Security Basics mailing list archives

Re: Windows XP Pro cracker?


From: Ansgar Wiechers <bugtraq () planetcobalt net>
Date: Fri, 5 Sep 2003 00:14:36 +0200

On 2003-09-04 Halverson, Chris wrote:
On 2003-09-03, 11:08 AM, George Peek wrote:
Btw, if you have another account with admin prv you can log into, you
can reset any other local account's password.

That doesn't work it has to be the original password from the
installation.

Wrong. It's the current password. Maybe you are confusing this with the
password required for rebuilding AD on domain controllers?

To address the original topic: I heard that booting into the recovery
console from a Windows 2000 CD will log you in without password on
Windows XP systems. I'm not sure if this really works, since I haven't
checked it myself, but I would give it a shot.
I seem to recall that it was due to an incompatibility either in the SAM
or NTFS.

Regards
Ansgar Wiechers

---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
----------------------------------------------------------------------------


Current thread: