Windows Vista Security-Securing Vista Against Malicious Attacks

Roger A. Grimes

Jesper M. Johansson

Wiley Publishing, Inc.

Published by
Wiley Publishing, Inc.
10475 Crosspoint Boulevard
Indianapolis, IN 46256

© 2007 Wiley Publishing, Inc., Indianapolis, Indiana.


10 9 8 7 6 5 4 3 2 1

No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise, except as permitted under Sections 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should be addressed to the Legal Department, Wiley Publishing, Inc., 10475 Crosspoint Blvd., Indianapolis, IN 46256, (317) 572-3447, fax (317) 572-4355, or online at

Limit of Liability/Disclaimer of Warranty: The publisher and the author make no representations or warranties with respect to the accuracy or completeness of the contents of this work and specifically disclaim all warranties, including without limitation warranties of fitness for a particular purpose. No warranty may be created or extended by sales or promotional materials. The advice and strategies contained herein may not be suitable for every situation. This work is sold with the understanding that the publisher is not engaged in rendering legal, accounting, or other professional services. If professional assistance is required, the services of a competent professional person should be sought. Neither the publisher nor the author shall be liable for damages arising herefrom. The fact that an organization or Website is referred to in this work as a citation and/or a potential source of further information does not mean that the author or the publisher endorses the information the organization or Website may provide or recommendations it may make. Further, readers should be aware that Internet Websites listed in this work may have changed or disappeared between when this work was written and when it is read.

For general information on our other products and services or to obtain technical support, please contact our Customer Care Department within the U.S. at (800) 762-2974, outside the U.S. at (317) 572-3993 or fax (317) 572-4002.

Library of Congress Cataloging-in-Publication Data

Grimes, Roger A.
Windows vista security: securing vista against malicious attacks / Roger A. Grimes, Jesper M. Johansson.
p. cm.
Includes bibliographical references and index.
ISBN 978-0-470-10155-1 (paper/website)
1. Microsoft Windows (Computer file) 2. Computer security. I. Johansson, Jesper M. II. Title. QA76.9.A25G777 2007


Trademarks: Wiley, the Wiley logo, and related trade dress are trademarks or registered trademarks of John Wiley & Sons, Inc. and/or its affiliates, in the United States and other countries, and may not be used without written permission. Microsoft and Windows Vista are trademarks or registered trademarks of Microsoft Corporation in the United States and/or other countries. All other trademarks are the property of their respective owners. Wiley Publishing, Inc., is not associated with any product or vendor mentioned in this book.

Wiley also publishes its books in a variety of electronic formats. Some content that appears in print may not be available in electronic books.

I would like to dedicate this book to my beautiful wife, Tricia, who has been my biggest fan, constant rock, and who has never once complained about my insanely long work hours or world travel commitments.


I dedicate this book to my lovely and talented wife, Jennifer, who although she may complain occasionally about long working hours, is always right!


About the Authors

Roger A. Grimes (CPA, CISSP, CEH, CISA, MCSE: Security) is a 20-year Windows security veteran and four-time Microsoft Most Valuable Professional (MVP) for Windows security. Roger currently works for the Microsoft ACE Services team as a senior security consultant, but in the past has worked for Foundstone and consulted for dozens of the world's largest companies. This is Roger's seventh book on computer security. He is the author of over 200 magazine articles and he is the InfoWorld magazine security columnist and blogger.

Jesper M. Johansson is a security architect focusing on software security. Prior to his current position, he was an assistant professor at Boston University, and then a Senior Security Strategist at Microsoft where he worked in the Secure Windows Initiative and Trustworthy Computing Groups. He has worked in security for about 20 years and is the author of many articles and two books on the topic. He has delivered hundreds of presentations on security on every continent except Antarctica and South America and is a contributing editor to TechNet Magazine. Dr. Johansson has a Ph.D. in Management Information Systems and is a Certified Information Systems Security Professional (CISSP) and a certified Information Systems Security Architecture Professional (ISSAP). When he is not working on information security, he teaches scuba diving and enjoys life with less travel and more family.


Executive Editor
Carol Long

Development Editor
Kelly Talbot

Technical Editor
Alun Jones

Production Editor
Christine O'Connor

Copy Editor
Nancy Rapoport

Editorial Manager
Mary Beth Wakefield

Production Manager
Tim Tate

Vice President and Executive Group Publisher Richard Swadley

Vice President and Executive Publisher Joseph B. Wikert

Project Coordinator
Lynsey Osborn

Craig Woods, Happenstance Type-O-Rama

Sossity Smith

Robert Swanson

Anniversary Logo Design
Richard Pacifico


I wish to thank all the teachers in my 20-year computer security career, especially the other humbling MVP security contributors, friend Mark Minasi, the public security mailing lists, and friends in the industry. Twenty years ago I thought I knew everything; now I know I only know what fits on the end of a fingernail.

- Roger

I wish to thank the various people at Microsoft who helped get me information for my chapters, including Sarah Wahlert, Darren Canavor, Steve Hiskey, Eran Yariv, Eric Fitzgerald, Michael Kleef, and Peter Brundrett. I would also like to thank my current and former coworkers at Amazon, as well as my friends Susan Bradley and Alun Jones, who tirelessly reviewed everything we threw at them. Finally, I must not forget Jeremy Moskowitz, Jimmy Anderson, Mike Smith-Lonergan, and Mark Burnett, who provided valuable feedback on their respective areas of expertise.

- Jesper

Windows Vista Security. Securing Vista Against Malicious Attacks
Windows Vista Security. Securing Vista Against Malicious Attacks
ISBN: 470101555
Year: 2004
Pages: 163 © 2008-2017.
If you may any questions please contact us: