I'm sure this is probably already common knowledge to many but since I hadn't done a great deal of service work on XP machines until recently I just found this out about a week ago. If you have XP Home and haven't set a password on the Administrator account (which isn't normally even accessible under home), you can boot into Safe Mode and log in as Administrator with full admin privileges, including changing the default user's password if I'm not mistaken. I don't know if this is something that they've closed with SP1 or SP2, but I do know that after a clean install from the original XP Home CD, it's still accessible.
+ Reply to Thread
Results 1 to 11 of 11
-
Nothing can stop me now, 'cause I don't care anymore.
-
1st thing you do with ALL OSs is rename the admin account and give it a strong password.
In fact, I rename all built-in accounts. I create a dumby administrator account and limit its access to everything.
BTW, just as bad is the everyone group having full access to your hard drives. Hackers dream! -
The problem is, most XP Home users don't even know the account exists since it's not even listed in the Users section.
Nothing can stop me now, 'cause I don't care anymore. -
Originally Posted by ViRaL1If God had intended us not to masturbate he would've made our arms shorter.
George Carlin -
The real problem is that you can image boot into any XP or
2k box and reset the Admin account with ease.
The only way to block is to remove access to all removable media or block soft/hard resets. -
Image boot? Elaborate.
Nothing can stop me now, 'cause I don't care anymore. -
This was taken care of months ago, I believe.
Microsoft released several patches to keep people with a 2000 disc from accessing the admin account on an xp machine. -
This was taken care of months ago, I believe.
-
Originally Posted by ViRaL1
or cdrom to boot into windoze and reset the admin password.
Most use Isolinux. There are copies avail on the
net. It will still work on non patched XP and Y2k systems.
Search for cd040818.zip -
All you need is a tool called CIA commander, then you can access any PC that has a ntfs drive. it allows you to change the pwd of whichever user you want to change.
Gives a new meaning to physical security of computers.
Similar Threads
-
Popcorn Audio Converter is Backdoor Trojan...
By snadge in forum Video ConversionReplies: 3Last Post: 24th Nov 2015, 09:52 -
BackDoor.Flashback.39 trojan infects Apple computers
By TreeTops in forum Off topicReplies: 5Last Post: 2nd May 2012, 20:18 -
vob2mpg Backdoor.Trojan
By otherwhorl in forum SVCD2DVD & VOB2MPGReplies: 4Last Post: 1st Jan 2010, 03:37 -
Help on Security Issue on PC (Backdoor.bot)
By mn072065 in forum ComputerReplies: 14Last Post: 27th Oct 2009, 20:04 -
Backdoor.Win32.Padodor.gen
By alegator in forum ComputerReplies: 3Last Post: 24th Mar 2008, 02:10