hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Bypass Windows Login?
Aaron5278
Hello, This is my first post here! My name is Aaron. This site is really great! Ok enough with the blabbing. rolleyes.gif

My question is, I was wondering if there is a way to get pass the Log-in screen on Windows XP. In other words, when you boot up, the log in screen appears. Is there any way to crack the password or just simply by-pass the login screen and have admin capabilities? I have heard of different ways on Windows 98 and stuff, but none for XP. Any help is greatly appreciated! Thank you! smile.gif


Best Regards,

AARON
ComSec
try this

as it boots hit F8 to boot in to safe mode...now providing the owner has not setup a password for the default admin account on installation..you can login and create an account

you should see 2 accounts (ie)

Admininstrator login ... default
owner login .....passworded

MpR
Hey Dude theres a few ways around it , the easiest way and only way I feal like explaining , (I dont have 2 hours) if to get a password recovery boot disk just google it .. It will take the hashes show the accounts and from there you can give the Administrator account a new pass.. That account is the best to reset if on another persons computer solely because its the one rarely used and usually doesnt show up on the XP log in .. After you reset the password at the log in screen hit CTRL + ALT +DEL a couple times youll get a different log in screen Type in the Username and the new password and away you go
MpR
Actually heres a link too one Ive used in the past


http://home.eunet.no/~pnordahl/ntpasswd/ seemed to work well, but then again everything can and will screw up at one point..
Aaron5278
Thanks alot man., I will give it a try. I'll let you know if it works. smile.gif
MpR
no prob man lol hit the right keys and it will work
dissolutions
Windows XP boot disk into recovery console works with win2k as well smile.gif
mekros
might be far off from whut you're asking but if you just want to elevate your privilege... pipeupadmin might help... biggrin.gif
netcomm
there was a trick i use to use at skool.
not sure this is very relavant to the topic but ill tell ya anyway.

when on a skool network unplug the network cable from the back of your
workstation. at the login screen delete the text next to domain
and leave username and password blank and hit cancel.
this way the computer doesnt validate on the network.
then when u want to surf the net plug it back in and goto IE.
its good 4 getting around download limits and lets ya look at Pawn and stuff.


Peace
NetCOmm
virus
QUOTE (MpR @ Sep 4 2003, 05:14 AM)
...  if to get a password recovery boot disk just google it .. It will take the hashes show the accounts and from there you can give the Administrator account a new pass.
......

I don't think that'll work cause that's not the way a password recovery disk works. When you are creating a password recovery disk, u have to specify your admin password and only then it'll make the disk. This disk is used in case u forget the password, it will recover it. U can use a program that was uploaded by chris*** in the file downloads section. Its a bootable disk that will get u admin password/privilege. Its a .iso so u have to burn it. I haven't tried it as yet but it seems promising biggrin.gif
Hope this help smile.gif

P.S: Welcome to GSO Aron smile.gif
MpR
If You continue too read and you follow the link below, You will realize that I am not talkign about a recovery disk made by Windows for those shitty moments, read a little farther and comment again wink.gif
Aaron5278
Thanks for all your replies!! I learned alot. I do have another question, and sorry if their is another topic about this. Is there a way to diable "FoolProof"? I am not sure of the version number etc. I belive it's on Windows 98 or 2000, I know it's a big difference, but that's all the info I can get. unsure.gif My teacher was asking if anyone thought they could get into blocked files/programs. After class I told my teacher I might be able to access some blocked stuff, she said I could try anything I wanted. Then I tried and I was able to get into cmd.exe [MS-DOS], but once in there, you can't type mad.gif I was upest and embaressed. lol. So now I'm determined to show her something I can do on the school computers. This is all with her permission BTW. Anyways, thanks alot. and hope to get some more respones from you. Just in case you forgot the question after all of that.............

Is there any possible way to disable the program "FoolProof"??? biggrin.gif

Thanks!

Regards,

Aaron
ComSec
LOL ....ok i gotcha

your or (where) hacking your school computer..only we dont know that rolleyes.gif lol rolleyes.gif

you have got past the login... with the advice from above ohmy.gif

But cannot run anything sad.gif

we 'ooppps' you have to bypass FoolProof...for you wink.gif

thus you gaining a rep in school as a cool hacker ph34r.gif

and with your teachers blessing 'what a girl'.... dry.gif

neat.... i like it 10/10 biggrin.gif biggrin.gif
Aaron5278
CODE
LOL ....ok i gotcha

your or (where) hacking your school computer..only we dont know that  lol  

you have got past the login... with the advice from above  

But cannot run anything  

we 'ooppps' you have to bypass FoolProof...for you

thus you gaining a rep in school as a cool hacker

and with your teachers blessing 'what a girl'....  

neat.... i like it 10/10  


biggrin.gif LOL! Excellent guess! I would think the same thing, but actually, [this is the truth] the first post was for me to get into my friends computer. At school we all have our own logins anyways. Oh and one other thing LOL blink.gif

CODE
and with your teachers blessing 'what a girl'....  


I am actually a guy, if it was the name that threw you off, for future reference, girls spell it Erin [Usually] and guys spell it Aaron or Aron or Arron etc. lol, Don't mean to lecture you about names here biggrin.gif

But yeah, if anyone has any advice or help about "FoolProof" it would be greatly appreciated. lol

Regards,

Aaron ph34r.gif
MpR
Yeah to bypass fool proof you can boot into a cmd promp , edit win.ini usually a section in there to load it delete that crap usually all is well after ..
Aaron5278
Thanks, I will give it a try. cool.gif
MpR
Actually before you realize Im probably wrong I'll say it first..lol Win.ini if yah can if not the original disk I gave yah the link too has a reg edit before windows on it yah can run you can rip that bad boy right out if it comes down too it
williamtell323
The first thing you should do is download and install FoolProof on your own home computer to become thoroughly familiar with the program. You can download it here:

FoolProof Downloads
http://www.smartstuff.com/downloads/fps/index.html

You will need two codes: an unzip code, and an Install Code. Can't post them here.

I hacked FoolProof about a year ago. It's not that hard, unless the person who installed it hardened the default settings. I used the ECHO command once to overwrite the FoolProof exe file, and it worked. But it really depends on the individual settings. You want to try and copy the settings files and install them on your own home installation of FoolProof in order to know what you're up against. These are the settings files:

Basic Settings are located in c:\sss\local\basic.lfl
Other settings files seem to be located in c:\sss\local\00000000.lfl
c:\sss\local\00000001.lfl, etc., and c:\sss\defs\resource.lfl

Since you know the password on your own version of FoolProof you could substitute the settings files from your school's installation of FoolProof, plug them in to your own installation and open up the FoolProof control panel and see what settings are in place. And what is NOT restricted too. The trial version of FoolProof is fully-functional.

The password file is c:\sss\local\fp.db. You might try and substitute your own password file onto your school's computer (using the password file from your own installation of FoolProof). Then you could open up FoolProof Control Panel and turn it off. Try copying it from a floppy disk (or download from your email) to c:\sss\local to see if it will let you replace it. If you just delete the password file it does you no good, since you still cannot open the FoolProof Control Panel. A message just pops up saying "Database not found."

You can use Process Explorer to kill the two FoolProof processes:
fpwinldr.exe 32-bit shell hook loader
fpwldr16.exe 16-bit shell hook loader
The fpwldr16.exe you may have to be patient with. It takes 40 seconds or so before it dies. Do it twice if you have to.

But you will still need to edit c:\config.sys and delete the following line: DEVICE=C:\SSS\FOOLDRV.SYS

Also, another powerful hack on Windows 95/98 is using a wininit.ini file (a simple text file you can create with Notepad) to delete all the FoolProof files. You'll need to use syntax like the following:

[Rename]
NUL=C:\sss\shlhkw16.dll

Save it as wininit.ini in the Windows directory. Wininit.exe executes this file before most everything else loads. It is used to delete files in use. Include the line above too, because shlhkw16.dll is the only file I was not able to delete because it was "in use". wininit.ini will delete it on the next reboot.

Download the Manual
http://www.smartstuff.com/downloads/fps/index.html

Using Process Explorer and wininit.ini and deleting pointers in special boot files like config.sys, autexec.bat, winboot.ini you can hack most all Windows 95/98 security programs.

Process Explorer
http://www.sysinternals.com/ntw2k/freeware...e/procexp.shtml

FoolProof Downloads
http://www.smartstuff.com/downloads/fps/index.html

The syntax for the wininit.ini is as follows. One NUL line for each file to delete. Create it in Notepad and save it as wininit.ini in the windows directory. Then restart the computer.

[Rename]
NUL=C:\sss\shlhkw16.dll

Kill that puppy!!

Aaron, I sent you an email here on this system too. Check it.


Aaron5278
williamtell323, thank you so much! You would not belive how much I appreciate a response like that. I will reply to you through the e-mail, so we can talk.

smile.gif smile.gif smile.gif smile.gif smile.gif smile.gif smile.gif smile.gif


Regards,

Aaron
netcomm
if your on 98 or 2000
hit F8 on bootup then if you dont mind f*(&ing the computer a bit
then delete the win.ini and autoexec.bat from your c: drive.
then try the trick i talked about earlier.
unplug the cable then login. you would have FULL access then.

OR

download "cain" and get the admin username/password for that computer
that way you can just uninstall that programe your tAlking about.

Goodluck
Peace
NetComm
opium-
hey guys.. first post... i tried the programs that you guys put links to and they dont work.. i have xp and i tried the things they gave for xp... but nothin seemed to work... plz help!
MpR
Hwy wait yes they do work ...use the password reset bootdisk all the time. try again
opium-
im such a newb... us that just another cd? or is it on the original windows xp cd?
manu
What do u want guys?.. You want to reset the Admin password and you have the full local access to the XP machine.. Why can't you think of the LINUX boot disk to reset Admin password and get in to it?. I had posted the CD image for making that disk in this forum.. Search for it.. Pretty cool, nothing to worry... Then, I think I don't need to teach u how to make a bootable disk from Cd image, Well, use Easy Cd creator or Nero, Striaght forwad thing..............

Boot with this Cd and reset the Admin or any user password... Cool........

I should add the CD image once again here, I guess.. Here we go..!!
Johny
don't hack your school's computer but your girlfriends computer and perhaps you'll discover things you've never have know. put a keylogger, msn logger, remote desktop prog, ftp , etc
Really, believe me, it helped me to discover a lot of things about her I didn't know smile.gif
manu
Johny, before doing all those stuffs, try to check ur PC first, whether there are no keyloggers or other (filtered) stuffs installed... biggrin.gif ... Lollllllllll..

Manu
chris105
QUOTE (netcomm @ Sep 4 2003, 03:52 AM)
there was a trick i use to use at skool.
not sure this is very relavant to the topic but ill tell ya anyway.

when on a skool network unplug the network cable from the back of your
workstation. at the login screen delete the text next to domain
and leave username and password blank and hit cancel.
this way the computer doesnt validate on the network.
then when u want to surf the net plug it back in and goto IE.
its good 4 getting around download limits and lets ya look at Pawn and stuff.


Peace
NetCOmm

Going to give it a try tommorow i usually use google translator so that u type in the url and convert from english into english it gos throught the google translation server and u can view it!! they fixed batch scripts last week though ... and .reg went a couple of days ago, still got .com files though!!
chris105
I got a stripped down knoppix on a floppy disk, wouldnt be without it!!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.