Recovery Windows account with Reset or crack Password
Forgot your administrator password ? This page provides step-by-step how to reset your local Windows password. This only works for local user accounts, and unfortunately not for domain account. please take this old trick for education( computer hacking security ) purpose only.
Overview
- You do not need to know the old password to set a new one.
- It works offline, that is, you have to shutdown your computer and boot off a floppydisk or CD or another system.
- Will detect and offer to unlock locked or disabled out user accounts!
- There is also a registry editor and other registry utilities that works under linux/unix, and can be used for other things than password editing.
The password recovery tool, is written by Petter Nordahl-Hagen, and the original information, as well as the downloadable tool, can be found from his website.This tool should be working for Windows NT/2000/XP/Vista.
The tool can be downloaded at here. With this tool, you should be able to reset your local administrator password in case you lost your password.
How To Recovery Windows account ( Cracking/hacking windows password account )
- Download the bootdisk, which includes the password recovery tool here. The file contains the ISO CD image.
- Unzip the ISO file and burn the ISO file to a CD. Note that this is an ISO file, you must burn it to CD as an ISO image, not a normal files. To find out how, click here.
The walkthrough
- Startup your computer with the bootdisk created above. You should see a welcome screen following with a prompt:
boot:
- Just wait, the bootup process will continute automatically. Then you should see a screen similar to this:
========================================================= . Step ONE: Select disk where the Windows installation is ========================================================= .... NT partitions found: 1 : /dev/sda1 4001MB Boot 2 : /dev/sda5 2148MB Please select partition by number or a = show all partitions, d = automatically load new disk drivers m = manually load new disk drivers l = relist NTFS/FAT partitions, q = quit Select: [1]
- Notice the last line “Select: [1]” contains the [1] as default since the tool detects the bootup partition is [1]. This might be different on your own machine, but double-check with the information shown under “NT partitions found:“, the partition with the word “Boot” should be selected.
- Hit Enter if the default partition is correct, or enter the number for the boot parition then hit Enter. Here’s what you should see next:
========================================================= . Step TWO: Select PATH and registry files ========================================================= .... What is the path to the registry directory? (relative to windows disk) [windows/system32/config] :
- Notice the last line “[windows/system32/config]” contains the default path, which was detected by the tool. If the path is correct, hit Enter, or if you wish to enter a different path, enter it now and hit Enter.
Here’re the paths for different versions of Windows:
- Windows NT 3.51: winnt35/system32/config
- Windows NT 4 and Windows 2000: winnt/system32/config
- Windows XP/2003 (and often Windows 2000 upgraded from Windows 98 or earlier): windows/system32/config - Once you hit “Enter” the following similar information should display:
-r-------- 1 0 0 262144 Jan 12 18:01 SAM -r-------- 1 0 0 262144 Jan 12 18:01 SECURITY -r-------- 1 0 0 262144 Jan 12 18:01 default -r-------- 1 0 0 8912896 Jan 12 18:01 software -r-------- 1 0 0 2359296 Jan 12 18:01 system dr-x------ 1 0 0 4096 Sep 8 11:37 systemprofile -r-------- 1 0 0 262144 Sep 8 11:53 userdiff Select which part of registry to load, use predefined choices or list the files with space as delimiter 1 - Password reset [sam system security] 2 - RecoveryConsole parameters [software] q - quit - return to previous [1]
- Hit “Enter” with the default option selected “[1]“. You’ll get the next prompt similar to this:
========================================================= . Step THREE: Password or registry edit ========================================================= Loaded hives: 1 - Edit user data and passwords 2 - Syskey status & change 3 - RecoveryConsole settings - - - 9 - Registry editor, now with full write support! q - Quit (you will be asked if there is something to save) What to do? [1] -> 1
- Hit “Enter” with the default option selected “[1]“. You’ll get the next prompt similar to this:
===== chntpw Edit User Info & Passwords ==== RID: 01f4, Username: <Administrator> RID: 01f5, Username: <Guest>, *disabled or locked* RID: 03e8, Username: <HelpAssistant>, *disabled or locked* RID: 03eb, Username: <pnh>, *disabled or locked* RID: 03ea, Username: <SUPPORT_388945a0>, *disabled or locked* Select: ! - quit, . - list users, 0x<RID> - User with RID (hex) or simply enter the username to change: [Administrator]
- Hit “Enter” with the default option selected “[Administrator]“, or select another user account. Here you can enter the full user account with < >, CASE-SENSITIVE, or enter the RID number (i.e. 0×1f4). Assuming you select the Administrator account, here’s what you should see:
RID : 0500 [01f4] Username: Administrator fullname: comment : Built-in account for administering the computer/domain homedir : Account bits: 0x0210 = [ ] Disabled | [ ] Homedir req. | [ ] Passwd not req. | [ ] Temp. duplicate | [X] Normal account | [ ] NMS account | [ ] Domain trust ac | [ ] Wks trust act. | [ ] Srv trust act | [X] Pwd don't expir | [ ] Auto lockout | [ ] (unknown 0x08) | [ ] (unknown 0x10) | [ ] (unknown 0x20) | [ ] (unknown 0x40) | Failed login count: 0, while max tries is: 0 Total login count: 3 * = blank the password (This may work better than setting a new password!) Enter nothing to leave it unchanged Please enter new password: *
- At the prompt “Please enter new password“, Enter the * for a blank password (HIGHLY RECOMMENDED!) then press Enter
Please enter new password: * Blanking password! Do you really wish to change it? (y/n) [n] y
- At the prompt, type in “y“, then press Enter. Note that the default option is “n”.
Do you really wish to change it? (y/n) [n] y Changed! Select: ! - quit, . - list users, 0x - User with RID (hex) or simply enter the username to change: [Administrator] !
- Enter the “!” to go back to the main menu. Then select “q” at the following menu to quit:
<>========<> chntpw Main Interactive Menu <>========<> Loaded hives: 1 - Edit user data and passwords 2 - Syskey status & change 3 - RecoveryConsole settings - - - 9 - Registry editor, now with full write support! q - Quit (you will be asked if there is something to save) What to do? [1] -> q
- A prompt to save changes displays, enter “y” to save:
========================================================= . Step FOUR: Writing back changes ========================================================= About to write file(s) back! Do it? [n] : y
- Last of all, the changes saved. The following is what you should see, press Enter, and reboot your computer.
Writing sam ***** EDIT COMPLETE ***** You can try again if it somehow failed, or you selected wrong New run? [n] : n
Download sources
- cd080802.zip (~3MB) - Bootable CD image. (md5sum: 33ecd38263f935b82e7b2e3e9f5de563)
- cd080526.zip (~3MB) - Previous release, Bootable CD image. (md5sum: 1c6f5af7c682b7ee5d01935bc11f37f6)
Floppy release, s
- bd080526.zip (~1.4M) - Bootdisk image (md5sum: 37889e4c540504e59132bdcdfe7f9bb7)
- drivers1-080526.zip (~310K) - Disk drivers (mostly PATA/SATA) (md5sum: 72ac1731c6ba735d0ac2746a30dbc3ee)
- drivers2-080526.zip (~1.2M) - Disk drivers (mostly SCSI) (md5sum: 30172bec657c85a5f1a0b43601452fb7)
Leave a Reply