How to Reset a Windows Password Through a Backdoor

How to Reset a Windows Password Through a Backdoor


Check out my SysAdmin blog:
http://www.TheNubbyAdmin.com

Talk to me on Twitter:
https://twitter.com/#!/nonapeptide

Email me at:
nonapeptide@gmail.com

This screencast is the video counterpart to this article of mine:
http://www.simple-talk.com/sysadmin/g...

TechNet Link about EFS:
http://technet.microsoft.com/en-us/li...

What I used to create the presentation portions of the screencast:
http://prezi.com/

Important time links:
0:11 Disclaimer. Please take heed
0:52 What this backdoor will and will not allow you to do
1:45 How this will be done
4:03 Beginning of demonstration with victim PC
6:05 Brief discussion about EFS and why this password reset could cause data loss
7:47 Continuance of demonstration with the victim PC
14:33 Wrap up

Have some other topic you'd like me to explain in a screencast? Let me know in the comments.

Oh, and yes, I start sentences with the word "so" and "now" far too much. So, now, I'm going to try and stop doing that in future videos.
Closed Caption:

in this screencast i'll be showing you a
simple back door that can be used to
reset the password of any windows
account on virtually any version of
windows
however before we get started I need to
mention two very important disclaimers
the first is that you should only use
these techniques to access computers
that you have a lawful right to access
so I'm not condoning tampering with
computers that you do not have the right
to be accessing and I do not intend this
tutorial to be used for those purposes
secondly if you lose data destroy your
computer make anyone angry disrupt your
day
give yourself a headache or otherwise
how bad things happen because of this
tutorial
it's entirely your fault so follow these
instructions at your own risk
with that out of the way let's define
some terms
this method for resetting windows
passwords through a back door will
perform a password reset the
nomenclature of the term password reset
implied something a little different
than just a password change a password
reset can be disruptive resets do not
perform any additional operations like
changing the encryption keys that are
associated with the user account and
we're going to find that out here
shortly
you should also know that this operation
is not a crack
this is not a password recovery you're
not going to be able to see the user
accounts old password
there are entirely different methods are
seeking to uncover an account password
but this tutorial doesn't touch on any
of those this method simply resets the
accounts current password to a new
password of your choosing and you will
never see what the old password was so
now that you understand what this method
will and will not do
let's discuss a little bit about how
we're going to be doing it first off
physical access is a must now that can
be through physically touching the
machine or a kvm over IP device with
remote media with remote media is
important
this is not a method to reset a password
/ network so this won't work if you only
have remote console access to say
VNC rdp or some other remote access to
like bomgar or teamviewer the whole
method hinges on having physical access
to the pc because ultimately the goal of
this technique is to acquire unencrypted
offline access to the windows system32
folder and rename a single executable
file within that folder you can use any
number of methods to do this including
sliding the drive to another pc and
browsing the file system using a Windows
installation disk using any other google
media really they can interact reliably
with the NTFS file system so for
instance a linux live image on a CD or
USB Drive you can use a recovery
partition like you might find on a
consumer pc whatever you do it really
doesn't matter as long as you have
unencrypted access to the system32
folder while the windows instance itself
is not running because it won't let you
rename anything with in system32 if it's
running
so now would be a good time to mention
that if someone has physical access to a
computer and his intent on doing
mischief they pretty much owned that
computer in question
so keep your physical assets safe and
that's actually where drive encryption
can really help you out if it's the
right kind there's different kinds and
different level of encryption and not
just encryption key strength but also
methods such as volume versus disk
encryption and that's a little bit
outside the scope of this video
now notice how I said you need
unencrypted offline access to the
system32 folder
that's because if you're trying to
perform this method for resetting a
password on a windows machine drive
encryption is going to ruin it for you
if the boot volume is encrypted
that's actually pretty rare though so
you probably don't have to worry about
it
that's the breakdown
we need physical access to the computer
and offline unencrypted access to the
windows system32 folder let's move our
victim pc
this pc is running windows 7
professional show you right here
windows 7 professional service pack 1
i'm logged in right now
and of course i know the password to
this account so i'm going to set the
password to something random guy off the
cop or just hammer on the keyboard here
so there's no way that I can possibly
remember that at least not with my
memory
so let's go set password to this complex
one
and then we go we set our password
so let me now draw your attention to
this folder on the desktop here
this is encrypted with ef-s prove it to
you encrypt contents to secure data is
selected
there's a visual indicator within a
folder notice that all the file names
are in green
notice that these files themselves are
also encrypted notice that i can see
inside these files
so i am going to log out and we're going
to get going with password reset
demonstration however before I do let me
set the stage for a demonstration of how
Windows handles EFS and why this is
actually going to be important
anytime you reset a password using this
method
TFS stands for encrypting file system
and as a technology within windows that
allows users to easily protect their
files with encryption and the following
information that you see here is taken
from technology at microsoft.com and a
link to the specific article is in the
notes below the video if you're watching
on YouTube or Vimeo
I won't read it all but what this means
in a nutshell is that EFS keys are
protected by each user's account
password
so if you lose your account password you
lose access to any files protected by FS
BFS is performed at the file system
level basically within ntfs itself so
applications have no clue about it
they don't have any role to play in the
encryption of the files at the writing
to disk BFS encrypted files can only be
unencrypted through the key pair that is
itself encrypted using your account
password properly changing your password
will change the encryption keys and
that's you're not going to lose access
to your gfs encrypted files a proper
password change is done through the
control panel or by pressing control of
the weed and changing your password from
the option present to you they're
resetting a password using the method
that we're about to use is not going to
update the fs keep air and thus you will
lose access to any data that's encrypted
using the fs and of course there are
caveats to the danger of losing access
to your data and those involved setting
up designated recovery agents before any
password resets are performed but those
topics are beyond the scope of this
screencast and if those sound of
interest to you and your situation then
I advise you to google that
let's get back to our victim pc
so now that I've explained all that to
you its tongue to log off at this point
after all that talk about the fs I have
no recollection of what that password is
that we changed so i can't get back in
so I pretty much locked myself out of
this pc take a look down in the lower
left corner of the login page you see
this little icon
that's the accessibility options icon
and probably not a lot of people have
ever looked at or even noticed it was
there if they did they probably never
clicked on when we press it
we see that we have various options to
launch some basic accessibility
utilities for example we have the
on-screen keyboard here which is helpful
if we have a tablet or some kind of
touch screen
what you don't see is that the
executables that are launched from the
accessibility options tool down there in
the lower left-hand corner
they're all running as the system user
the system user is basically the
granddaddy of all windows users so we
have the on-screen keyboard running
right now as the most powerful user on
this computer is the most powerful
on-screen keyboard you will ever see now
is when our boot disk comes into play or
any of the other offline access methods
that were listed earlier in this video
such as a bootable USB Drive or recovery
partition
i'm going to be using a Windows
installation disk to gain offline access
to this hard drive in fact i'm going to
go old school just for kicks and i'm
going to use a Windows 2000 server cv
so let's put into that
boy that brings back memories I'm going
to skim over the options that I choose
here it's just the standard options that
you would choose to get into the windows
recovery console on an older version of
windows
it's going to get us into a command
prompt where we can make a few changes
to the underlying file system on a hard
drive
so this part really isn't that important
so let's move to the system32 folder now
i happen to know that the on-screen
keyboards executable is OS k dot exe and
there you see it
I also know that of course the command
prompt is cmd.exe so what would happen
if we simply renamed cmd.exe 20 s k dot
exe
let's find out
and it's as simple as that - let's
reboot
so now we're back at the login screen
and of course I still can't login don't
remember the password
let's see if the on-screen keyboard will
help us
that is a funny looking on screen
keyboard even more importantly look at
that I am the system user
at this point it's just a matter of
changing passwords using good old net
user and that's my password by the way
let me know
and notice there's no smoke and mirrors
here this is a seven character password
and if you remember the password that we
reset it to that big long jump password
was well with more than 7 characters
look at that we now have access to the
account that we locked ourselves out
over here
now notice the command prompt is still
up
it stays with you but notice that i am
now the user account rather than the
system account now we could have just as
easily done this to add a user instead
of modifying an existing users password
for example we could have gone
and of course I'm tonight because i'm
not at an elevated command prompt
but the idea is if you wanted to add a
user rather than tamper with an existing
user
that's just another option now if we had
created a new user we wouldn't have to
worry about losing access to ntfs
encrypted files
like for instance these we can open up
the folder but notice we can get to any
of these files access is denied
now i might seem kind of hopeless at
this point but I've found that if you
reset your password back to what it was
previously are back to what it was the
last time you did a proper password
reset
you can access those EFS encrypted files
again so let's reset the password back
to the complex one that we had said
before which is this one
current password is let me in and paste
the new old password and the one we
reset you think that we'd at least have
to log off and log back on again to be
able to access easy FS encrypted files
but in fact we don't
so there we are we can access the fs
encrypted files once we set the password
back to what it was the last time it was
properly set and that's a good point
keep in mind that we could have reset
this password hard like this using this
little backdoor method a dozen times
over the course of a month and we still
have to go back to the last password
that was changed gracefully which in our
case was this one right here
that is how you defeat account security
in windows if you have physical access
to the pc an unencrypted offline access
to the system32 folder
don't forget to go back and rename the
command prompt that we named 20 s k dot
exe of course you're going to want to
rename osk exe back to its original name
if you want that because otherwise you
have this gaping security hole just
sitting there waiting for someone to use
it if you found this video to be useful
and you watched it on YouTube please
like it with the thumbs up button and
subscribe to see more videos if you
watch this on video please like it with
the heart button and subscribe to my
video uploads check the notes below
these videos if you're watching them on
youtube or vimeo for some more
information and cool links
feel free to share this video or
embedded anywhere that you think people
would appreciate it thanks for watching

Video Length: 15:26
Uploaded By: Wesley David
View Count: 3,344,910

Related Software Products
Any Windows Password Reset
Any Windows Password Reset

Published By:
passwordseeker

Description:
Any Windows Password Reset 7 is a professional Windows password recovery utility to reset administrator and user passwords on any Windows system. If you have forgotten your password, or are locked out, or you do not have access to the password of the system, Any Windows Password Reset 7 allows you to burn a CD/DVD, USB flash drive and floppy disk to reset your lost password, you can be back in your system in minutes with it.BRBRIt works on all and any Windows versions and computers any ...

Windows Password Reset Enterprise
Windows Password Reset Enterprise

Published By:
Passkiller

Description:
Anmosoft Windows Password Reset Enterprise is safe, easy-to-use and professional Windows password recovery software which can help enterprises to reset lost or forgotten Windows domain, Windows administrator password, user password and guest password. With this reliable Windows password recovery tool, you can easily and securely regain access to your computer by burning a bootable CD/DVD password or USB flash drive. And this Windows password reset tool support Windows password reset from all ...

Windows Password Recovery software
Windows Password Recovery software

Published By:
PasswordSeeker

Description:
Windows Password Recovery 6.0 is an easy-to-use tool designed for resetting local administrator and user passwords on any Windows system. If you have forgotten your password, or are locked out, or you do not have access to the password of the system. It is the most effective product on the market. with a Graphical background and it is the easiest solution for Home Users and the overall Best for Businesses. You only need to boot from Windows Password Recovery 6.0 CD/DVD, and reset forgotten ...

Windows Password Reset Professional
Windows Password Reset Professional

Published By:
Passkiller

Description:
Anmosoft Windows Password Reset Professional is a secure, easy and professional Windows password recovery tool for you to reset the forgotten Windows passwords and log back onto the system. It can help to reset all local Windows passwords. It not only resets Windows administrator password but user and guest passwords. This Windows password reset tool is easy to use by burning a CD/DVD or USB Flash drive, which is rarely available for its competitors. It resets all local Windows passwords, ...

Windows Password Reset Ultimate
Windows Password Reset Ultimate

Published By:
PowerPoint to DVD

Description:
Anmosoft Windows Password Reset Ultimate is safe, easy-to-use and professional Windows password recovery software which can reset lost or forgotten Windows domain, Windows administrator password, user password and guest password. With this reliable Windows password recovery tool, you can create a new Administrator user account or change your windows password easily and securely by burning a bootable CD/DVD password or USB flash drive. And this Windows password reset tool support Windows ...

Windows 7 Password Reset
Windows 7 Password Reset

Published By:
Spowersoft

Description:
Windows 7 Password Reset is an all-in-one Windows 7 password reset tool that can reset windows 7 password for destop PC and laptop safely and fast. If forget winows 7 password, Windows 7 Password Reset can help you create a CD/DVD or USB windows 7 password reset boot disk to reset forgotten password with old password. You don't need to format your hard drive and resinstall windows.p Key Features: 1. Reset (recover) Windows 7 without old password. 2. Reset all user and ...


Related Videos
How to Remove a Windows User Login Password
How to Remove a Windows User Login Password

If you forgot your Windows log in password and locked yourself out of your own computer, this video is for you. This works with most windows machines. See website link for all the details. Supports all Windows from NT3.5 to Win7, also 64 bit and also the Server versions (like 2003 and 2008) Software link: http://pogostick.net/~pnh/ntpasswd/ If you need a tutorial on how to create a CD version of this tool, I made a video here ...
Video Length: 15:00
Uploaded By: GuruBrew
View Count: 1,937,541

Reset Windows 7 Password Without CD Or Software
Reset Windows 7 Password Without CD Or Software

Forgot your Windows 7 Password (This is not a HACK), You can reset Password without CD Or any software using CMD. In this video we will show you how can you do that but if u have any windows Bookable CD there is a second way to reset password, just check our other video for that.
Video Length: 04:10
Uploaded By: Tech Bachhal
View Count: 1,721,369

Windows 7 Password Reset & Recovery - Free Tool
Windows 7 Password Reset & Recovery - Free Tool

http://windows-server-training.com/wi... for the full text walkthrough with screenshots. Use this free tool for Windows 7 Password Reset & Recovery. Video and walk through guide to help you reset your Windows 7 password. If you have been using a computer for any amount of time you have no doubt forgotten a Windows 7 password or two and have had to have it reset or recovered from you administrator at the office. With the increase of security on home computers Windows 7 ...
Video Length: 06:06
Uploaded By: MSVideoTraining
View Count: 1,593,228

How to Reset/Recover Forgotten Windows 7 Password - AvoidErrors
How to Reset/Recover Forgotten Windows 7 Password - AvoidErrors

Forgetting your password is never any fun, but luckily there's a really easy way to reset the password. All you need is a copy of Hirens Boot CD Change First Boot Device in BIOS to Boot From CD/DVD. http://www.avoiderrors.net/?p=10562 Optional: Launch Hiren's BootCD from USB Flash Drive https://youtu.be/M-_lNrAd2Cc Hirens Boot CD: http://www.hirensbootcd.org/download/ hr / bClosed Caption:/b hi my name is Miguel from avoid ...
Video Length: 04:15
Uploaded By: AvoidErrors
View Count: 1,498,689

Bypass Forgotten Windows 7 Password with Kon-Boot V1.1 by Britec
Bypass Forgotten Windows 7 Password with Kon-Boot V1.1 by Britec

Bypass Forgotten Windows 7 Password with Kon-Boot V1.1 by Britec Kon Boot is an application which will bypass the authentication process of a Windows logon. Kon Boot can work on either a USB flash drive, CD-ROM, or floppy diskette. Using Kon Boot is simple. First load it to your desired media (CD, USB flash, or floppy diskette) then insert it into the target computer, and start it up! The password is not required to logon to Windows, nor is it overwritten. ...
Video Length: 02:55
Uploaded By: Britec09
View Count: 941,387

How to Remove Windows 7 User Login Password
How to Remove Windows 7 User Login Password

Please DO NOT Subscribe to STF channel without browsing it first. These kind of videos will not be uploaded on this channel, but will go on https://www.youtube.com/123DoneTutorials ----------------------------------------------------------- A way to remove Windows 7 user Login Password without any software. Here is another simple way to do it: https://www.youtube.com/watch?v=CFmvK... Thanks for watching!br ...
Video Length: 04:35
Uploaded By: Shake the Future
View Count: 917,639

Windows 7 How To: Login Without a Password
Windows 7 How To: Login Without a Password

Computertv host Bauer shows you some helpful tips on Windows' latest operating system. In this how to, Bauer shows you how to add or remove the windows password for logging in your system. Tired of always seeing the username and password screen everytime you turn your PC on? You probably were forced to set one up during installation or setting up a newly purchased PC. Well fear not, Bauer shows you how to get rid of it and log in quickly to windows 7. hr / bClosed Caption:/b br ...
Video Length: 01:58
Uploaded By: TigerDirect
View Count: 876,456

Reset Windows 8 Password
Reset Windows 8 Password

Reset Windows 8 Password In this video I will show you a quick and easy way to reset or recover from and lost or forgotten windows 8 pass password, will will be using Microsoft Diagnostics and Recovery Toolset MSDaRT 8.0 we will regain access to a system using, The Locksmith wizard can be used to list the local user accounts and change passwords. hope this helps you out. http://www.briteccomputers.co.uk hr / bClosed Caption:/b yeahbr ...
Video Length: 03:54
Uploaded By: Britec09
View Count: 867,567

Reset Password in Windows XP, Vista, 7 For FREE by Britec
Reset Password in Windows XP, Vista, 7 For FREE by Britec

Reset Password in Windows XP, Vista, 7 For FREE by Britec Forgot your Windows NT/2k/XP/Vista/Win7 admin password? This is a utility to reset the password of any user that has a valid (local) account on your Windows NT/2k/XP/Vista/Win7 etc system. You do not need to know the old password to set a new one. It works offline, that is, you have to shutdown your computer and boot off a floppydisk or CD or another system. Will detect and offer to unlock locked ...
Video Length: 04:12
Uploaded By: Britec09
View Count: 728,634

Recover from Forgotten Windows 8 Password
Recover from Forgotten Windows 8 Password

Recover from Forgotten Windows 8 Password Now we all have forgotten our windows Microsoft Administrator User Account Password, so in this video I show you you how to reset it with Hirens Boot CD. You can remove password or reset it to a new password. or just leave it blank. http://www.briteccomputers.co.uk hr / bClosed Caption:/b what you guys going to another video here for you now a few for locked yourself out of your ...
Video Length: 04:04
Uploaded By: Britec09
View Count: 648,027

Copyright © 2025, Ivertech. All rights reserved.