Summary
This chapter showed you how to work with COM security in order to allow and deny access to a COM server. Early in the chapter, you learned some fundamental concepts about Windows security with relation to COM.
Next, I tackled security descriptors. I accessed them programmatically and discussed their purpose. The different descriptor types were discussed and related registry entries listed.
We took a look at Access Control Lists (ACL) and the API functions to access them. Then, a special sample program was used to read through the ACLs on the current system.
The last major topics discussed were impersonation and cloaking. Understanding them is important if a comprehensive understanding of COM security is to be obtained.
COM security is ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access