System Account Hack

Pages: 1, 2
free web hosting

Read Latest Entries..: (Post #13) by SilverFox on May 12 2007, 06:14 PM. (Line Breaks Removed)
...the write of this article is posting feedback on it?]LMAO
Read the FIRST post of this Topic. - Express your Opinion! Contribute Knowledge :-).

Free Web Hosting > Computers & Tech > Security issues & Exploits

System Account Hack

XPkiller
i found this when i accidently put CMD in my task manager:
________________________________________________________________
To start, lets open up a command prompt (Start > Run > cmd > PRESS ENTER).

At the prompt, enter the following command but replace 15:25 with 2 mins after current system time

CODE
at 15:25 /interactive "cmd.exe"

(dont forget to replace 15:25 with 2 minutes after current system time)

at the time set a new CMD box will magicaly appear

You'll notice that the title bar has changed from cmd.exe to svchost.exe (which is short for Service Host)
close the first CMD box but leave svchost open

now press CTRL+ALT+DEL, In task manager, go to the processes tab, and kill explorer.exe; your desktop and all open folders should disappear, but the system command prompt should still be there.

in the command prompt that remains type explorer.exe

A desktop will come back up, but what this? It isn't your desktop. Go to the start menu and look at the user name, it should say "SYSTEM". Also open up task manager again, and you'll notice that explorer.exe is now running as SYSTEM. The easiest way to get back into your own desktop

You are now the God of the windows machine

Abnormalities & experimentation

I've noticed different results depending on the service pack and hot fixes installed; for example, sometimes when I try to open the user control panel applet, I get a error saying user not recognized, and the location where the Local System account profile is stored also varies. I haven't had much time to explore this, so if you find anything else, please use the email address found in the contact section of this article, and send a note my way.

A quick fix

A way to prevent this from happening at all, would be to make the task scheduler service run under a unprivileged account. You can do this by opening the services control panel (Start > Run > services.msc), and right clicking "Task Scheduler" and going to the Log On tab. Change it to "This Account" and enter the account information you want it to use (has to be an existing account) then restart the service. This may break some programs that use the Task Scheduler and depend on it for SYSTEM access; you have been warned. Otherwise, simple disable the Task Scheduler service.

 

 

 


Reply

nightfox
Wow... I printed this one out for future reference! Gotta love Windows! smile.gif But this really shows you how dumb Microsoft really is. There might even be other tricks too... such as executing malicious code or what not at a time. In other words, your system could be a ticking time bomb and the malicious code could really do some damage (especially being "god windows user").

[N]F

Reply

Jimmy89
Its amazing that there is such a huge hole in their Operating System. Though, most come to expect things like this from microsoft, not something as massive as this!

Do you know which versions of Windows does this effect? Only XP, or does it go back a few versions?
-jimmy

Reply

saint-michael
Wow I wonder if Microsoft knows about it little trick, would it possible to do this on another computer through the net if you had a good trojan put in place?

Reply

XPkiller
Unfortunatly i only have XP, so cant try it on older versions but im sure it would work

and im also fairly sure the Trojan thing would work too

Reply

Team Destiny 07
What are the benefits?

Reply

FirefoxRocks
This was discussed before in: http://astahost.com/windows-scheduler-can-...hts-t13956.html

Anyways, I submitted this security threat to Secunia a few months ago, but they didn't look at it. But this could make a limited account even higher than Administrator on the computer (it doesn't work on the Guest account though, my friend tried it out).

But, yeah, someone could probably remotely trigger this command. It's not that hard to start and kill a task you know?

Reply

XPkiller
i did it at school back in the good old times when my sys admin forgot to disable the cmd

lol, that was quite funny

Reply

duoo
nice xpkiller

Reply

develCuy
I suggest Linux for that reason. Now I have another prove to feel me insecure using windows and safer with Linux. "A patched system will ever have new holes, including the patches".
Blessings!

Reply

Latest Entries

SilverFox
...the write of this article is posting feedback on it?

]LMAO

Reply

Nintendo
i just tryed to remotly connect to my test PC using this method
it succeeded, then, depending on the XP service pack, it would either let me do it with guest
or not let me do it with guest, if you can then the PC is just wide open from guest----> system

when i was in i experimented with differant things
i changed the administrator and all the other passwords remotly, locking the user out

you can kill the AV's and FWL's on a PC

you can also revert windows back to its previus state (being win 98 here)

you can play messages or music to the user of the PC, you can lock the PC



Reply

mvs.en
Yeah, I checked this out and tested the whole exploit thing a week or two ago...

Didn't seem to do any real damage (I probably should have thought about it a bit before I tested it)
But it DID kind of hurt my STart menu in that after I was done with it all those lovely little programs that get listed on the XP start menu (The most commonly openned programs)... They all vanished off the list and I am unable to get them back.

I'm fine with it though, they weren't really that important to me and I've already found ways to compensate for them.

For a couple days using the exploit also killed the configurations for my mouse... But I was able to fix that.

I think there were a couple other little blips I noticed after testing the exploit, but none of them were very noticeable at all.

The only one that I'd be careful for is the programs under the Start Menu issue... But I'm not even 100% sure they dissapeared because of the SYSTEM account.

I'd just keep it in mind if any of you choose to test it at all.

Reply


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

Pages: 1, 2
Recent Queries:-
  1. hack facebook password - 4.53 hr back. (2)
  2. hacking facebook accounts and passwords - 13.58 hr back. (1)
  3. free programs to hack myspace accounts - 15.64 hr back. (1)
  4. hack a wow account - 18.77 hr back. (1)
  5. free wow account hacks - 27.91 hr back. (1)
  6. hack facebook account password - 44.88 hr back. (1)
  7. hacking into facebook account - 46.13 hr back. (1)
  8. prevent wow account hack - 69.38 hr back. (1)
  9. how to kill system account - 71.01 hr back. (3)
  10. hack into a facebook account - 71.30 hr back. (1)
  11. hack facebook - 85.64 hr back. (2)
  12. hack facebook account - 99.65 hr back. (1)
  13. scheduler to get system access - 106.47 hr back. (1)
  14. hack a facebook account - 115.91 hr back. (1)
Similar Topics

Keywords : system, account, hack

  1. Facebook Hack
    (0)
  2. Hack Tools (for Education And Hobby Only)
    hack tools that most hackers use (4)
    For education and hobby use only. The is a live cd called " backtrack" there are many hacker
    tools inside include hydra- web cracking tools, wireshark -sniffing tool and ect. BackTrack is the
    most Top rated linux live distribution focused on penetration testing. With no installation
    whatsoever, the analysis platform is started directly from the CD-Rom and is fully accessible within
    minutes. It's evolved from the merge of the two wide spread distributions - Whax and Auditor
    Security Collection. By joining forces and replacing these distributions, BackTrack ha....
  3. Myspace.com Flash Hack
    (5)
    http://www.trap17.com/forums/myspace-com-f...ack-t40903.html heres the post i made on trap17 about
    this.....
  4. Please Hack My Site
    (23)
    Sorry for the subject, as i will not give you my website link /tongue.gif"
    style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" /> It is a service i hope to
    see it soon, though it is so much dangerous but i hope to have it, as i'm a web developer, the
    biggest problem to me always is to test the website i coded, test its security and how much is it
    safe, don't tell me try it yourself by trying to hack it, i already know all the passwords
    /tongue.gif" style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" />, i need someone
    or a s....
  5. Need To Hack An Admin Account On Xp... No Problem!
    It's so easy to hack an account you'll be amazed (61)
    Well recently one of my good girl that is a friend got a laptop from her dad. Her dad does websites
    so the laptop was new and worked fine, but needed to be defraged. The one problem, her nor her dad
    knew the admin password. I told her to post her question on Trap 17 and it got answered with in
    minutes. All you have to do is these few steps: 1. Reboot 2. Before the windows logo comes up press
    F11 (Just start clicking it over and over again until the windows logo comes up.) 3. Just sit and
    let it do it's thing and when the login screen comes up click on the Admin icon....

    1. Looking for system, account, hack






*SIMILAR VIDEOS*
Searching Video's for system, account, hack
advertisement




System Account Hack