Files
MemRelay/projects/ea207d36-693c-4349-b3c8-7c40c8c889f5/forum-winlogon(Gitee lieranhuasha-winlogon)Rust Credential Provider 原型验证结论.md
T

26 lines
2.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: forum-winlogon(Gitee lieranhuasha/winlogon)Rust Credential Provider 原型验证结论
type: experience
permalink: main/projects/ea207d36-693c-4349-b3c8-7c40c8c889f5/forum-winlogon-gitee-lieranhuasha-winlogon-rust-credential-provider-原型验证结论
stable_id: 67499b3a-97a6-4982-9c16-4afaa59d45f3
scope: project
project_id: ea207d36-693c-4349-b3c8-7c40c8c889f5
memory_type: experience
status: active
revision: 1
restored_from_commit: 6a6a895eafcca6052e81a14fca103a42635dd1c2
created_at: '2026-09-23T15:12:19.064069+00:00'
updated_at: '2026-09-23T15:12:19.064125+00:00'
---
来源:吾爱破解帖 52pojie thread-2083713;Gitee git clone https://gitee.com/lieranhuasha/winlogon.git。本地参考副本在 C:\Users\Administrator\AppData\Local\Temp\winunlock-research\forum-winlogon(同目录另有 hodor(C++工程化参考)、rust-cp-sample)。
验证结论(用 rustc/cargo 1.94.1 + x86_64-pc-windows-msvc 实测):
- 能编译,产出 winlogon.dll(~256KB)。dumpbin /exports 确认正确导出 DllGetClassObject / DllCanUnloadNow / DllMain —— 因为 Rust cdylib 会自动导出 #[no_mangle] pub extern 函数。
- Cargo.toml 里写的 [target.x86_64-pc-windows-msvc] rustflags = /DEF:exports.def 是无效键(cargo 明确警告 unused manifest key,rustflags 应放 .cargo/config.toml),但因 cdylib 自动导出,不影响结果;说明作者构建理解有偏差。
- 缺陷1:DllMain 硬编码日志路径 D:\log\winlogon.log 且用 .expect(),D:\log 不存在时 DLL 被 LogonUI 加载即 panic。
- 缺陷2:README 全是 Gitee 模板占位符;命名不规范、有死代码。定性=可行的教学原型,验证了『命名管道 + Credential Provider + CredPackAuthenticationBufferW 序列化给 LSA』路线,但非拿来即用成品。
用法(测试.txt):DLL 加载后监听命名管道 \\.\pipe\MansonWindowsUnlockRust;外部脚本按 UTF-16LE 依次写用户名(.\机器名 格式,如 .\OMEN)与密码即可解锁。
关键教训(新实现须规避):DllMain 绝不 panic;日志路径不硬编码;管道要带长度前缀协议;管道 ACL 拒绝远程;只在 UNLOCK 场景激活;密码用完 zeroize。