WELCOME GUEST ENJOY YOUR STAY HERE...

TELL A FRIEND ABOUT US.. Share/Save/Bookmark
Showing posts with label admin. Show all posts
Showing posts with label admin. Show all posts

Thursday, August 20, 2009

Hack Windows Vista Admin/Administrator Account password.

Please take note that this handy tip is intended to recover/regain a forgotten Vista Administrator password. It is not intended to illegally hacking into a Vista system that's not owning by users who refer this guide!!
It is also intended to inform Vista users about the method by which anyone can access their private accounts by cracking passwords....Thus anyone can hack into administrator account and bypass guest user restrictions....
Lets start...
Steps to hack Windows Vista Administrator account password:
1. Reboot the Windows Vista and boot up with Windows Vista installation DVD.
Crack Windows Vista logon account password in minute with the Windows Vista installation DVD. Click on the Repair Your Computer option, bring up Command Prompt to open Local Users and Groups management in MMC.
2. While the Windows Vista installation interface pops up, click the Repair You Computer link at the bottom-left corner.
3. Next, the System Recovery Options dialog box appears. There are few options that related to repairing Windows Vista, looks like Recovery Console in Windows XP:
Startup Repair options is used to automatically fix problems that are preventing Windows Vista from starting.
System Restore to restore Windows Vista setting to an earlier point in time.
Windows Complete PC Restore to restore Windows Vista from a full system backup.
Windows Memory Diagnostic Tool could be the first Microsoft memory tester toolkit that bundled with Windows setup media.
Command Prompt is the target option of this Vista hacking guide. Click on this option now.
4. In the Windows Vista Command Prompt, type mmc.exe and press ENTER key to bring up the Microsoft Management Console.
5. Click on the File menu, select Add / Remove Snap-in option, locate and select the Local Users and Groups on the left panel, and click Add button to add it to the right panel.
6. Now, the Choose Target Machine dialog box pop up. Keep the default setting by clicking the Finish button - that means using the Local Users and Groups snap-in to manage this local computer, and not another computer in network.
7. Click OK button and return to MMC windows. Under the Root Console in left panel, double- click Local Users and Group that was added earlier. Click on User folder, locate and right-click the target Vista logon account that found in the right panel.
Select the Set Password from the right-click menu to set a new password / reset old password.
Note this does not work on all versions of Vista. But, it can be used to hack administrator account password of Windows Vista...
Further Read:
Hacking Password Protected Laptops
Vista tips,tricks and tweaks
Activate Administrative shares on Vista

Monday, August 17, 2009

Hacking Password Protected Laptops

Password protecting a laptop does not ensure data protection, the password protection of laptops provides a false sense of security. Passwords on laptops are good to implement to prevent unauthorized access, however when a thief steals a laptop and has time, getting around the password is quite simple. There are also issues if there was no way to get around passwords, as even admins forget them and need access to the system. Passwords are good to have, but will not stop a thief from accessing the device, only slow them down a bit. Here is a quick run through of some common techniques for getting around the passwords for different platforms:
Windows XP & Vista
Windows can be cracked using several available tools one popular one is OphCrack, which is free. The software can works with Windows, Mac OS X and Linux. It comes with a LiveCD version which automates the retrieval, decryption, and cracking of passwords from a Windows system. The latest version uses a new faster technique using rainbow tables and can crack 99.99 % of alphanumeric passwords of up to 14 characters in usually a few seconds, and at most a few minutes. The software works with older versions of Windows as well. Another commerical product is Proactive Password Auditor from Elcomsoft. The software utilizes similar techniques to OphCrack but with a bit more automation and a friendlier user interface. The product basically makes password a mainstream technique that anyone can use to gain access to a system.
OS X
For OS X 10.4 The root password can be easily reset in OS X by booting the system from the Mac OS X installation CD and selecing the Reset password option under "Utilities" from the installer screen and follow the directions. OS X 10.5 can be reset using single user mode. (hold down 'Command' and 'S' during reboot or startup.) At the prompt, type fsck -fy Type mount -uw /Type launchctl load /System/Library/LaunchDaemo ns/com.apple.DirectoryServices. plist Type dscl. -passwd /Users/username newpassword replace with the real "username" and follow with the new password, as shown.
Linux
Boot Linux into single-user mode
Reboot the machine.
Press the ESC key while GRUB is loading to enter the menu.
If there is a 'recovery mode' option, select it and press 'b' to boot into single user mode.
Otherwise, the default boot configuration should be selected. Press 'e' to edit it.
Highlight the line that begins with 'kernel'. Press 'e' again to edit this line.
At the end of the line, add an additional parameter: 'single'. Hit return to make the change and press 'b' to boot.
Change the admin password
The system should load into single user mode and you'll be left at the command line automatically logged in as root. Type 'passwd' to change the root password or 'passwd someuser' to change the password for your "someuser" admin account.
Reboot
Enter 'reboot' to restart into your machine's normal configuration.
These are just a few techniques used to get around password protection on laptops. The first thing that should be implemented is making passwords longer, a 14 character password can be cracked in a matter of minutes. Most IT administrators require a password of 8 characters, this is not sufficient. It is better to devise a phrase instead of just a word.
Encryption, Encryption, Encryption
If you have sensitive information on your system, it is important to ensure that the data is encrypted, many operating systems have this built-in and there is also free encryption tools such as TrueCrypt that provide excellent encryption, so even if your password protected laptop is cracked, your data is still secure, just make sure you use a different password for your encrypted drive.

Friday, August 14, 2009

Create Hidden Admin Account in XP

Since we are going to do all the Editing in Window Registry it is Recommended to Back Up the Registry before going Further. After you have Backed up your registry follow the Steps to Create your Hidden Account:
First Goto Start -> Run -> Type regedit -> Enter
In the Left Menu goto,
HKEY_LOCAL_MACHINE\Softwa re\Microsoft\WindowsNT\Curre ntVersion\Winlogon\SpecialAcc ounts\UserList
In the Right pane, Right click -> New -> String Value
Right click on the new String Value and click Rename
Type the Name of the Account you want to hide.
Hit Enter then Right click on the String Value again and Change value to 0 which hides it. If you want it to be Visible to all Enter the Value 1.
Now Save and Exit the Registry and Logoff.
Goto welcome screen and Hit ctrl+ alt+del twice to bring up Logon prompt
Type hidden Accounts name and password
Enjoy!!!

Sunday, August 2, 2009

HACKING WEBPAGES...

Getting the Password File Through FTP
Ok well one of the easiest ways of getting superuser access is through
anonymous ftp access into a webpage. First you need learn a little about
the password file...
root:User:d7 Bdg:1 n2 HG2 :1127 :20:Superuser
TomJones:p5 Y(h0 tiC:1229 :20:Tom Jones,:/usr/people/tomjones:/b in/csh
BBob:EUyd5 XAAtv2 dA:1129 :20:Billy Bob:/usr/people/bbob:/bin/csh
This is an example of a regular encrypted password file. The Superuser is
the part that gives you root. That's the main part of the file.
root:x:0 :1:Superuser:/:
ftp:x:202 :102 :Anonymous ftp:/u1/ftp:
ftpadmin:x:203 :102 :ftp Administrator:/u1/ftp
This is another example of a password file, only this one has one little
difference, it's shadowed. Shadowed password files don't let you view or
copy the actual encrypted password. This causes problems for the password
cracker and dictionary maker(both explained later in the text). Below is
another example of a shadowed password file:
root:x:0 :1 :0000 - Admin(0000):/:/usr/bin/csh
daemon:x:1 :1 :0000 -Admin(0000):/:
bin:x:2 :2 :0000 - Admin(0000):/usr/bin:
sys:x:3 :3 :0000 -Admin(0000):/:
adm:x:4 :4 :0000 - Admin(0000):/var/adm:
lp:x:71 :8 :0000 - lp(0000):/usr/spool/lp:
smtp:x:0 :0:mail daemon user:/:
uucp:x:5 :5 :0000 - uucp(0000):/usr/lib/uucp:
nuucp:x:9 :9 :0000 - uucp(0000):/var/spool/uucppubl ic:/usr/lib/uucp/uucico
listen:x:37 :4:Network Admin:/usr/net/nls:
nobody:x: 60001 : 60001 :uid no body:/:
noaccess:x: 60002 : 60002 :uid no access:/:
webmastr:x:53 :53:WWW Admin:/export/home/webmastr :/usr/bin/csh
pin4 geo:x:55 :55 :PinPaper Admin:/export/home/webmastr /new/gregY/test/pin4geo:/bin/ false
ftp:x:54 :54:Anonymous FTP:/export/home/anon_ftp:/bi n/false
Shadowed password files have an "x" in the place of a password or sometimes
they are disguised as an * as well.
Now that you know a little more about what the actual password file looks
like you should be able to identify a normal encrypted pw from a shadowed
pw file. We can now go on to talk about how to crack it.
Cracking a password file isn't as complicated as it would seem, although the
files vary from system to system. 1.The first step that you would take is
to download or copy the file. 2. The second step is to find a password
cracker and a dictionary maker. Although it's nearly impossible to find a
good cracker there are a few ok ones out there. I recomend that you look
for Cracker Jack, John the Ripper, Brute Force Cracker, or Jack the Ripper.
Now for a dictionary maker or a dictionary file... When you start a
cracking prog you will be asked to find the the password file. That's where
a dictionary maker comes in. You can download one from nearly every hacker
page on the net. A dictionary maker finds all the possible letter
combinations with the alphabet that you choose(ASCII, caps, lowercase, and
numeric letters may also be added). We will be releasing our pasword file
to the public soon, it will be called, Psychotic Candy, "The Perfect Drug."
As far as we know it will be one of the largest in circulation. 3. You then start up the cracker and follow the directions that it gives
you.
The PHF Technique
Well I wasn't sure if I should include this section due to the fact that
everybody already knows it and most servers have already found out about
the bug and fixed it. But since I have been asked questions about the phf
I decided to include it.
The phf technique is by far the easiest way of getting a password file
(although it doesn't work 95% of the time). But to do the phf all you do
is open a browser and type in the following link:
http://webpage_goes_here/cgi- bin/phf?Qalias=x%0 a/bin/cat%20/etc/passwd
You replace the webpage_goes_here with the domain. So if you were trying to
get the pw file for www.webpage.com you would type:
http://www.webpage.com/cgi- bin/phf?Qalias=x%0 a/bin/cat%20/etc/passwd
and that's it! You just sit back and copy the file(if it works).
The best way to get root is with an exploit. Exploits will be explained soon.,enjoy

Follow Me... Stay Connected

MY STATS

Top Blogs

Learn hacking tips tricks earn online hints cheats

Blog Directory & Search engine

blogarama - the blog directory

BlogsByCategory.com

Technology Blogs - Blog Rankings

Visit blogadda.com to discover Indian blogs

Computers

Computers Blogs