20 ms·
How to get into an admin account on a Windows computer
- x0n 12y agoPhysical access and all bets are off. This is not a vulnerability.
- dsacco 12y agoNo, but it is interesting to know methods like this. You can achieve admin on an OS X machine by adding a new one like so: 1. Enter single user mode via cmd + s during startup. 2. Mount the hard drive via /sbin/mount/ -uw / 3. Delete the setupdone check via rm /var/db/.applesetupdone 4. Reboot, and now you are presented with the wizard for adding a new admin account.
- fuzzix 12y agoI remember someone (not me, oh no...) used one for NT4 with inadequate policies to get Admin access. Create a batch file with the content: net localgroup administrators NewUser /add ...then stick this into the 'StartUp' directory for All Users. Break something. Call support. They log in as Administrator, running your batch file in the process. NewUser would be created with Admin rights. You wouldn't promote your own login, of course.
- M4v3R 12y agoOf course this is only possible if FileVault is disabled, otherwise you would not be able to mount the hard drive without user's password.
- Leszek 12y agoIn which case, why bother with user passwords at all?
- nolok 12y agoTo ward off the dummy 99%. You can't stop a guy who knows what he's doing, but you can stop Josie from the next desk snooping around in HR's file. Also, it causes a breach, which depending on where you live might be needed to show intent.
- msl09 12y agoYou do not want that binary that you have downloaded to be able to do a privilege escalation without your consent. Also, some people may feel like changing your wallpaper to something inappropriate, but they may not be motivated enough to hack your pc.
- baby 12y agoI can't remember it correctly but there is a saying along these lines: most people would open your door if there was no lock on it. Eventhough it's useless.
- daigoba66 12y agoSame reason we put locks on our doors. If someone is really serious, he or she can (destructively) break in. But a locked door will prevent someone from casually getting in.
- audunw 12y agoBIOS password lock, and physical lock on computer and/or an environment where it is hard to open the computer without being detected (work/school) makes other options hard. This exploit you could even pull off on a school lab computer while the teacher is in the room. If he comes over while you're working, inconspicuously power off the machine.
- dguido 12y agoThis is a vulnerability. This attack does not require physical access. Do you really think that startup repair mode is required to swap the position of cmd.exe and sethc.exe?
- Someone1234 12y agoThe Repair Tool requires unrestricted physical access, it is running as administrator. The same way that a Live CD could. > Do you really think that startup repair mode is required to swap the position of cmd.exe and sethc.exe? A Live CD/DVD would work just as well. As would a USB-based OS. You could also (although it would require more work) use network boot to run your own code. There's no vulnerability, this is unfixable, you just have to secure the system using full disk encryption and secure boot.
- x0n 12y agoNo, it's not, because sethc.exe resides in %systemroot%\system32 - an area that is protected by ACLs, only allowing regular users read access. Going into startup repair mode grants system-level access to files there. Without repair mode, users cannot swap these files.
- tomp 12y agoTry doing that with my phone. I think (hope?) you wouldn't succeed.
- Someone1234 12y agoYou can do this with a phone or tablet (Android). That's essentially how many root exploits are accomplished, boot into the default recovery (typically hold volume up during power on), run a script, and recovery replaces key files which are used later to provide you with root. This is less common NOW, but back in the Android 2.xx days it was the defacto way of getting root.
- utxaa 12y agoencrypting helps no? maybe not all bets are off in that case.
- diminoten 12y agoWhat? It absolutely is a vulnerability, insofar that it allows unintended access to a computer system. That's like saying, "Car door was open, therefore not theft."
- richthegeek 12y agoWow this takes me back to busting into Windows 98 via the Help > Print > something > Explorer method. Actually, someone linked to something like it in the comments: https://i.imgur.com/n9Th4q5.jpg https://i.imgur.com/n9Th4q5.jpg I can't imagine how difficult it must be to secure a login system with so much added surface due to accessibility and dumb users.
- tomp 12y agoIt's very simple really; just don't run any external programs. Better still would be to limit the permissions of each specific executable (like iOS does), but that's not how Windows was designed...
- jlgaddis 12y agoIt's been a little while (obviously) but, if memory serves, all you had to do on Windows 98 was click "Cancel" at the logon screen.
- ominous 12y agouser comment on imgur: "As a network manager, disable startup repair via group policy. Fixed." Does this fix it?
- IkmoIkmo 12y agoJust this one method, yeah. But unless you encrypt your harddrive you're not going to really get security when someone has physical access to your device.
- arca_vorago 12y agoThere are other things you can do though. FDE, encrypted bootloader, BIOS passwords (on boot if important enough), removal of DVD Drive/USB ports as an option. Security isn't binary, it's about layers and compromises based on use case.
- cordite 12y agoIf the trick is to modify the contents of the file system, then surely booting from a Linux stick or likewise could suffice too.
- mkaufmann 12y agoYes because the recovery menu won't be accessible than (which is needed to replace the sticky key executable) The settings can be changed with bcdedit: bcdedit /set {default} recoveryenabled No bcdedit /set {default} bootstatuspolicy ignoreallfailures Additionally booting from USB/... should be disabled in the BIOS/UEFI options and also access to that should be password secured. Further more because the person has physical access, the computer should be locked away so that the harddrive can't be accessed. Also all cables should be secured so that no sniffer can be plugged in between. This also especially includes the USB ports on the monitor if those are enabled.
- arca_vorago 12y agoNote: Make sure to run bcdedit commands with elevated privileges. I am currently working on adding this into my ansible test AD replacement.
- runeks 12y agoIf you have physical access to the PC, why not just boot up Ubuntu, and replace the files that need replacing? No need to rely on a feature in Windows that can be disabled. If full-disk encryption isn't used, there's really not much the underlying OS can do to prevent this.
- sauere 12y agoPhysical-access always means "game over" unless full-disk encryption is used.
- ygra 12y agoIn this case FDE won't help, right? As the OS already can read the hard drive during the repair phase (or otherwise can't get that far).
- DangerousPie 12y agoIt looks like you can only launch the repair once you have decrypted the hard drive [1]. [1] http://answers.microsoft.com/en-us/windows/forum/windows_7-system/running-windows-7-repair-on-a-bitlocker-encrypted/89e2cae0-7d49-4cc4-981e-3776701bbf4b http://answers.microsoft.com/en-us/windows/forum/windows_7-s...
- DanBlake 12y agoYou can do a entire dump of the HD while its turned on and save it to a backup. Then you can restore the backup back to the initial HD
- r3bl 12y agoCould you link some kind of a guide about what should be changed from a Live CD/USB?
- ominous 12y agoAccording to step 7 and 8, you only need to create a copy of the cmd binary and name it sethc. Here's a 'guide' from 2012 http://carnal0wnage.attackresearch.com/2012/04/privilege-escalation-via-sticky-keys.html http://carnal0wnage.attackresearch.com/2012/04/privilege-esc... And here's a 'fix' from microsoft: https://social.technet.microsoft.com/Forums/windows/en-US/a3968ec9-5824-4bc2-82a2-a37ea88c273a/sticky-keys-exploit https://social.technet.microsoft.com/Forums/windows/en-US/a3...
- slenk 12y agoIf they use BitLocker, you can't get to the startup repair without the recovery key...
- dguido 12y agoStartup repair is not necessary to use the sethc trick.
- vkr 12y agoIf booting from a CD or USB is allowed, you can just change the password using the Pogostick [1] live cd - or any linux live cd. [1] http://pogostick.net/~pnh/ntpasswd/ http://pogostick.net/~pnh/ntpasswd/
- dguido 12y agoAnd then you can't set it back (since you don't know what it is), so the owner of the machine would immediately know you were there. They wouldn't be able to log in.
- xenophonf 12y agontpasswd isn't a pentesting tool; it's a recovery tool.
- StuffMaster 12y agoActually you can, by exporting/importing the right registry keys. Or at least you could on XP.
- zarify 12y agoI found out about this method last week and it's my new favorite after having to fix up a couple of weird situations caused by someone joining their laptop to the school domain, and someone locking themself out of their only admin account. I was quite surprised to find that the command shell ran with admin privs from before the login process, since I was unable to elevate in any other way (including by trying system restore back before joining, or trying to get into safe mode).
- dguido 12y agoMake sure to set it back when you're done! If you don't, then an unauthenticated RDP session can use this trick to login to the machine you fixed.
- xenophonf 12y agoThis is the de facto standard for local lost-admin-password resets since Windows NT was released, although back in the day the trick was to change the login screen saver to the command interpreter. The imgur album is a nice touch, I guess, but if you do a web search for "windows lost admin password" (or similar), you'll get some variation on these instructions.
- cesarb 12y agoI had to do this once to change the password of a machine's account (the machine's previous user had left the company). Of course, I used an Ubuntu live DVD to do the file renaming. It's the cleanest method, since it allows you to use Window's own routines to change the password, instead of an external program which might miss updating something. But the interesting part of this post is the trick to do the file renaming without having to boot from any external media. This bypasses any security preventing the use of external media. Even if a user has access only to the keyboard, mouse, and power button (or can cut the power by pulling the cable), he can use this trick to do the file renaming and gain local admin access.
- xenophonf 12y agoIt isn't exactly novel. Using the Windows Recovery Environment (however you get there) is exactly how this has been accomplished since the introduction of WinRE in Vista.
- dEnigma 12y agoHad to do something similar at work a couple months ago when a Windows computer somehow ended up without a single account with administrator privileges but I replaced magnifier.exe with cmd (for some reason I even switched them around) and then opened the supercharged "magnifier" on the login screen. I also didn't use "Startup repair" but a Ubuntu Live CD. I then got called away from the computer before I could switch magnifier and cmd back to normal and somebody started using the computer again, with hilarious consequences (Note: I'm not the IT guy in this company xD)
- deleted 12y ago[deleted]
- blueskin_ 12y agoAnyone who hates annoyance will already have disabled the stickykeys shortcut. A more reliable way if you're somewhat prepared is to just use a live linux system and NTPasswd. Any distro that can be installed to a flash drive should have it available.
- chdir 12y agoIs there a good software (preferably open) to remotely kill/erase your data on a Windows machine. Not all versions have bitlocker. Truecrypt's future is unpredictable.
- dr_zoidberg 12y agoAny "secure eraser" - those programs that rewrite the contents of a file before deletion - does the job. Despite what is claimed (even by those programs and their developers), just 1 pass zeroing out the data is enough to securely delete information from a HDD. Usually they reference a government document that says that physical destruction of the media is the only correct method to erase TOP SECRET (and above) data, but that is mostly paranoid burocracy. If you're using a SDD however, you have to deal with firmware wear-leveling, garbage collection and the drive having a lot of GBs hidden from everyone, even the OS. There are some proposed techniques to force an unavailable block back into the available pool and then reading long-deleted data. Afaik, there's little you can do in this scenario, even full disk encryption might not help you with the old data blocks that are still waiting to be zeroed by the GC. Then again, like you said, FDE is probably the easiest way. TrueCrypt was vulnerable to some on-memory-key attacks, but for data killing its more than enough. There are some projects that have forked TCs code, and there also the old version available thats still fully functional.
- jjoonathan 12y agoIt's worth mentioning that there are ATA commands for secure erase these days. https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase If you have a linux box handy, you can probe your ATA-compatible drives with: root# hdparm -I /dev/X look for: Security: Master password revision code = 65534 supported enabled not locked not frozen not expired: security count supported: enhanced erase Security level high 2min for SECURITY ERASE UNIT. 2min for ENHANCED SECURITY ERASE UNIT. "Enhanced Security Erase Unit" should get all of the sectors that have been previously used even on a SSD with wear leveling. Of course, you still have to trust that the vendor has correctly implemented it. I have no idea what best practices are in that regard. If anybody here has a better idea, I'd love to hear (Is FIPS certification a good sign? If the drive implements encryption and can therefore do a secure erase by dropping the keys can it be trusted? Can drive vendors generally trusted to not use ECB mode? etc.)
- dguido 12y agoThis trick is widely used by hackers to maintain persistent access to large enterprise networks. You can RDP around and press Shift 5 times to pop up the cmd.exe on machines you've modified. No malware needed. Performing this modification DOES NOT require rebooting the computer into startup repair if you have admin access (which is typical after you get hacked). There is a process that watches system32 for modifications and resets them, but if you script it and change the files fast enough it won't notice. The utility of this trick is really insane. Would you realize that a hacker had backdoor access to your computer via RDP if the only thing that was modified was cmd.exe and sethc.exe swapping places?
- benplumley 12y agoSurely the thing you'd notice so you could lock them out is admin passwords being changed? Not that this fixes the root of the problem, it would just make you aware that you had a problem.
- ikeboy 12y agoOr you can boot from kon-boot. That makes any password work for login, but only once, and it's undetectable after a reboot. http://piotrbania.com/all/kon-boot/index2.html http://piotrbania.com/all/kon-boot/index2.html is the free version, which can be installed with http://www.pendrivelinux.com/yumi-multiboot-usb-creator/ http://www.pendrivelinux.com/yumi-multiboot-usb-creator/. That only works on 32-bit systems and up to Windows 7. If you want the paid version, you can either buy it from http://www.piotrbania.com/all/kon-boot/ http://www.piotrbania.com/all/kon-boot/, or get it from http://kickass.so/kon-boot-v2-4-remedy-for-lost-password-mumbai-tpb-t8760369.html http://kickass.so/kon-boot-v2-4-remedy-for-lost-password-mum... or your usual source.
- lawl 12y agoPublicly advertizing warez is probably a bad idea. I'm pretty sure everyone interested on here is able to find the "usual sources".
- psykovsky 12y agoPublicising warez of a cracking tool will bring him problems?
- lawl 12y agoWhat constitues as "cracking tool" in your opinion? Ahould the tools locksmith's use also be considered illegal and therefore you can steal them? Of course not. There are many valid usecases for tools like this. Especially for people working as sysadmins.
- ericlathrop 12y agoI did exactly this over the holidays to get into a deceased family member's computer.
- stephengillie 12y agoWow, it took 5 days for this to get reposted on HN? It's kinda cool watching the web go round. (https://imgur.com/gallery/H8obU/comment/356517825 https://imgur.com/gallery/H8obU/comment/356517825)
- utxaa 12y agothis is nothing new. why go through all the trouble? just take the disk out and mount it elsewhere. that's why one has to encrypt drives.
- sixothree 12y agoWouldn't this give you access to EFS files?
- crb 12y agoAs Raymond Chen would say: "it rather involves being on the other side of this airtight hatchway".
- discreditable 12y agoThis is one reason why we use BitLocker with TPM unlock on all of our student PCs. If the system is booted in an usual way like this, the disk won't unlock. We had issues our first year with a student who booted a Linux DVD and reset the local administrator password and another instance where the student removed the hard drive to do the same (after we'd locked our BIOS settings). Encrypting the drives has 100% prevented these problems, and makes us feel better about sending failed drives to vendors without wiping them.
- Shank 12y agoIf your students can physically remove the hard drive, you should consider physical security rather than software security.
- Someone1234 12y agoWhat exactly are you suggesting? Those dumb case keys everyone now has? Or security screws? CCTV likely won't help as you cannot realistically get 100% coverage of every lab on site. So while it might stop someone walking out with a tower (or ID them), it wouldn't stop anyone doing this... Honestly software security is the optimal solution. It solves a whole host of threat models (alternative boot media, repair tool, HDD removal, stolen machines, HDD warranty data leaks, lost laptops, etc). All physical security does with that in place is stop someone stealing your internal components, but it is expensive to do well and relatively easy to defeat with just a screwdriver or paperclip (and "unlimited" time).
- discreditable 12y agoThese are laptops that the students take home with them. The lab computers are physically secured.
- driverdan 12y agoIf the student knows enough to boot Linux and remove admin passwords why don't you just let them have admin access?
- pjc50 12y agoI think it's now two decades since I first found how to overwrite BIOS passwords from MS-DOS QBasic in order to break into school computers. Somehow reassuring that kids are still doing the same thing. The comments about bitlocker and TPM are a good reminder that he who controls the boot sequence controls the computer / phone / car / IoT toaster.
- bohol 12y agoYou can of course also make quite convincing BIOS password prompts with QBasic.
- knodi123 12y agothat's how I got in trouble for hacking in high school; used our pascal IDE (in DOS) to make a perfect replica of our fancy ASCII login. It would capture your username and password, and then spit you back out to the real prompt. I only got caught because I kept all my stolen logins in my home dir, in passwords.txt. I talked the teacher into canceling all of my detentions in return for showing him how to secure his bootdisks. Man, kids today would just get expelled or go to jail. I'm glad I grew up when I did.
- path411 12y agoI graduated from HS 9 years ago and I almost got suspended from all computer access, ended up getting some detentions, and various other punishments just for using Firefox. (Would have hated to see what the naive principal would have dished out if I wasn't one of the top students in my class)
- knodi123 12y agoThat's the truth. I went to s particularly safe middle school, so when we had a random weapons sweep with metal detectors, only 3 students got caught. I was one of them; I had my little 1" swiss army knife, one girl had a steel nail file with a sharp point, and a mexican kid had a 3" folding buck knife. Me and the girl were white honor students, and we were let off with a stern warning, and our "weapons" were handed to our parents. The mexican kid with poor english skills got sent to an alternative school (the kind for disciplinary risk kids).
- bigp3t3 12y agoI refer to it as the sticky-keys hack. Been using it since before I left High School. (admittedly only 5 years ago)
- runjake 12y agoWhy is this on here and not flagged? Similarly, on any UNIX OS, you can boot into single-user mode and obtain root access. These are ancient techniques. The obligatory response every. single. time this is brought up: Local access? All bets are off. (With certain caveats, of course).
- bonif 12y agoRemembers me of the ol' winnuke days (windows 95)