Sunday, August 31, 2008

Gain administrative rights on a computer

For this to work you need physical access to the computer, for example on a library computer. You will need to boot the computer from a CD
To do this, you need to set the computer to change the boot order and start the CD/DVD drive prior to the Hard drive (if it's a dumb terminal then it's a waste of time since there's no "local" admin rights, everything is on the school server so you're screwed, i'll think of a trick later on, stay tuned!)
While booting, press the [delete] button. This will get you in the bios editor. If the editor requires no password then the administrator is a real n00b, since locking the bios is the first thing you should always do on any machine... anyway say it's password protected.
There is a number of ways to remove the BIOS password. There's first of all the option to actually unscrew the tower and pull the motherboard battery out then wait a few seconds and put it back in place, this should reset the password. (IF YOU ARE GOING TO DO THIS MAKE SURE THE COMPUTER IS TURNED OFF AND UNPLUGGED, I TAKE >>>NO<<< RESPONSIBILITY IF YOU GET ELECTROCUTED!! !!!)
My suggestion would be not to do this. Reasons:
1) carrying a screwdriver at school is the easiest part, yet hard if your school has a metal detector
2) unscrewing and opening a computer in a library is a bit too obvious and will draw unwanted attention, don't you think?!?
3) finding the battery is usually a bit hard among all these cables and memories and drivers and cards and the general hell that reigns inside towers
4) i have done it. no1 saw me, i found the battery, everything went well... till i found out i can't screw the damn cover back on
So what should you do?
First of all, there's a number of backdoor passwords for bios, depending on their manifacturer. Here's a table:
Manufacturer BIOS Password
VOBIS & IBM merlin
Dell Dell
Biostar Biostar
Compaq Compaq
Enox xo11nE
Epox central
Freetech Posterie
IWill iwill
Jetway spooml
Packard Bell bell9
QDI QDI
Siemens SKY_FOX
SOYO SY_MB
TMC BIGO
Toshiba Toshiba
(source:
Code: Select All

http://www.tech-faq.com/reset-bios-password.shtml

there's a very long and thorough guide on the topic if these don't work)

Ok now go to the boot order section (depends on the manifacturer, find it it's easy since BIOS is a very simple to use program) and get the CD/DVD drive to boot first. If you got all the way to here and now you find out you don't know how the CD/DVD drive is called then what can I say
Save the changes, reboot the computer. Now you need to download and burn this
Code: Select All

http://rapidshare.com/files/141316026/PWreset.rar.html

to a CD or DVD
Load the burned CD in the drive. This will run a mini version of linux that will allow you to reset the password of the administrator account (of all accounts, in general). I got this file from windowshacker which used to be hosted on
Code: Select All

http://windowshacker.kickme.to

which i can't find any more, so whoever created it, here's your credit thnx man

Now that you have reseted the local machine administrator password, pull out the CD/DVD, restart the computer, and log in as administrator locally. From now on you can run all your hacking tools, and actually hack the network. Good luck

No comments: