Tutorial  Updated

Exploitation Of Windows 7 Start Up Repair and Sticky Keys

<!--Not Liable for Damages To System or Any Misuse Of Info-->
<!--Please read the comments in the "Source Of Info" May not work and can mess up your system->


Exploitation of Windows Startup Repair and Sticky Keys:

Boot windows when you see "Starting Windows" Turn off system.

Gkl3MSN.png


Turn on system than boot into windows this should pop up:

pIr536N.png


Click "Launch Startup Repair (recommended)
Let it do it's stuff. When you get this screen push "Cancel" (MUST DO THIS DO NOT CLICK "Restore")

pYxugvA.png


After pushing cancel it should pop up this Screen:

pHCiP16.png


Click on "Show problem details" then scroll down to the bottom and click the link on the very bottom. Notepad should open up. In notepad click File/Open then double click your Local Disk (The below picture is D: because of virtual box but your's should be C: if not using virtual box.)

MAyXFwT.png


Once in your "Local Disk" click "Windows" then "System32" DO EVERYTHING I DO FROM THIS POINT! IF NOT YOU MAY BREAK YOUR COMPUTER! Scroll down and find "cmd," then make a copy of it in the same folder (Ctrl-C, Ctrl-V). You should get a file named "cmd - Copy" or something like that. :

5HMRUFk.png


Then find "sethc" in the same folder. This file runs Sticky Keys (That thing when you click shift to many times.) Rename it to "sethc 1":

F7uuTRG.png


Then rename your copy of cmd ("cmd - Copy") to "sethc"

grcYqLB.png


Now exit Notepad and turn off your computer either by clicking "Finish" or Restart it manually. Now it should boot up to the login screen:

dZF2CDh.png


Click shift 5 times to open up cmd (As seen as above)
Next, we need to find out your local administrator is. To do this type in (To the cmd) "net localgroup Administrators" This will show all the admins on your PC look for an administrator account that does not have your school/work domain in front of it followed by "./" As you can see, one of the admins is named "qwaszx." This is common for schools to use random strings to ward off evil spirits (Kids).

GgF7xE2.png


Now we need to change the admin password to do so type (Into cmd) "net user <ACCOUNT NAME HERE> *" Then type in your new password twice (Into cmd) Now you can log on to the admin account! But some schools/workplaces like to disable this account if so just go and do the following things:

4J0GnCI.png


If admin disabled type "net user <ACCOUNT NAME HERE> /active:yes" This will allow you to access the admin account.

Ny5K0BL.png


(SOURCE OF INFO)
 
Last edited by Luglige,

cracker

Nyah!
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
Many years ago, a friend of mine (a Mac guru) brought in a a daemon for AppleScript. He let me in on the deal and we had some fun. In short, it let you remote execute a script on any Mac it was installed in as long as you knew the IP. We had learned all the IPs so we knew where to send the scripts when people we didn't like came in. Let me make it clear that it was for retaliatory purposes for bullying, etc. One time I sent a script to alert 5000 times to a Mac this girl was working on while she was quite a ways in on a paper she was working on. Quack... quack... quack... *reboots without having saved* Revenge of the nerds!
 
  • Like
Reactions: TheLegendofMario

osaka35

Instructional Designer
Global Moderator
Joined
Nov 20, 2009
Messages
3,740
Trophies
2
Location
Silent Hill
XP
5,950
Country
United States
You know it security is something you can study right ? As joom said there are a lot of things you would need to learn and it could possibly take you several years and after that a lot of your knowledge is outdated again XD

Maybe Start with the Basics like some Network Protokolls ... if you know exactly how they work you can use this to your advantage ... some basic stuff like dns attacks still work usually so that you could build your own gbatemp and make some dns Server Link gbatemp.net to your ip instead of the real one xD

But you need to learn how all those things work ...
I'm at the point where I'm outdated again :P My knowledge is too old to be very functional nowadays, and I'm assuming I should start over and do my best to keep up this time.
 
Last edited by osaka35,

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,076
Country
United States
Many years ago, a friend of mine (a Mac guru) brought in a a daemon for AppleScript. He let me in on the deal and we had some fun. In short, it let you remote execute a script on any Mac it was installed in as long as you knew the IP. We had learned all the IPs so we knew where to send the scripts when people we didn't like came in. Let me make it clear that it was for retaliatory purposes for bullying, etc. One time I sent a script to alert 5000 times to a Mac this girl was working on while she was quite a ways in on a paper she was working on. Quack... quack... quack... *reboots without having saved* Revenge of the nerds!
Code:
chattr +i /Users/*
Much more effective.
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,076
Country
United States
OSX was the first Unix-based Mac OS (based on NeXT). There wasn't anything command-line-wise except maybe 3rd party pseudo-shells.
TIL. Interesting. I've always wanted to throw OS 9 or prior on a VM for shits and giggles. I knew OS X was based on NeXT and code from FreeBSD, though I thought the OS had always shared traits with UNIX systems.
 

VashTS

Beat it, son
Member
Joined
Mar 14, 2009
Messages
4,308
Trophies
1
Age
39
Location
Upstate NY
XP
3,750
Country
United States
Does this change the password to a networked administrator?

I'm trying to do this but I'm afraid it's easy to be caught logging I'm this way
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,076
Country
United States
Does this change the password to a networked administrator?

I'm trying to do this but I'm afraid it's easy to be caught logging I'm this way
No. This only allows you to run a prompt with administrative privileges on the local machine. Changing the password of a network administrator would require access to the issuing host server.
 

VashTS

Beat it, son
Member
Joined
Mar 14, 2009
Messages
4,308
Trophies
1
Age
39
Location
Upstate NY
XP
3,750
Country
United States
No. This only allows you to run a prompt with administrative privileges on the local machine. Changing the password of a network administrator would require access to the issuing host server.

oh so you can't actually login to the admin account or escalate privilege to another account?
 

DarkGabbz

Resident XBOX Guy
Member
Joined
Dec 29, 2015
Messages
1,185
Trophies
0
Age
21
Location
Modding Xbox'es
XP
621
Country
Micronesia, Federated States of
The school laptops that were distributed to my high school were easily exploitable. The IT guys were smart enough to not lock up the local admin account so a bunch of kids (including I) logged onto it. It took them around a month to finally discover it and all they did was call our parents in for a meeting :rofl:. My parents thought I hacked the school servers and I was in deep shit. Once the meeting came along all they told my parents were we logged in to a unprotected account and for me to not do it again.:teach:
I used a live usb and the Admin in school said its illegal to use a live usb on school pc´s:rofl2:
 
  • Like
Reactions: Luglige

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    S @ salazarcosplay: How are you @AncientBoi :tpi: :tpi: :tpi: :tpi: :tpi: