Tutorial  Updated

Exploitation Of Windows 7 Start Up Repair and Sticky Keys

<!--Not Liable for Damages To System or Any Misuse Of Info-->
<!--Please read the comments in the "Source Of Info" May not work and can mess up your system->


Exploitation of Windows Startup Repair and Sticky Keys:

Boot windows when you see "Starting Windows" Turn off system.

Gkl3MSN.png


Turn on system than boot into windows this should pop up:

pIr536N.png


Click "Launch Startup Repair (recommended)
Let it do it's stuff. When you get this screen push "Cancel" (MUST DO THIS DO NOT CLICK "Restore")

pYxugvA.png


After pushing cancel it should pop up this Screen:

pHCiP16.png


Click on "Show problem details" then scroll down to the bottom and click the link on the very bottom. Notepad should open up. In notepad click File/Open then double click your Local Disk (The below picture is D: because of virtual box but your's should be C: if not using virtual box.)

MAyXFwT.png


Once in your "Local Disk" click "Windows" then "System32" DO EVERYTHING I DO FROM THIS POINT! IF NOT YOU MAY BREAK YOUR COMPUTER! Scroll down and find "cmd," then make a copy of it in the same folder (Ctrl-C, Ctrl-V). You should get a file named "cmd - Copy" or something like that. :

5HMRUFk.png


Then find "sethc" in the same folder. This file runs Sticky Keys (That thing when you click shift to many times.) Rename it to "sethc 1":

F7uuTRG.png


Then rename your copy of cmd ("cmd - Copy") to "sethc"

grcYqLB.png


Now exit Notepad and turn off your computer either by clicking "Finish" or Restart it manually. Now it should boot up to the login screen:

dZF2CDh.png


Click shift 5 times to open up cmd (As seen as above)
Next, we need to find out your local administrator is. To do this type in (To the cmd) "net localgroup Administrators" This will show all the admins on your PC look for an administrator account that does not have your school/work domain in front of it followed by "./" As you can see, one of the admins is named "qwaszx." This is common for schools to use random strings to ward off evil spirits (Kids).

GgF7xE2.png


Now we need to change the admin password to do so type (Into cmd) "net user <ACCOUNT NAME HERE> *" Then type in your new password twice (Into cmd) Now you can log on to the admin account! But some schools/workplaces like to disable this account if so just go and do the following things:

4J0GnCI.png


If admin disabled type "net user <ACCOUNT NAME HERE> /active:yes" This will allow you to access the admin account.

Ny5K0BL.png


(SOURCE OF INFO)
 
Last edited by Luglige,

cracker

Nyah!
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
Many years ago, a friend of mine (a Mac guru) brought in a a daemon for AppleScript. He let me in on the deal and we had some fun. In short, it let you remote execute a script on any Mac it was installed in as long as you knew the IP. We had learned all the IPs so we knew where to send the scripts when people we didn't like came in. Let me make it clear that it was for retaliatory purposes for bullying, etc. One time I sent a script to alert 5000 times to a Mac this girl was working on while she was quite a ways in on a paper she was working on. Quack... quack... quack... *reboots without having saved* Revenge of the nerds!
 
  • Like
Reactions: TheLegendofMario

osaka35

Instructional Designer
Global Moderator
Joined
Nov 20, 2009
Messages
3,745
Trophies
2
Location
Silent Hill
XP
5,982
Country
United States
You know it security is something you can study right ? As joom said there are a lot of things you would need to learn and it could possibly take you several years and after that a lot of your knowledge is outdated again XD

Maybe Start with the Basics like some Network Protokolls ... if you know exactly how they work you can use this to your advantage ... some basic stuff like dns attacks still work usually so that you could build your own gbatemp and make some dns Server Link gbatemp.net to your ip instead of the real one xD

But you need to learn how all those things work ...
I'm at the point where I'm outdated again :P My knowledge is too old to be very functional nowadays, and I'm assuming I should start over and do my best to keep up this time.
 
Last edited by osaka35,

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
Many years ago, a friend of mine (a Mac guru) brought in a a daemon for AppleScript. He let me in on the deal and we had some fun. In short, it let you remote execute a script on any Mac it was installed in as long as you knew the IP. We had learned all the IPs so we knew where to send the scripts when people we didn't like came in. Let me make it clear that it was for retaliatory purposes for bullying, etc. One time I sent a script to alert 5000 times to a Mac this girl was working on while she was quite a ways in on a paper she was working on. Quack... quack... quack... *reboots without having saved* Revenge of the nerds!
Code:
chattr +i /Users/*
Much more effective.
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
OSX was the first Unix-based Mac OS (based on NeXT). There wasn't anything command-line-wise except maybe 3rd party pseudo-shells.
TIL. Interesting. I've always wanted to throw OS 9 or prior on a VM for shits and giggles. I knew OS X was based on NeXT and code from FreeBSD, though I thought the OS had always shared traits with UNIX systems.
 

VashTS

Beat it, son
Member
Joined
Mar 14, 2009
Messages
4,308
Trophies
1
Age
39
Location
Upstate NY
XP
3,763
Country
United States
Does this change the password to a networked administrator?

I'm trying to do this but I'm afraid it's easy to be caught logging I'm this way
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
Does this change the password to a networked administrator?

I'm trying to do this but I'm afraid it's easy to be caught logging I'm this way
No. This only allows you to run a prompt with administrative privileges on the local machine. Changing the password of a network administrator would require access to the issuing host server.
 

VashTS

Beat it, son
Member
Joined
Mar 14, 2009
Messages
4,308
Trophies
1
Age
39
Location
Upstate NY
XP
3,763
Country
United States
No. This only allows you to run a prompt with administrative privileges on the local machine. Changing the password of a network administrator would require access to the issuing host server.

oh so you can't actually login to the admin account or escalate privilege to another account?
 

DarkGabbz

Resident XBOX Guy
Member
Joined
Dec 29, 2015
Messages
1,185
Trophies
0
Age
21
Location
Modding Xbox'es
XP
621
Country
Micronesia, Federated States of
The school laptops that were distributed to my high school were easily exploitable. The IT guys were smart enough to not lock up the local admin account so a bunch of kids (including I) logged onto it. It took them around a month to finally discover it and all they did was call our parents in for a meeting :rofl:. My parents thought I hacked the school servers and I was in deep shit. Once the meeting came along all they told my parents were we logged in to a unprotected account and for me to not do it again.:teach:
I used a live usb and the Admin in school said its illegal to use a live usb on school pc´s:rofl2:
 
  • Like
Reactions: Luglige

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BakerMan
    I rather enjoy a life of taking it easy. I haven't reached that life yet though.
  • BigOnYa @ BigOnYa:
    I don't trust the free ones, but ipvanish I've used for couple years now, n like
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder if they could get CPUs to run that hot then use the heat to power a steam turbine to power the CPUs....
  • BigOnYa @ BigOnYa:
    Good idea, or at least power the GPU
  • Psionic Roshambo @ Psionic Roshambo:
    It's not the movies or games downloads that I would worry about, like breaking into networks, downloading encrypted things, spying on network traffic. I have seen so many "Top Secret" seals on files when I was a kid
  • Psionic Roshambo @ Psionic Roshambo:
    I was obsessed with finding UFOs, a surprising amount of US files where stashed on computers in other countries, China back in the early 90s omg sooo much
  • BigOnYa @ BigOnYa:
    Yea that crazy, I've never tried hack into anything, I just pirate, and my ISP have send me 3-4 letters, so had to VPN it
  • Psionic Roshambo @ Psionic Roshambo:
    Ship to ship communication software for the Navy although without access to the encrypting chips it was mostly useless
  • Psionic Roshambo @ Psionic Roshambo:
    I bet now a 4090 could probably crack it? Hmmm maybe not even back then I'm pretty sure they where using like 1024 bit encryption
  • Psionic Roshambo @ Psionic Roshambo:
    Yayyy the one set finished 324GBs lol
  • Psionic Roshambo @ Psionic Roshambo:
    Compressed....
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder how many years that would have taken on a 56K modem lol
  • Psionic Roshambo @ Psionic Roshambo:
    18000 hours lol
  • Psionic Roshambo @ Psionic Roshambo:
    750 days lol
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    So Internet is very much faster now lol
  • BigOnYa @ BigOnYa:
    "Time Remaining- 2 years, 9 girlfriends, 6 hairstyles, please standby..."
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I remember one time I downloaded like a 500MB ISO file on 56K and that literally took like 2 days
  • Psionic Roshambo @ Psionic Roshambo:
    I had some sort of resume thing, I remember the software had chains
  • Psionic Roshambo @ Psionic Roshambo:
    Damned if I can't remember.the name though
  • Psionic Roshambo @ Psionic Roshambo:
    Some sort of download management app
  • BigOnYa @ BigOnYa:
    Ok good chatting, I'm off to the bar, to shoot some pool, nighty night.
    +1
  • BakerMan @ BakerMan:
    hey psi
  • BakerMan @ BakerMan:
    i call your girl lyndon the way she b on my johnson
    BakerMan @ BakerMan: i call your girl lyndon the way she b on my johnson