I don't know what format your win2000 is using. If, like mine, it uses FAT32, then it's easy: boot with a win98 startup disk, copy out winnt\system32\config\SAM., and use the l0phtcrack tool on it. If the admin password was set simply,
it will be recovered very quickly.
If your win2000 uses ntfs format, you can copy the ntfsdos tool onto a dos boot disk. After booting, you can also grab winnt\system32\config\SAM. and use l0phtcrack on it.
I heard you still have a guest account you can use. If this machine is connected to a network, you can try a program aimed at the Win2000 NetDDE message privilege escalation vulnerability. Since my win2000 has always been used as a standalone machine, I never had a chance to try it. See here.
http://security.nsfocus.com/showQuery.asp?bugID=1240
Some time ago I saw a technician at a security company in Beijing write a program targeting a name pipe vulnerability in winnt. The program can masquerade as a system service program and read and write the parts of the registry that only system has permission to read and write. First go to my homepage and download a program
http://www.tengzhen.com/freesky/tools/service.zip extract it as service.exe. After you log in with guest, run service.exe /install, and the program will register itself as a win2000 service program. The service name is testserver, and you can see this service in the service manager. After the next reboot, this service will copy the system administrator's attributes to guest, so guest becomes a member of administrators and has administrator privileges.
If your guest account is also disabled, then here's the most ruthless move, a method I discovered a long time ago. Install another win2000. I succeeded with this, it can work! Note that you must first back up the boot sector mbr information. There are many ways, for example KV300. If you understand assembly, you can read an article of mine, "How to Low-Level Format a Hard Disk and Back Up mbr with debug". This new win2000 must not be installed on the same drive as the original one. If your original win2000 is on C:, then install the new one on D:, and the hard disk format must be the same as the original. After installation, log in with admin. Now you have absolute write permission to the original win2000. You can grab the original SAM and run it, and even more, you can take all the files in the new
d:\winnt\system32\config\ and overwrite them into the
c:\winnt\system32\config\ directory, then use kv300 to restore the previous mbr. Now you can log into the old win2000 as admin.
(If reposting this method, please indicate the source as: http://ttfreesky.126.com)
ko20010214
=================================
大功告成,打个Kiss!
ko20010214@MSN.com
神州优雅Q300C
Intel CeleronM 370处理器 | 256MbDDR内存
40G硬盘 | USB2.0 | IEEE 1394
13.3 ' WXGA 宽屏(16:10) | COMBO光驱
10/100M网卡 | 四合一读卡器