Tutorial  Updated

Exploitation Of Windows 7 Start Up Repair and Sticky Keys

<!--Not Liable for Damages To System or Any Misuse Of Info-->
<!--Please read the comments in the "Source Of Info" May not work and can mess up your system->


Exploitation of Windows Startup Repair and Sticky Keys:

Boot windows when you see "Starting Windows" Turn off system.

Gkl3MSN.png


Turn on system than boot into windows this should pop up:

pIr536N.png


Click "Launch Startup Repair (recommended)
Let it do it's stuff. When you get this screen push "Cancel" (MUST DO THIS DO NOT CLICK "Restore")

pYxugvA.png


After pushing cancel it should pop up this Screen:

pHCiP16.png


Click on "Show problem details" then scroll down to the bottom and click the link on the very bottom. Notepad should open up. In notepad click File/Open then double click your Local Disk (The below picture is D: because of virtual box but your's should be C: if not using virtual box.)

MAyXFwT.png


Once in your "Local Disk" click "Windows" then "System32" DO EVERYTHING I DO FROM THIS POINT! IF NOT YOU MAY BREAK YOUR COMPUTER! Scroll down and find "cmd," then make a copy of it in the same folder (Ctrl-C, Ctrl-V). You should get a file named "cmd - Copy" or something like that. :

5HMRUFk.png


Then find "sethc" in the same folder. This file runs Sticky Keys (That thing when you click shift to many times.) Rename it to "sethc 1":

F7uuTRG.png


Then rename your copy of cmd ("cmd - Copy") to "sethc"

grcYqLB.png


Now exit Notepad and turn off your computer either by clicking "Finish" or Restart it manually. Now it should boot up to the login screen:

dZF2CDh.png


Click shift 5 times to open up cmd (As seen as above)
Next, we need to find out your local administrator is. To do this type in (To the cmd) "net localgroup Administrators" This will show all the admins on your PC look for an administrator account that does not have your school/work domain in front of it followed by "./" As you can see, one of the admins is named "qwaszx." This is common for schools to use random strings to ward off evil spirits (Kids).

GgF7xE2.png


Now we need to change the admin password to do so type (Into cmd) "net user <ACCOUNT NAME HERE> *" Then type in your new password twice (Into cmd) Now you can log on to the admin account! But some schools/workplaces like to disable this account if so just go and do the following things:

4J0GnCI.png


If admin disabled type "net user <ACCOUNT NAME HERE> /active:yes" This will allow you to access the admin account.

Ny5K0BL.png


(SOURCE OF INFO)
 
Last edited by Luglige,

cracker

Nyah!
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
Many years ago, a friend of mine (a Mac guru) brought in a a daemon for AppleScript. He let me in on the deal and we had some fun. In short, it let you remote execute a script on any Mac it was installed in as long as you knew the IP. We had learned all the IPs so we knew where to send the scripts when people we didn't like came in. Let me make it clear that it was for retaliatory purposes for bullying, etc. One time I sent a script to alert 5000 times to a Mac this girl was working on while she was quite a ways in on a paper she was working on. Quack... quack... quack... *reboots without having saved* Revenge of the nerds!
 
  • Like
Reactions: TheLegendofMario

osaka35

Instructional Designer
Global Moderator
Joined
Nov 20, 2009
Messages
3,745
Trophies
2
Location
Silent Hill
XP
5,979
Country
United States
You know it security is something you can study right ? As joom said there are a lot of things you would need to learn and it could possibly take you several years and after that a lot of your knowledge is outdated again XD

Maybe Start with the Basics like some Network Protokolls ... if you know exactly how they work you can use this to your advantage ... some basic stuff like dns attacks still work usually so that you could build your own gbatemp and make some dns Server Link gbatemp.net to your ip instead of the real one xD

But you need to learn how all those things work ...
I'm at the point where I'm outdated again :P My knowledge is too old to be very functional nowadays, and I'm assuming I should start over and do my best to keep up this time.
 
Last edited by osaka35,

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
Many years ago, a friend of mine (a Mac guru) brought in a a daemon for AppleScript. He let me in on the deal and we had some fun. In short, it let you remote execute a script on any Mac it was installed in as long as you knew the IP. We had learned all the IPs so we knew where to send the scripts when people we didn't like came in. Let me make it clear that it was for retaliatory purposes for bullying, etc. One time I sent a script to alert 5000 times to a Mac this girl was working on while she was quite a ways in on a paper she was working on. Quack... quack... quack... *reboots without having saved* Revenge of the nerds!
Code:
chattr +i /Users/*
Much more effective.
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
OSX was the first Unix-based Mac OS (based on NeXT). There wasn't anything command-line-wise except maybe 3rd party pseudo-shells.
TIL. Interesting. I've always wanted to throw OS 9 or prior on a VM for shits and giggles. I knew OS X was based on NeXT and code from FreeBSD, though I thought the OS had always shared traits with UNIX systems.
 

VashTS

Beat it, son
Member
Joined
Mar 14, 2009
Messages
4,308
Trophies
1
Age
39
Location
Upstate NY
XP
3,762
Country
United States
Does this change the password to a networked administrator?

I'm trying to do this but I'm afraid it's easy to be caught logging I'm this way
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
Does this change the password to a networked administrator?

I'm trying to do this but I'm afraid it's easy to be caught logging I'm this way
No. This only allows you to run a prompt with administrative privileges on the local machine. Changing the password of a network administrator would require access to the issuing host server.
 

VashTS

Beat it, son
Member
Joined
Mar 14, 2009
Messages
4,308
Trophies
1
Age
39
Location
Upstate NY
XP
3,762
Country
United States
No. This only allows you to run a prompt with administrative privileges on the local machine. Changing the password of a network administrator would require access to the issuing host server.

oh so you can't actually login to the admin account or escalate privilege to another account?
 

DarkGabbz

Resident XBOX Guy
Member
Joined
Dec 29, 2015
Messages
1,185
Trophies
0
Age
21
Location
Modding Xbox'es
XP
621
Country
Micronesia, Federated States of
The school laptops that were distributed to my high school were easily exploitable. The IT guys were smart enough to not lock up the local admin account so a bunch of kids (including I) logged onto it. It took them around a month to finally discover it and all they did was call our parents in for a meeting :rofl:. My parents thought I hacked the school servers and I was in deep shit. Once the meeting came along all they told my parents were we logged in to a unprotected account and for me to not do it again.:teach:
I used a live usb and the Admin in school said its illegal to use a live usb on school pc´s:rofl2:
 
  • Like
Reactions: Luglige

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Thought it was some warzone dlc bs
  • Psionic Roshambo @ Psionic Roshambo:
    Looks like an enhanced Far cry 1
  • K3Nv2 @ K3Nv2:
    That's a far cry from it
  • BigOnYa @ BigOnYa:
    Is it a free to play bs, pay to get any good weapon/gear
  • K3Nv2 @ K3Nv2:
    Not free to play but $35
  • K3Nv2 @ K3Nv2:
    Inb4 kiiwii gives it a 0/10
  • BigOnYa @ BigOnYa:
    6/10 rating on steam
  • Psionic Roshambo @ Psionic Roshambo:
    I would like a Predator game "Kill Team" it takes place in the Jungle of the first movie, your team is sent to hunt the predator, using current tech drones and a trained team. Set traps use strategy to hunt and trap or kill the predator.
  • BigOnYa @ BigOnYa:
    Ill stick with my Battlefield. Yea a predator hunting game like that would be cool. Esp if you can be Arnold and say "Get to da choppa"
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Maybe Arnold could do a cameo voice acting, he is the one briefing you on the mission
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Honestly surprised they didn't make a tie in game for Predators that movie was awesome
  • Psionic Roshambo @ Psionic Roshambo:
    I was kinda sad the Yakuza guy died sword fighting a predator lol
  • Psionic Roshambo @ Psionic Roshambo:
    The Russian guy went out like a boss
  • Psionic Roshambo @ Psionic Roshambo:
    Double claymores to the face definitely kill a predator lol
  • BigOnYa @ BigOnYa:
    I went today and looked at a motorcycle someone was selling. I get there and the battery on it was dead, so the guy grabbed a battery charger and hooked it up. He plugged it into the wall, and the motorcycle sparked and started smoking. Come to find out the bike uses a 6 volt battery and the guy had the charger set to 12v. I said sorry to the dude and walked away. I felt bad for him tho.
  • Psionic Roshambo @ Psionic Roshambo:
    Sounds like it would be an exciting ride....
  • Psionic Roshambo @ Psionic Roshambo:
    Not sure I would want something on fire between my legs
  • BigOnYa @ BigOnYa:
    He ruined it basically. Sad cause it was a decent old bike. It would take more money to rewire the bike than it was worth tho.
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah I'm sure at minimum the starter was fried
  • Psionic Roshambo @ Psionic Roshambo:
    Alternator and battery
  • BigOnYa @ BigOnYa:
    Prob alot of fried parts. It was still smoking when I left.
  • K3Nv2 @ K3Nv2:
    I would've said show me how it rides
  • Psionic Roshambo @ Psionic Roshambo:
    I always wanted one of those Smart Cars with a Hyabusa motor in it.
    Psionic Roshambo @ Psionic Roshambo: I always wanted one of those Smart Cars with a Hyabusa motor in it.