[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 05-17-2006, 08:10 PM   #1
eSDee
Old Skooler Numba 1
 
eSDee's Avatar
 
Join Date: Nov 2000
Location: Diego
Posts: 10,063
Send a message via AIM to eSDee
Hack a Windows XP user account

I have a friend who forgot his password for a laptop that he screwed up when he was in Iraq. Basically he crushed the screen so you can't see anything, and he though he had lost everything since he couldn't access his files anymore. He tried hooking it up to an external monitor but it didn't work, because as soon as it passed the Windows XP screen the external monitor would go blank. I figured out that if you boot into Safe Mode then you can still log in to Windows. The problem is I can only log into the Guest Account because he forgot his password. I tried using the Ultimate Boot CD but for some reason it wouldn't boot. However the Windows XP disk works as a boot disk and so I was able to reset his password by following the instructions on this page:

http://pubs.logicalexpressions.com/p...cle.asp?ID=305

Basically, do a Windows Repair. After it copies all the files it needs to repair with, it will reboot. When you are in the Windows installation screen, hit Shift + F10. This gets you to a command prompt, at which point you type in the command NUSRMGR.CPL and hit enter. It then pops up the GUI Accounts panel, which allows you to delete/change user passwords. You have to continue the installation process but after that, you're good to go!

This is a great nugget of knowledge for Sys Admins. I thought a few of you might appreciate it.
__________________
~~~~~~~~~~~~
3 days ~ Willie Nelson

3 days I dread to see arrive
3 days I hate to be alive
3 days filled with tears and sorrow
yesterday today and tomorrow
eSDee is offline   Reply With Quote
Old 05-18-2006, 06:55 AM   #2
mechmike0034
aka the keg killer
 
mechmike0034's Avatar
 
Join Date: Dec 2002
Location: Ala-effin'-bama!
Posts: 2,738
Great stuff, bro, but there's a quicker and easier way that does not require a repair install:

http://home.eunet.no/pnordahl/ntpasswd/

Linux-based boot disk that resets passwords - works excellent...

I'm still gonna make note of your method. There's always more than one way to get there...
__________________
"The price of progress is trouble." (C. F. "Boss" Kettering)
"50% of the American public has below-average intelligence. 70% of the American public now has regular access to the Internet. Do the math." (unknown)
mechmike0034 is offline   Reply With Quote
Old 05-18-2006, 06:57 AM   #3
MikeD
President, Cowboys Nation
 
MikeD's Avatar
 
Join Date: Dec 2004
Location: In the 'burbs, west of D.C.
Posts: 5,139
Good info guys. This Sys Admin thanks both of you.
__________________
MikeD is offline   Reply With Quote
Old 05-18-2006, 08:52 AM   #4
mcs328
Admiral
 
mcs328's Avatar
 
Join Date: Feb 2001
Location: Maryland
Posts: 6,578
Excellent!! Should we have a sub-forum for all these tricks or does a search work out well? I've bookmarked some of the sites mechmike posted before posts like these are very good to keep around.
__________________
mcs328 is offline   Reply With Quote
Old 05-18-2006, 10:17 AM   #5
eSDee
Old Skooler Numba 1
 
eSDee's Avatar
 
Join Date: Nov 2000
Location: Diego
Posts: 10,063
Send a message via AIM to eSDee
Well like I said I was having trouble booting to other discs other than the XP disc. Not sure why, since I tried multiple CD's to no avail. But thanks for that link as well. This way I described takes about 40 mins or so, which is not good if you are in a rush.
eSDee is offline   Reply With Quote
Old 05-18-2006, 10:58 AM   #6
Jeffbx
Fleet Admiral
 
Jeffbx's Avatar
 
Join Date: Mar 2000
Location: Michigan
Posts: 9,390
Send a message via MSN to Jeffbx
Quote:
Originally Posted by mechmike0034
Great stuff, bro, but there's a quicker and easier way that does not require a repair install:

http://home.eunet.no/pnordahl/ntpasswd/

Linux-based boot disk that resets passwords - works excellent...

I've used this one before on an old laptop that one of the VPs found in a drawer from when he worked in our Japanese office. No idea what the password was, and it was a Japanese version of W2K. Booted up with this program on a floppy, and it worked like a charm. It extracts the administrator password in just a few seconds.
Jeffbx is offline   Reply With Quote
Old 05-18-2006, 01:27 PM   #7
gwilks98
Vice Admiral
 
gwilks98's Avatar
 
Join Date: Aug 2000
Location: StL
Posts: 4,300
Send a message via AIM to gwilks98
Quote:
Originally Posted by mechmike0034
Great stuff, bro, but there's a quicker and easier way that does not require a repair install:

http://home.eunet.no/pnordahl/ntpasswd/

Linux-based boot disk that resets passwords - works excellent...

I'm still gonna make note of your method. There's always more than one way to get there...


Important to note this about your utility:
(From the FAQ)
Why can't I access my encrypted (EFS) files after resetting the password?
Because in XP and possibly later service packs in win2k the password itself is used to encrypt the keys needed for EFS.
Sorry, there is no way to recover the files once the password has been reset.
A lot of times, users protect "my documents" with EFS. Let the user beware
__________________
"I know the pieces fit, cause I watched them fall away."

"Cold silence has
A tendancy to
Atrophy any
Sense of compassion."

MJK
gwilks98 is offline   Reply With Quote
Old 05-18-2006, 03:53 PM   #8
mechmike0034
aka the keg killer
 
mechmike0034's Avatar
 
Join Date: Dec 2002
Location: Ala-effin'-bama!
Posts: 2,738
Quote:
Originally Posted by gwilks98
Important to note this about your utility:
(From the FAQ)
Why can't I access my encrypted (EFS) files after resetting the password?
Because in XP and possibly later service packs in win2k the password itself is used to encrypt the keys needed for EFS.
Sorry, there is no way to recover the files once the password has been reset.
A lot of times, users protect "my documents" with EFS. Let the user beware

Great point, and I should have noted that. Most of the users I deal with wouldn't have a clue about encrypting files, but then again the limited IT stuff I do is way outside the corporate world.

Any time I do have to work on a PC for an individual, I make sure that I explain that worst case scenario everything could be gone. Usually by the time I get to it I am the "last chance garage" so to speak.

Still, thanks for bringing up that very important point.

Quote:
Originally Posted by mcs328
Excellent!! Should we have a sub-forum for all these tricks or does a search work out well? I've bookmarked some of the sites mechmike posted before posts like these are very good to keep around.

Check the links page of my humble (and newly re-done) website. The addy is posted in the Spam forum, as well as in my profile. I made a page of what I felt was the "best of the best" for home users.

Maybe I should put a tech tricks/tech links page together... Ahh, so many projects, so little time...

Last edited by mechmike0034 : 05-18-2006 at 03:56 PM. Reason: Automerged Doublepost
mechmike0034 is offline   Reply With Quote
Old 05-18-2006, 06:00 PM   #9
gwilks98
Vice Admiral
 
gwilks98's Avatar
 
Join Date: Aug 2000
Location: StL
Posts: 4,300
Send a message via AIM to gwilks98
Anyone know if SD's method works around the EFS issue? I've never used it before, so I would only be guessing.
gwilks98 is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 09:22 AM.