Bertster7
Confused Pothead
+1,101|7050|SE London

joker3327 wrote:

Bertster7 wrote:

OK. Foolproof solution.

You are using a laptop at the moment, right? I assume it at least has a CD writer and you have access to a CD.

1) Get this (note the NT password recovery feature - that's what you want)
2) Burn it to CD.
3) If neccessary change the boot settings in the BIOS so the system boots from the CD before the HDD.
4) Use the Admin password reset feature
5) Reboot.
6) Log in as the Administator (which won't come up as an option on the welcome screen - unless in safe mode or if you "Hold Ctl + alt and pres delete twice." (not one I've ever tried, but sounds like it'll work)).

There you go. You are now logged on in an account that your dad is highly unlikely to ever check. Nor will it show up anywhere.

If you can't get into the BIOS to change the boot sequence (because of a password), you may need to reset your BIOS.
[VulnWatch] Blank Administrator password in DELL XP Professional install

    * To: <bugtraq@xxxxxxxxxxxxxxxxx>
    * Subject: [VulnWatch] Blank Administrator password in DELL XP Professional install
    * From: "Michael Scheidell" <scheidell@xxxxxxxxxx>
    * Date: Mon, 27 Jun 2005 13:08:07 -0400
    * Cc: <security@xxxxxxxx>, <vulnwatch@xxxxxxxxxxxxx>, <cert@xxxxxxxx>, <security@xxxxxxxx>
    * Delivered-to: mailing list vulnwatch@xxxxxxxxxxxxx
    * Delivered-to: moderator for vulnwatch@xxxxxxxxxxxxx
    * List-help: <mailto:vulnwatch-help@vulnwatch.org>
    * List-post: <mailto:vulnwatch@vulnwatch.org>
    * List-subscribe: <mailto:vulnwatch-subscribe@vulnwatch.org>
    * List-unsubscribe: <mailto:vulnwatch-unsubscribe@vulnwatch.org>
    * Mailing-list: contact vulnwatch-help@xxxxxxxxxxxxx; run by ezmlm
    * Thread-index: AcV7Osm6xFvJtGqyT6KgZctjh9FUxg==
    * Thread-topic: Blank Administrator password in DELL XP Professional install

Vulnerability in DELL Windows XP Professional - default hidden Administrator account allows local Administrator access

Systems: DELL(tm) Laptops with Windows(tm); Professional
Vulnerable: DELL Laptops with pre installed Microsoft Windows XP Professional SP2
Severity: High
Category: Unauthorized Administrator Access
Classification: Default Authentication
BugTraq-ID: tbd
CVE-Number: CAN-1999-0504
Remote Exploit: Maybe
Local Exploit: Yes
Vendor URL: www.dell.com
Author: Michael Scheidell, SECNAP Network Security
Internal Release date: May 31, 2005
Notifications: May 31, 2005, Emailed various security and cert addresses at DELL
Vendor Response: June 7, 2005: Dell Emailed and requested more information
SECNAP response: June 7, 2005: Sent Dell serial number and service tag code on test system
Additional Contact: Emailed Dell on June 14, 2005 to request status
Additional Contact: Emailed Dell on June 21, 2005 to request status, cc'd original cert and security addresses
FBI Infragard Release: June 24, 2005
Public Release Date: June 27, 2005

Problem:

DELL OEM XP Processional has a default hidden administrator account.  Use of this account will allow anyone with physical access to the computer to fully control the computer, add spyware, keystroke loggers, password stealing software and read all files, including temp files, local files, documents, and any email that has been stored locally.

DELL does not inform the installer of this account, nor give them the option of putting a password on this account. If a savvy installer finds the function to change the password for the Administrator account, they are warned that they could lose data. Security best practices REQUIRE a password on all administrative (and root) accounts.



FYI Bert        and Noob..... so your parents have set an admin password
*Cough Cough*

Bertster7 wrote:

I know on Dell and IBM machines they don't set a password. Leaving the system vulnerable to local exploitation, but on machines from vendors that are less rubbish they do.
I know. They're still unlikely to notice. Who uses their Admin account? It's a security nightmare.
Noobpatty
ʎʇʇɐdqoou
+194|6823|West NY
Ok Bert, so if it doesn't already boot from the CD how do i change it?
jsnipy
...
+3,277|6991|...

Noobpatty wrote:

Ok Bert, so if it doesn't already boot from the CD how do i change it?
now we are back to the bios.

Bertster7 wrote:

Who uses their Admin account? It's a security nightmare.
... for an idiot.I rename all my accounts, including the default Administrator account.

Last edited by jsnipy (2007-04-12 09:52:31)

Bertster7
Confused Pothead
+1,101|7050|SE London

jsnipy wrote:

Noobpatty wrote:

Ok Bert, so if it doesn't already boot from the CD how do i change it?
now we are back to the bios.
Indeed we are.

You go into the BIOS (press del, F2 - whatever the prompt tells you to, BIOS is often refered to as setup)

Once in the BIOS look around for options to do with boot sequence and set the CD drive to boot before the HDD.
Bertster7
Confused Pothead
+1,101|7050|SE London

jsnipy wrote:

Bertster7 wrote:

Who uses their Admin account? It's a security nightmare.
... for an idiot.I rename all my accounts, including the default Administrator account.
Nothing to do with the naming. To do with the stuff you can access. There are things that are only accessible through the Administrator account. That is why using it is a bad idea, not because of the simple name.
jsnipy
...
+3,277|6991|...

Bertster7 wrote:

jsnipy wrote:

Bertster7 wrote:

Who uses their Admin account? It's a security nightmare.
... for an idiot.I rename all my accounts, including the default Administrator account.
Nothing to do with the naming. To do with the stuff you can access. There are things that are only accessible through the Administrator account. That is why using it is a bad idea, not because of the simple name.
For most people i guess ...
Bertster7
Confused Pothead
+1,101|7050|SE London

jsnipy wrote:

Bertster7 wrote:

jsnipy wrote:


... for an idiot.I rename all my accounts, including the default Administrator account.
Nothing to do with the naming. To do with the stuff you can access. There are things that are only accessible through the Administrator account. That is why using it is a bad idea, not because of the simple name.
For most people i guess ...
No. For all people. It is a bad idea to use the Administator account. It's like being logged in as root in Linux (well, not quite as bad).
Noobpatty
ʎʇʇɐdqoou
+194|6823|West NY
so after i set admin password, i change it back to boot from HDD?
jsnipy
...
+3,277|6991|...

Bertster7 wrote:

jsnipy wrote:

Bertster7 wrote:

Nothing to do with the naming. To do with the stuff you can access. There are things that are only accessible through the Administrator account. That is why using it is a bad idea, not because of the simple name.
For most people i guess ...
No. For all people. It is a bad idea to use the Administator account. It's like being logged in as root in Linux (well, not quite as bad).
linux i dont use the root account all the time (because I don't understand linux nearly as  much)

Not all people ... how you can do any development  if you are logged in as an admin? Maybe if your understanding is big black black cloud I could understand using a less priveldged account ... that is the same mentailty as always saying "reformat" when you give up on trying to solve an issue.

Last edited by jsnipy (2007-04-12 10:05:12)

BeerzGod
Hooray Beer!
+94|7039|United States
Try not being such a little bastard and they'll probably stop locking the thing up on you.
Bertster7
Confused Pothead
+1,101|7050|SE London

jsnipy wrote:

Bertster7 wrote:

jsnipy wrote:


For most people i guess ...
No. For all people. It is a bad idea to use the Administator account. It's like being logged in as root in Linux (well, not quite as bad).
linux i dont use the root account all the time

*NO* Not all people ... how you can do any development (like services and such) if you are logged in as an admin? Maybe if your understanding is big black black cloud I could understand using a less priveldged account ... that is the same mentailty as always saying "reformat" when cannot solve an issue.
Being logged in as an Admin and being logged in as the Administrator accounts are two different things.

Being logged in as an admin is very usefull, being logged in as the Administrator is not generally any more usefull, except for doing things you don't want done.
Bertster7
Confused Pothead
+1,101|7050|SE London

Noobpatty wrote:

so after i set admin password, i change it back to boot from HDD?
You should do really. Although you can just take the CD out and it'll boot normally.
Noobpatty
ʎʇʇɐdqoou
+194|6823|West NY
Alright. thanks alot bert, i'm gonna go on my quest to the store now to buy an empty CD...i left mine at school that i borrowed from my friend (same friend whos computer i'm using) and all of his CD's around his room have stuff on them..hopefully no one gets home before i'm back- he left and i'm alone in his house - don't think his parents would be happy...
Bertster7
Confused Pothead
+1,101|7050|SE London

jsnipy wrote:

Bertster7 wrote:

jsnipy wrote:


linux i dont use the root account all the time

*NO* Not all people ... how you can do any development (like services and such) if you are logged in as an admin? Maybe if your understanding is big black black cloud I could understand using a less priveldged account ... that is the same mentailty as always saying "reformat" when cannot solve an issue.
Being logged in as an Admin and being logged in as the Administrator accounts are two different things.

Being logged in as an admin is very usefull, being logged in as the Administrator is not generally any more usefull, except for doing things you don't want done.
if you look at  policy in windows you will see privelges are granted to the Administrator's group not the default admin account. So it is the same thing. Unless you have an example.
I'm pretty sure you need it to access NTFS password hashes.

There are several things. All of which are very obscure. That's why I'm saying no one should be using the Administrator account.
Noobpatty
ʎʇʇɐdqoou
+194|6823|West NY
Later guys
Noobpatty
ʎʇʇɐdqoou
+194|6823|West NY
Sorry for double posting, but how do i enter the BIOS - pressing Delete and F2 at the blue welcome screen doesn't work
[TUF]Whiskey_Oktober
mmmm...Toasty!
+91|7191|Oregon
its gonna either be F1, F2, F3, F10, F11, F12, or delete. hit all of them and one should work...if its an HP machine, hit F11...F1 only gets you into the limited bios.


im curious why you are so intent on getting online...shouldnt grades/social life be more important at your age? i know they are to me...
Noobpatty
ʎʇʇɐdqoou
+194|6823|West NY
Because I can't do anything else.... I can't fix my grade over break

Board footer

Privacy Policy - © 2025 Jeff Minard