首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >如何使用C#/ SendInput到WinSta0 0\Winlogon桌面

如何使用C#/ SendInput到WinSta0 0\Winlogon桌面
EN

Stack Overflow用户
提问于 2017-01-29 19:11:47
回答 1查看 3K关注 0票数 3

我正在用C#为一套技术支持工具编写一个远程控制应用程序。除了我无法在Winlogon桌面上使用SendInput之外,一切都很好。我正在成功地检测到从默认到Winlogon的更改,并且能够切换到它并捕获屏幕截图。它只是不接受SendInput函数。我知道这是可能的,因为TeamViewer做到了,而且他们的清单中没有uiAccess=true。他们似乎在使用我同样的程序

简单地说,我正在做的事情是:安装服务。服务侦听连接请求。服务使用CreateProcessAsUser在用户会话中启动新进程,并从winlogon.exe启动一个重复的访问令牌。查看器连接到新进程。

有人能识别出新进程访问SendInput来登录时缺少什么吗?下面是我用来从服务中启动新进程的代码。接下来是用于检测对Winlogon桌面的更改并切换到它的代码。

代码语言:javascript
复制
public static bool OpenProcessAsSystem(string applicationName, out PROCESS_INFORMATION procInfo)
{
    try
    {

        uint winlogonPid = 0;
        IntPtr hUserTokenDup = IntPtr.Zero, hPToken = IntPtr.Zero, hProcess = IntPtr.Zero;
        procInfo = new PROCESS_INFORMATION();

        // Obtain session ID for active session.
        uint dwSessionId = Kernel32.WTSGetActiveConsoleSessionId();

        // Check for RDP session.  If active, use that session ID instead.
        var rdpSessionID = GetRDPSession();
        if (rdpSessionID > 0)
        {
            dwSessionId = rdpSessionID;
        }

        // Obtain the process ID of the winlogon process that is running within the currently active session.
        Process[] processes = Process.GetProcessesByName("winlogon");
        foreach (Process p in processes)
        {
            if ((uint)p.SessionId == dwSessionId)
            {
                winlogonPid = (uint)p.Id;
            }
        }

        // Obtain a handle to the winlogon process.
        hProcess = Kernel32.OpenProcess(MAXIMUM_ALLOWED, false, winlogonPid);

        // Obtain a handle to the access token of the winlogon process.
        if (!OpenProcessToken(hProcess, TOKEN_DUPLICATE, ref hPToken))
        {
            Kernel32.CloseHandle(hProcess);
            return false;
        }

        // Security attibute structure used in DuplicateTokenEx and CreateProcessAsUser.
        SECURITY_ATTRIBUTES sa = new SECURITY_ATTRIBUTES();
        sa.Length = Marshal.SizeOf(sa);

        // Copy the access token of the winlogon process; the newly created token will be a primary token.
        if (!DuplicateTokenEx(hPToken, MAXIMUM_ALLOWED, ref sa, (int)SECURITY_IMPERSONATION_LEVEL.SecurityIdentification, (int)TOKEN_TYPE.TokenPrimary, ref hUserTokenDup))
        {
            Kernel32.CloseHandle(hProcess);
            Kernel32.CloseHandle(hPToken);
            return false;
        }

        // By default, CreateProcessAsUser creates a process on a non-interactive window station, meaning
        // the window station has a desktop that is invisible and the process is incapable of receiving
        // user input. To remedy this we set the lpDesktop parameter to indicate we want to enable user 
        // interaction with the new process.
        STARTUPINFO si = new STARTUPINFO();
        si.cb = (int)Marshal.SizeOf(si);
        si.lpDesktop = @"winsta0\default"; // interactive window station parameter; basically this indicates that the process created can display a GUI on the desktop

        // flags that specify the priority and creation method of the process
        uint dwCreationFlags = NORMAL_PRIORITY_CLASS | CREATE_NEW_CONSOLE;

        // create a new process in the current user's logon session
        bool result = CreateProcessAsUser(hUserTokenDup,        // client's access token
                                        null,                   // file to execute
                                        applicationName,        // command line
                                        ref sa,                 // pointer to process SECURITY_ATTRIBUTES
                                        ref sa,                 // pointer to thread SECURITY_ATTRIBUTES
                                        false,                  // handles are not inheritable
                                        dwCreationFlags,        // creation flags
                                        IntPtr.Zero,            // pointer to new environment block 
                                        null,                   // name of current directory 
                                        ref si,                 // pointer to STARTUPINFO structure
                                        out procInfo            // receives information about new process
                                        );

        // invalidate the handles
        Kernel32.CloseHandle(hProcess);
        Kernel32.CloseHandle(hPToken);
        Kernel32.CloseHandle(hUserTokenDup);

        return result;
    }
    catch
    {
        procInfo = new PROCESS_INFORMATION() { };
        return false;
    }
}
public static uint GetRDPSession()
{
    IntPtr ppSessionInfo = IntPtr.Zero;
    Int32 count = 0;
    Int32 retval = WTSAPI32.WTSEnumerateSessions(WTSAPI32.WTS_CURRENT_SERVER_HANDLE, 0, 1, ref ppSessionInfo, ref count);
    Int32 dataSize = Marshal.SizeOf(typeof(WTSAPI32.WTS_SESSION_INFO));
    var sessList = new List<WTSAPI32.WTS_SESSION_INFO>();
    Int64 current = (int)ppSessionInfo;

    if (retval != 0)
    {
        for (int i = 0; i < count; i++)
        {
            WTSAPI32.WTS_SESSION_INFO sessInf = (WTSAPI32.WTS_SESSION_INFO)Marshal.PtrToStructure((System.IntPtr)current, typeof(WTSAPI32.WTS_SESSION_INFO));
            current += dataSize;
            sessList.Add(sessInf);
        }
    }
    uint retVal = 0;
    var rdpSession = sessList.Find(ses => ses.pWinStationName.ToLower().Contains("rdp") && ses.State == 0);
    if (sessList.Exists(ses => ses.pWinStationName.ToLower().Contains("rdp") && ses.State == 0))
    {
        retVal = (uint)rdpSession.SessionID;
    }
    return retVal;
}

下面是我用来捕捉屏幕、检测桌面更改并切换到它的内容。

代码语言:javascript
复制
var hWnd = User32.GetDesktopWindow();
var hDC = User32.GetWindowDC(hWnd);
var graphDC = graphic.GetHdc();
var copyResult = GDI32.BitBlt(graphDC, 0, 0, totalWidth, totalHeight, hDC, 0, 0, GDI32.TernaryRasterOperations.SRCCOPY | GDI32.TernaryRasterOperations.CAPTUREBLT);
// Change to input desktop if copy fails.
if (!copyResult)
{
     var inputDesktop = User32.OpenInputDesktop();
     if (User32.SetThreadDesktop(inputDesktop) == false)
     {
         graphic.Clear(System.Drawing.Color.White);
         var font = new Font(FontFamily.GenericSansSerif, 30, System.Drawing.FontStyle.Bold);
         graphic.DrawString("Waiting for screen capture...", font, Brushes.Black, new PointF((totalWidth / 2), totalHeight / 2), new StringFormat() { Alignment = StringAlignment.Center });
         var error = Marshal.GetLastWin32Error();
         writeToErrorLog(new Exception("Failed to open input desktop.  Error: " + error.ToString()));
    }
    var dw = User32.GetDesktopWindow();
    User32.SetActiveWindow(dw);
    User32.SetForegroundWindow(dw);
    User32.CloseDesktop(inputDesktop);
 }
 graphic.ReleaseHdc(graphDC);
 User32.ReleaseDC(hWnd, hDC);
EN

回答 1

Stack Overflow用户

回答已采纳

发布于 2017-01-30 07:28:03

我让SendInput在登录桌面上工作(而且,事实证明,UAC安全桌面)。SetThreadDesktop不能赋予您与最初在目标桌面中启动进程相同的特权。

因此,当我检测到桌面更改时,我没有调用SetThreadDesktop,而是使用CreateProcessAsUser在新桌面上启动了另一个进程。然后我发出信号让查看者切换并关闭当前进程。

编辑(几年后):我最终错了。您只需要确保当前线程在当前桌面上没有任何打开的窗口或钩子。因为这只设置了调用线程(而不是进程)的桌面,其他线程也需要调用它。

票数 4
EN
页面原文内容由Stack Overflow提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://stackoverflow.com/questions/41924863

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档