Services and Session Zero in Vista and Windows Server 2008



If you’ve been running vista you might have come across this message: “A program can’t display a message on your desktop” with the options to show the message or remind you later.  So what’s the deal with this?


Gone over in detail in this doc, its because services that runs in session0 run separately from the user’s session and therefore can’t display popups directly to the user.


Windows Vista isolates services in Session 0 and runs applications in other sessions, so services are protected from attacks that originate in application code. In Windows Server 2003 and earlier versions of Windows, all services run in Session 0 along with applications, which poses a security risk because services run at elevated privilege and therefore are targets for malicious agents who are looking for a means to elevate their own privilege level.

The popup itself is Windows Vista playing nice with legacy services that send user interaction dialog boxes to session zero instead of the corresponding user session, this is called the “interactive service detection service”.  This workaround will be removed from the next version of Windows, at which time all applications and drivers must handle Session 0 isolation properly.

Proving that Microsoft devs are smart (IMHO), on a TS server in LH, these popups will only be displayed to the administrative sessions and not to the user sessions that are present on the TS server.

The whitepaper linked above has what devs should be doing these days to take into account this isolation.

BTW have you checked out the latest refresh of Windows Live Writer?  You should.

 


Comments (6)

  1. Anonymous says:

    Tonight's email says: "I realise you must be very busy however I have a message that continually

  2. Brian says:

    I figured out through painstaking online research and troubleshooting that this was the reason that I couldnt get RealVNC free version to work on Vista machines. I found a workaround though.

  3. A dude.. says:

    Good for you, Brian. Care to share?

  4. Jason says:

    So how do you stop the dialog box from popping up?

  5. james hines says:

    still cant get rid of this stupid pop up interactive service ive tried different things still wont go maybe i will need someone else to do it for me but thanks for youre help 🙂

  6. james hines says:

    still cant get rid of this stupid pop up interactive service ive tried different things still wont go maybe i will need someone else to do it for me but thanks for youre help 🙂