BetaArchive Logo
Total Current Archive Size: 4765.54GB in 15409 files
Navigation Home Screenshots Image Uploader Server Info FTP Servers Wiki Forum RSS Feed Rules Please Donate
UP: 6d, 23h, 24m | CPU: 19% | MEM: 5089MB of 12279MB used
{The community for beta collectors}

Post new topic Reply to topic  [ 7 posts ] 
Author Message
 PostPost subject: [How to] Gaining SYSTEM account access in Windows XP        Posted: Wed Feb 20, 2008 12:09 am 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Tue Oct 23, 2007 11:21 pm

Posts
593
Method 1
1. Switch to classic logon
2. Remove any Windows CD from the drive
3. Delete EVERYTHING in i386 (root or WINDOWS), repair (WINDOWS), dllcache (system32) and ServicePackFiles (WINDOWS)
4. Backup sethc.exe (located in system32)
5. Make a copy of cmd.exe and rename it to sethc.exe
6. Logoff
7. In logon screen, hold SHIFT for 8 seconds until a command prompt window appears.
8. Type "explorer.exe" and press ENTER.
9. Ready to go!

Method 2
1. Open command prompt
2. Kill explorer using taskmanager
3. Run:
3. AT XX:YY /INTERACTIVE cmd.exe
3. where XX:YY is your Windows time plus one minute
4. Wait no more than one minute.
5. Now you have SYSTEM command prompt
6. Run explorer.
7. Ready to go!

Method 3
1. Download PowerPrompt here
2. Run PowerPrompt.exe
3. Command prompt with SYSTEM privileges!



What you CAN do:
Use "control userpasswords2" (can be called by the command prompt instead of explorer.exe) to create a new user account
Change classic logon theme and wallpaper

What you CAN'T do:
Use taskmgr (it will appear completely bogus)

Known problems:
After a couple of minutes, explorer simply closes.

_________________
you've got to fling yourself. fling into space.


Last edited by RichardGatinho on Thu Mar 20, 2008 11:39 pm, edited 4 times in total.

Top  Profile
 PostPost subject:        Posted: Wed Feb 20, 2008 6:27 am 
Site Moderator
Site Moderator
User avatar
Offline

Joined
Wed Apr 11, 2007 2:11 pm

Posts
2549

Favourite OS
Mango
Another method:

- Quit the explorer with taskmanager.
- Run cmd.exe
- Type: AT HH:MM /INTERACTIVE cmd.exe (use your time + one minute for HH:MM)
Now you have a command line running with system users privileges
- Type explorer.exe

_________________
Image


Top  Profile  WWW
 PostPost subject:        Posted: Wed Feb 20, 2008 6:46 pm 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Tue Oct 23, 2007 11:21 pm

Posts
593
@D.Konieczny:
Screenies of your method.

Firefox, WLM, Task Manager and underneath cmd are running on my user. The rest is running on SYSTEM.
I can even kill SYSTEM's explorer.exe using task manager from my admin account.

Problems:
When killing SYSTEM's explorer.exe, some parts of the environment (eg. Windows effects, desktop background) will still run on SYSTEM. To take the things back on normal, logoff then login with your previous account.
When starting explorer.exe, Windows will ask for Windows Tour, AND, will display an error saying that some network drives could not be reconnected, even if you don't have one.

Image
Image
Image

_________________
you've got to fling yourself. fling into space.


Top  Profile
 PostPost subject:        Posted: Wed Feb 20, 2008 7:05 pm 
Site Moderator
Site Moderator
User avatar
Offline

Joined
Wed Apr 11, 2007 2:11 pm

Posts
2549

Favourite OS
Mango
RichardGatinho wrote:
When starting explorer.exe, Windows will ask for Windows Tour, AND, will display an error saying that some network drives could not be reconnected, even if you don't have one.


Thats because windows is creating a new user profile for SYSTEM.

_________________
Image


Top  Profile  WWW
 PostPost subject:        Posted: Wed Feb 20, 2008 7:30 pm 
Permanently Banned
Permanently Banned
Offline

Joined
Mon Dec 11, 2006 3:09 am

Posts
477
I have to make a pun on this then

Don't IRC as SYSTEM!!!


Top  Profile  WWW
 PostPost subject:        Posted: Thu Mar 20, 2008 7:10 pm 
Pro Beta Collector
Pro Beta Collector
Offline

Joined
Tue Oct 23, 2007 11:21 pm

Posts
593
Sorry if rulesbreaking, exactly 20 minutes worth to reach 1 month.

The second method works on Windows 2000, but the window comes from mstask.exe, not svchost.exe.

_________________
you've got to fling yourself. fling into space.


Top  Profile
 PostPost subject:        Posted: Thu Mar 20, 2008 7:55 pm 
Newbie Beta Collector
Newbie Beta Collector
Offline

Joined
Thu Nov 01, 2007 2:29 pm

Posts
42
Just for the record, third method (app to get system credentials):
http://grubletrang.com/Software.aspx?app=PowerPrompt

jaclaz


Top  Profile
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 




Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  

All views expressed in these forums are those of the author and do not necessarily represent the views of the BetaArchive site owner.

Powered by phpBB® Forum Software © phpBB Group

Copyright © 2006-2013

 

Sitemap | XML | RSS