Get the App
SLTechnology News&Howtos  ›  Servers  › 

Windows startup options (MSDN reading notes)

Shulou Source: shulou.com Published: 2022-06-02 07:09:25 10月03日 Update

If multiple systems are installed on a computer, there will be multiple startup options. Today, let's talk about windows startup options.

The startup options of windows are stored in the system or in RAM. The location of the storage depends on the version of the system and the version of the processor, as shown below:

System location xp, server2003 and previous systems

Bios firmware: stored in Boot.ini

EFI firmware: stored in nonvolatile RAM (NVRAM)

Vista, server2008 and subsequent systems

Stored in windows components

How to load boot items when the system is booted:

Xp, server, etc. The boot loader reads the startup options in boot or RAM directly and displays them according to the settings.

Vista, server2008 and the system after that, the boot loader calls the windows component and gives the system execution power to the component, which runs and displays the startup information in the component.

If there are multiple systems, each system has a boot entry for each system. It is important to note that the windows component can interact with boot or RAM to obtain startup information.

If there are multiple systems and all new versions of the system, the windows component in the front partition is started; if there are multiple systems but there are both new and old systems in multiple systems, the component in the front partition in the new system is started and used to get all startup information and display.

Next, let's look at how to edit the startup item:

1. The old version directly modified boot or RAM, in which boot can be edited directly with bootcfg or text editor, but RAM needs special tools (such as bootcfg, nvrboot) to read and write.

two。 The startup information of the new version is stored in the component, so it cannot be modified directly and needs to be managed through a tool provided by window: BCDedit or MSConfig.

The above three ways, each has its own storage format, management tools also have their own usage, Microsoft's official website already has instructions and a Chinese text, there is no more detail here, if necessary, you can go to MSDN to check.

How to determine whether a host is EFI firmware or bios firmware:

Method 1: check the product description

Method 2: open the command prompt, enter msinfo32 and enter, a panel of computer hardware information will pop up. In the BIOS mode on the right, if it is traditional, it is bios firmware, and if it is efi, it is UEFI firmware.

The ps:// firmware is determined when the computer leaves the factory and has nothing to do with the installed system.

Ask once a day:

Question: as an information security practitioner, why should I learn these things?

Personal answer:

In the post-stage, the target computer cannot work properly by modifying the startup item; (parody)

In the later stage, the target system is interrupted to enter the system by uploading the self-written startup loader and modifying the startup item, and our program is executed first to achieve some results.

If you have any good ideas, welcome to comment.

Tags: Systems components firmware information multiple storage computers programs tools versions locations methods goals phases and will management special security next things Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Apple Shulou Technology NVidia vpn