Re: MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD

From: Ben West (west_ben16@hotmail-no-spam.com)
Date: 07/13/02


From: "Ben West" <west_ben16@hotmail-no-spam.com>
Date: Sat, 13 Jul 2002 12:04:49 +0100


You might notice that the newsgroup has 'public' written in it for a reason!!
This is not a security loop at all, it's a means to reset your password. If the
system already has a password, how do you gain access to the registry?

"Paul Brown" <small_brown@yahoo.co.uk> wrote in message
news:1965c01c22a4f$758cf430$35ef2ecf@TKMSFTNGXA11...
> I have found a security loop hole with windows xp that
> allows you to set the administrator password to anything
> you want!
>
> I was browsing the knowledge base and found an article on
> how to reset a corrupted registry. By backing up the
> files SAM, SECURITY, SOFTWARE, DEFAULT & SYSTEM from
> the 'windows\system32\config\' directory and replacing
> them with the same files from 'windows\repair' (a backup
> of the registry from the orignal windows load) On my
> machine I had since changed the administrator password
> and upon reseting these files namely the SAM file my
> password went back to its original setting. I then tested
> this further by changing the administrator password
> to "password" copying the files to cd and replacing the
> registry files on my laptop. this worked and i logged in
> as administrator. The machine was terribly slow, probably
> due to the registry being changed to that from a
> different machine but I had managed to login as
> administrator within minutes. Please give some feedback
> on these findings.



Relevant Pages

  • Re: MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD
    ... This is why it is always said that Physical Security ... which will automate the registry replacement you ... > allows you to set the administrator password to anything ... > to "password" copying the files to cd and replacing the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD
    ... if you are afraid of this threat, you should use SYSKEY to protect your SAM ... Note that your attack on XP does not expose any user secrets or private ... > allows you to set the administrator password to anything ... > how to reset a corrupted registry. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: MAJOR SECURITY FLAW IN WINDOWS XP - RESET ADMIN PASSWORD
    ... > allows you to set the administrator password to anything ... > how to reset a corrupted registry. ... > of the registry from the orignal windows load) On my ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WINDOWS REGISTRY ERROR
    ... You need the administrator password, not the one you use for your user ... In a WinXP Home system, the administrator account is hidden and no ... C0000218 {Registry File Failure} The registry cannot load the ...
    (microsoft.public.windowsxp.general)