAuthenticationBufferW 序列化给 LSA』路线,但非拿来即用成品。
用法(测试.txt):DLL 加载后监听命名管道 \.\pipe\MansonWindowsUnlockRust;外部脚本按 UTF-16LE 依次写用户名(.\机器名 格式,如 .\OMEN)与密码即可解锁。
关键教训(新实现须规避):DllMain 绝不 panic;日志路径不硬编码;管道要带长度前缀协议;管道 ACL 拒绝远程;只在 UNLOCK 场景激活;密码用完 zeroize。