中国DOS联盟论坛

China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --
Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
Guest | Log in | Register | Members | Search | China DOS Union
中国DOS联盟论坛
The time now is 2026-08-25 19:19
47,812 topics / 349,910 posts / today 0 new / 48,263 members
其它操作系统综合讨论区 » XP password
Printable Version  995 / 6
Floor1 priscilla Posted 2003-06-18 00:00
初级用户 Posts 19 Credits 186
I'm using XP and forgot the admin password. Is it possible to delete the relevant files under DOS to clear the password?
I also downloaded ntpasswd before and followed the instructions, but it didn't work.
Floor2 峡飞使者 Posted 2003-06-21 00:00
初级用户 Posts 3 Credits 110
You can enter this under DOS: c;\win\system32\sam\config and delete it (assuming XP is on drive C, sam is the user password file).
Floor3 ko20010214 Posted 2003-06-21 00:00
版主 Posts 1,628 Credits 7,296
Password recovery for WIN NT/2000/XP
----------------------------------------------------------------------------
----
Posted by: refdom Source: Original Category: Original World Date: 02-19 Today's/Total views: 6/3281
After reading Adam's "Password Recovery After Reinstalling Windows 2000" (http://www.sometips.com/t
ips/systemmanagement/331.htm), I also summarized some password recovery methods, although my
purpose is not quite the same as Adam's. In XP, a new feature has already been provided, namely creating
a password recovery disk, which can be used to recover an account password.
Note: these methods are not guaranteed to be 100% successful. If they fail,
the impact may be destructive. I also won't discuss methods that use SAM cracking or exploit system vulnerabilities to break into the system and then change the password.
Method 1:
If you don't care about any of the original accounts in the system, and you have two operating systems, you can boot with
the other operating system (it must be able to access NTFS, otherwise use other tools to access NTFS),
then delete the SAM file under the C:\W
INNT\system32\config directory, that is, the account password database file. Then reboot, and at that time
the administrator account will have no password. Of course,
you can also remove the hard drive and put it in another machine to delete the
SAM file.
Method 2:
Use a DOS boot disk and use the NTFSDOS tool (download location www.cgsecurity.org/index.h
tml?ntfs.html). This tool can write to NTFS partitions from DOS. Then go to the system directory, for example
C:\WINNT\system32, rename logon.scr to logon.scr.bak, and copy a command.com (for 20
00 you can use cmd.exe) file and rename it to logon.scr. Then after booting the machine and waiting 15 minutes, what should have been the screen saver now becomes a command-line mode,
and it has administrator privileges. Through that you can change the password
or add a new administrator account. After you're done, change the screen saver
name back.
Method 3:
Create and use Linux boot disks. This boot disk can access the NTFS file system, and can read the reg
istry and rewrite account passwords. You only need to follow its prompts step by step after booting. The success rate is very high.
This boot disk can be downloaded here: http://home.eunet.no/~pnordahl/ntpasswd/, and there are also
usage instructions there.
Method 4:
You can use some third-party password recovery software.
1. Use the NTAcess tool (http://www.sunbelt-software.com/product.cfm?id=265
This tool can bypass the protection of the system syskey (refer to "Analysis of Alleged Vulnerability in
Windows 2000 Syskey and the Encrypting File System" (http://www.microsoft
com/technet/security/topics/efs.asp)). This tool can reset NT, 2000, and XP passwords
by using a boot disk modified by NTAcess.
2. Passware Kit also provides a tool (http://www.lostpassword.com/windows-xp-2000
-nt.htm) for recovering system passwords. Likewise, this tool also supports various NT systems; for details you can refer to its introduction.
3. Use O&O Bluecon 2000 (http://www.oosoft.com its usage is about the same as the above
third-party software.
There are also many password recovery methods. If you have more methods (excluding the use of third-party software), please contact Refdom@
263.net
Floor4 ko20010214 Posted 2003-06-21 00:00
版主 Posts 1,628 Credits 7,296
Title: A major vulnerability discovered in Microsoft Windows 2000 !!!!!!!!


A major vulnerability discovered in Microsoft Windows 2000
At the logon screen, move the cursor to the username input box and press Ctrl+Shift on the keyboard. At this time, under the default
installation state, the input method status bar will appear. Move the mouse to the input method status bar and right-click it. In the dialog box that appears,
choose Help, then choose Operating Guide or Input Method Introduction
(Microsoft's Pinyin input method and Intelligent ABC do not have this option).
In the Operating Guide or Input Method Introduction window that appears, there will be several buttons, and the key one is the Options button. If it is
a Windows 2000 system without Service Pack 1 or IE5.5 installed, left-click the Options button, and in the dialog box that appears
choose Home Page. At this time, on the right side of the already opened help window, the IE browser "This page cannot be displayed" page will appear,
and there is a link there for checking network settings. Clicking it will bring up the network settings options,
and you can make any changes to network settings or even the Control Panel. Left-click the Options button, and in the dialog box that appears choose
Internet Options; you can also make any changes to the home page, connections, security, advanced options, etc.
Most seriously, if you right-click the Options button, a dialog box will appear. Choose Jump to URL, and then another dialog box will appear,
with an input box for Jump to this URL. Enter any path you want to see, for example c:\ . Then, on the right side of the already opened he
lp window, the Explorer interface for drive C will appear. At this time you already have system administrator privileges and can perform any operation on the data you see.
That means you have bypassed Windows 2000's logon verification mechanism!
If Service Pack 1 or IE5.5 is installed on the Windows 2000 system, the network settings options cannot be executed,
but Internet Options can still be executed. The Explorer interface can still appear. Through path input,
files in all folders and files under the root directory can still be seen, but they can no longer be operated on directly. However, we can still
right-click folders and files and choose Delete, Permanent Delete (hold Shift),
Rename, Send to floppy, and other operations, and can even format the disk!
Or right-click a blank area and choose Web or Thumbnail
view mode, which will leak some files that can be displayed.
Also, we can right-click the drive letter at the upper left corner of the Explorer interface, or any folder, or view any file. In the dialog box for drive letters and folders,
choose Sharing; in the dialog box for a single file, choose Properties. You can arbitrarily add sharing permissions,
for example Everyone, and you can choose the Full Control option. Then as long as this machine is on the network, you can still
log in remotely through the network and fully control all data and materials! That is to say, whether through remote network login
or by physical access to a computer running Windows 2000, we can control everything!
This vulnerability exists in all Windows 2000 systems that have multiple input methods. After such abnormal operations,
after normal login there will also randomly appear various program runtime errors. The temporary solution is:
in Control Panel choose the input method regional option under Regional Options, check the checkbox to enable the indicator on the taskbar,
keep only the one input method you are best at and delete all the rest,
and the internal encoding input method must be deleted! Because the method described below is ineffective against the internal encoding input method.
Then on the taskbar left-click the pen-shaped icon of the input method icon and choose to close the input method status.
--
Floor5 ko20010214 Posted 2003-06-21 00:00
版主 Posts 1,628 Credits 7,296
Floor6 priscilla Posted 2003-06-24 00:00
初级用户 Posts 19 Credits 186
Thank you!
I only knew before that deleting *.pwl under DOS can clear the password for win98 or me.
Floor7 bgn Posted 2003-06-24 00:00
中级用户 Posts 78 Credits 349
Thank you. If I get the chance, I'll try it.
[ Contact the Union admin team - 中国DOS联盟 - Standard version ]
Sponsored by ifanr Inc | © 2001–2023