Security Basics mailing list archives

RE: Windows XP Pro cracker?


From: Marco Obaid <marco () muw edu>
Date: Thu, 4 Sep 2003 16:59:30 -0500

Hi,

If someone tries this on Windows XP or 2000 w/ syskey enabled (which it is
by default), let me know.

I just tried it on my XP Pro (patched up-to-date) and here is my findings:

It works well, but it is best to *blank* the password first and change it to 
whatever you want *after* you logon to the system. 

I created a user called "user" and assigned it a password. Then, using this 
tool, I changed the password. I could not logon to the system using "user", nor 
was I able to change the password from the Administrator account. So I used the 
tool again and *blanked* the password for user. Then, I was able to logon as 
usaul. The same thing happend when I used this tool against Administrator.

This is my first time using this tool and I read every note in the docs.

Hope this helps
Marco

_________________________________________________________________
This mail is sent through MUW Webmail: http://www.MUW.Edu/webmail
For the latest MUW Events, visit  http://www.MUW.Edu/calendar

---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
----------------------------------------------------------------------------


Current thread: