MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD

From: Paul Brown (small_brown@yahoo.co.uk)
Date: 07/13/02


From: "Paul Brown" <small_brown@yahoo.co.uk>
Date: Sat, 13 Jul 2002 02:27:08 -0700


I have found a security loop hole with windows xp that
allows you to set the administrator password to anything
you want!

I was browsing the knowledge base and found an article on
how to reset a corrupted registry. By backing up the
files SAM, SECURITY, SOFTWARE, DEFAULT & SYSTEM from
the 'windows\system32\config\' directory and replacing
them with the same files from 'windows\repair' (a backup
of the registry from the orignal windows load) On my
machine I had since changed the administrator password
and upon reseting these files namely the SAM file my
password went back to its original setting. I then tested
this further by changing the administrator password
to "password" copying the files to cd and replacing the
registry files on my laptop. this worked and i logged in
as administrator. The machine was terribly slow, probably
due to the registry being changed to that from a
different machine but I had managed to login as
administrator within minutes. Please give some feedback
on these findings.



Relevant Pages

  • Re: Repair Windows/Passwd Remedy
    ... How to log on to Windows XP if you forget your password or your password ... > since I could not provide administrator password. ... >> Hi Ray, ... WinXP does not suffer from registry bloat like some ...
    (microsoft.public.windowsxp.general)
  • Re: Repair Windows
    ... I tried to repair Windows without success ... since I could not provide administrator password. ... > A repair installation is similar to the "over the top" installation of old ... WinXP does not suffer from registry bloat like some older ...
    (microsoft.public.windowsxp.general)
  • Re: MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD
    ... This is not a security loop at all, it's a means to reset your password. ... > allows you to set the administrator password to anything ... > how to reset a corrupted registry. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Repair Windows/Passwd Remedy Link
    ... Windows XP Home Edition or Windows XP Professional in a workgroup ... >> since I could not provide administrator password. ... >>> affected only by the replaced entries. ... WinXP does not suffer from registry bloat like some ...
    (microsoft.public.windowsxp.general)
  • Re: MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD
    ... This is why it is always said that Physical Security ... which will automate the registry replacement you ... > allows you to set the administrator password to anything ... > to "password" copying the files to cd and replacing the ...
    (microsoft.public.windowsxp.security_admin)