Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-27-2005, 03:06 PM
tarquinlinbin
Guest
 
Posts: n/a
Default Getting win2k admin password?

Hello,
i have a laptop on which i am unable to access the administrator
account becuase i havent got the password. Is there an easy way of
finding/bypassing this?
ta

jo



Remove antispam and add 670 after bra to email

http://www.no2id.org/

Reply With Quote
  #2 (permalink)  
Old 10-27-2005, 03:46 PM
Stephen Howard
Guest
 
Posts: n/a
Default Re: Getting win2k admin password?

On Thu, 27 Oct 2005 15:06:20 +0100, tarquinlinbin
<braantispam@hotmail.com> wrote:

>Hello,
> i have a laptop on which i am unable to access the administrator
>account becuase i havent got the password. Is there an easy way of
>finding/bypassing this?
>ta
>

There's a linux boot disk you can download that allows you to reset
the admin password.

http://home.eunet.no/~pnordahl/ntpasswd/

Regards,



--
Stephen Howard - Woodwind repairs & period restorations
www.shwoodwind.co.uk
Emails to: showard{whoisat}shwoodwind{dot}co{dot}uk

Reply With Quote
  #3 (permalink)  
Old 10-27-2005, 04:22 PM
nemo_outis
Guest
 
Posts: n/a
Default Re: Getting win2k admin password?

tarquinlinbin <braantispam@hotmail.com> wrote in
news:pkn1m1t06uf42fatjluaj40bfnbc4461cf@4ax.com:

> Hello,
> i have a laptop on which i am unable to access the administrator
> account becuase i havent got the password. Is there an easy way of
> finding/bypassing this?
> ta
>
> jo



I assume you are talking about the *local* administrator account on the
machine itself.

Yes, there are a number of ways of escalating privilege. The simplest
are the "canned" solutions which are easy to apply if you can boot from
floppy, CD (or USB). The Winternals Admin pack contains such a module
which will allow you to (re)set the Admin password to whatever you wish
(Note that it clobbers the original password so you may wish to back up
the sam first). Elcomsoft and Passware have commercial modules which do
the same thing.

There are some free ones out there too such as:

http://www.grape-info.com/doc/win200.../ntpasswd.html
(I haven't tried this particular one but there are many! others out
there)

Be aware that if you are too aggressive with some of these schemes you
can make some things (e.g., EFS encrypted files) inaccessible. However,
if you don't clobber the SID but just the password all will be well.

Even if you can't boot from CD there are a few tricks to escalate
privilege (so you can run things like Cain & Abel or lsadump to get
passwords). The most elegant are the "shatter" attacks that take
advantage of the insecure and unauthenicated windows message-passing
mechanism. But here's a simple "golden oldie" one that often works:

Go to a command prompt and type in:

at hh:mm /interactive taskmgr
(put in the time a few minutes from now)

At the specified time, task manager will pop up - as a system process!

End task explorer.exe, Click on New Task and type in explorer.exe (the
less greedy will just open a window with cmd). You are now running at
system level! Bingo! (I can almost hear the patter of little sysadmin
feet running to close off this loophole as I type).

Regards,




Reply With Quote
  #4 (permalink)  
Old 10-27-2005, 09:10 PM
Phil
Guest
 
Posts: n/a
Default Re: Getting win2k admin password?

tarquinlinbin wrote:

> i have a laptop on which i am unable to access the administrator
> account becuase i havent got the password. Is there an easy way of
> finding/bypassing this?


Why not ask the owner of the laptop?


Reply With Quote
  #5 (permalink)  
Old 10-28-2005, 08:41 AM
tarquinlinbin
Guest
 
Posts: n/a
Default Re: Getting win2k admin password?

On Thu, 27 Oct 2005 22:10:54 +0200, Phil <rotsky@nospam.org> wrote:

>tarquinlinbin wrote:
>
>> i have a laptop on which i am unable to access the administrator
>> account becuase i havent got the password. Is there an easy way of
>> finding/bypassing this?

>
>Why not ask the owner of the laptop?

A) i dont need to,ive sorted it now

and

B) who says im not the owner?



Remove antispam and add 670 after bra to email

http://www.no2id.org/

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Patent buster for a method that increases password security Juuso Hukkanen alt.computer.security 15 12-07-2006 03:45 PM
Patent buster for a method that increases password security Juuso Hukkanen comp.security.misc 17 12-07-2006 03:45 PM
Win2K Complex Password Enforcement Mr. Security alt.computer.security 5 09-02-2005 09:01 PM
HP Pavilion ZE4600 Power on Password madscientist alt.computer.security 1 08-30-2005 01:01 AM
HP Pavilion ZE4600 Power on Password madscientist alt.comp.hardware 0 08-29-2005 11:24 PM


All times are GMT. The time now is 11:42 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45