Windows Password LoopholeThis is a featured page



I wish i'd quit finding these !! : Fainted brain



a. ok now, what you need to do is to run compmgmt.msc

b. and click on local users and groups.

c. once you've gotten here you need to open up the 'users' folder.


at this point i am walking along with you and notice that there are several
major security holes dealing specifically with the password:
1. double clicking on the any user name allows you a list that looks
something like this:
"user name"

full name: -----------------------
|__________________|

description: -----------------------
|__________________|
--
|_| user must change password at next logon

--
|_| user cannot change password

--
|/| password never expires

--
|_| account is disabled

--
|_| account is locked out


"ok" "cancel" "apply"

ok if you can get past my cheesy drawing, i must ask, did you notice that
the "password never expires" box is checked? if you did, then you may have
realized that this means that you can also uncheck it!

2. if ure paying attention, you'll see that the 'user must change password
at next logon' box is unchecked. if you put a check in this box of course,
when you shut down the system will prompt for a new password!

3. going back to step c.,
right click on any account and notice the dialoge that appears:
set password...
all tasks
delete
rename
properties
help

i think you can handle it from here

ps. i wonder if you can access this data if this stuff is locked to the user
by the admin by going in through the command prompt. i doubt it but if neone
finds a way let me know.


punkey8oy
punkey8oy
Latest page update: made by punkey8oy , Jul 7 2008, 4:47 AM EDT (about this update About This Update punkey8oy Edited by punkey8oy

No content added or deleted.

- complete history)
Keyword tags: None
More Info: links to this page
Started By Thread Subject Replies Last Post
untildeath @ above all 0 May 28 2009, 1:54 AM EDT by untildeath
Thread started: May 28 2009, 1:54 AM EDT  Watch
m studying in university and there are limited accounts which are logged by student name and not with administrator and they do not havew access to many parts like installing some softwares and many other thngs and the way the post owner tells is not working here and gives error that restricted by the user
Do you find this valuable?    
Keyword tags: None
mallki hi1 0 Mar 30 2009, 2:41 AM EDT by mallki
Thread started: Mar 30 2009, 2:41 AM EDT  Watch
hi my name is manjusha my profile has been hacked can u tell my password
manjis25@gmail.com plz send the password to manjis97@gmail.com
Do you find this valuable?    
Keyword tags: None
choudhary.dhaka1 admin password 0 Mar 27 2009, 10:42 PM EDT by choudhary.dhaka1
Thread started: Mar 27 2009, 10:42 PM EDT  Watch
heloo
use dreampack pl
Do you find this valuable?    
Keyword tags: None
Showing 3 of 4 threads for this page - view all