Saturday, March 15, 2014

PWN Win7+ w/o admin or tools

Want to look like an awesome hacker type. Okay, maybe more like you know a trick or two, but its still cool for demonstration purposes. Remember this is for educational purposes only.

This type of "attack" requires that you have physical access to the target computer.

  1. Restart the targeted computer
  2. At Splash screen kill the power
  3. Turn the computer back on
  4. Click on the Launch Repair
  5. At prompt to restore click on CANCEL
  6. When prompt to send click on “View problem details”
  7. Scroll to the bottom
  8. Click on the link at the
  9. Notepad should come up
  10. Goto File > Open > Computer > Local Disk (C:)
  11. Change file type to all files
  12. Goto Windows > System32
  13. Rename file called Sethc to Sethc.org
  14. Copy cmd.exe, scroll to the bottom of the screen, click on a blank spot, right-click and paste it
  15. Rename “cmd.exe copy” to Sethc
  16. Click Cancel
  17. Click “Don't send”
  18. You should now be back in the login screen
  19. Click on Shift x5
  20. A terminal should now come up
  21. Recon for an user name by typing in: net users
  22. Provide a new password for the targeted user name - net user <NAME> <PASSWD>
  23. If successful close the terminal, otherwise try again or another user
  24. Attempt to login as the user you change the password for
  25. You should now be successfully logged as the use