<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>What&#039;s My Pass? &#187; Privilege Escalation</title>
	<atom:link href="http://www.whatsmypass.com/category/privilege-escalation/feed" rel="self" type="application/rss+xml" />
	<link>http://www.whatsmypass.com</link>
	<description>Password Recovery for Windows, Mac, Linux, browsers, email, instant messengers, BIOS</description>
	<lastBuildDate>Tue, 24 Jan 2012 16:08:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cracking WPA/WPA2 with Reaver</title>
		<link>http://www.whatsmypass.com/cracking-wpawpa2-with-reaver</link>
		<comments>http://www.whatsmypass.com/cracking-wpawpa2-with-reaver#comments</comments>
		<pubDate>Tue, 24 Jan 2012 15:57:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1311</guid>
		<description><![CDATA[The WiFi Protected Setup (WPS) protocol is vulnerable to a brute force attack that allows an attacker to recover an access point’s WPS pin, and subsequently the WPA/WPA2 passphrase, in just a matter of hours, using the open source tool called Reaver. Think your 32 character alpha-numeric password is uncrackable? If your wireless router is [...]]]></description>
			<content:encoded><![CDATA[<p>The WiFi Protected Setup (WPS) protocol is vulnerable to a brute force attack that allows an attacker to recover an access point’s WPS pin, and subsequently the WPA/WPA2 passphrase, in just a matter of hours, using the open source tool called <a href="http://code.google.com/p/reaver-wps/" title="http://code.google.com/p/reaver-wps/" target="_blank">Reaver</a>. Think your 32 character alpha-numeric password is uncrackable? If your wireless router is using WPS then your router may be spit back your password in plain-text to the attacker in less than 10 hrs. WPS allows users to enter an 8 digit PIN to connect to a secured network without having to enter a passphrase. When a user supplies the correct PIN the access point essentially gives the user the WPA/WPA2 PSK that is needed to connect to the network. Reaver will determine an access point&#8217;s PIN and then extract the PSK and give it to the attacker. When we tested Reaver in our labs we were able to recovery the WPA password in 1.5hrs and the longest run was 7.5hrs <img alt="Reaver Test" src="http://i.imgur.com/MQ0Su.jpg" title="Reaver Test" class="aligncenter" width="520" height="480" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/cracking-wpawpa2-with-reaver/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone iOS 4.3.5 vulnerability</title>
		<link>http://www.whatsmypass.com/iphone-ios-4-3-5-vulnerability</link>
		<comments>http://www.whatsmypass.com/iphone-ios-4-3-5-vulnerability#comments</comments>
		<pubDate>Mon, 12 Dec 2011 15:16:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Privilege Escalation]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1309</guid>
		<description><![CDATA[iPhone iOS 4.3.5 vulnerability (pin/password bypass to make calls) from Sigtrap. Turn on the phone. Slide to unlock. Press Emergency Call. Enter a very long phone number. Press and hold down the Power button. Wait for one second. Press the Call button. The phone will show the &#8220;Slide to power off&#8221; screen. Release the Power [...]]]></description>
			<content:encoded><![CDATA[<p><center><iframe src="http://player.vimeo.com/video/31654453?title=0&amp;byline=0&amp;portrait=0" width="400" height="300" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe>
<p><a href="http://vimeo.com/31654453">iPhone iOS 4.3.5 vulnerability (pin/password bypass to make calls)</a> from <a href="http://vimeo.com/sigtrap">Sigtrap</a>.</p>
<p></center></p>
<ol>
<li>Turn on the phone.</li>
<li>Slide to unlock.</li>
<li>Press Emergency Call.</li>
<li>Enter a very long phone number.</li>
<li>Press and hold down the Power button.</li>
<li>Wait for one second.</li>
<li>Press the Call button.</li>
<li>The phone will show the &#8220;Slide to power off&#8221; screen.</li>
<li>Release the Power button.</li>
<li>Press Cancel.</li>
<li>Double press the Home button.</li>
<li>Press the Phone icon.</li>
<li>Make calls. </li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/iphone-ios-4-3-5-vulnerability/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bypass IPad 2 passcode with a smart cover</title>
		<link>http://www.whatsmypass.com/bypass-ipad-2-passcode-with-a-smart-cover</link>
		<comments>http://www.whatsmypass.com/bypass-ipad-2-passcode-with-a-smart-cover#comments</comments>
		<pubDate>Fri, 21 Oct 2011 04:13:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Privilege Escalation]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1292</guid>
		<description><![CDATA[Anyone with a Smart Cover can break into your “password-protected” iPad 2. This issue occurs in iOS 5, but we’re hearing uncorroborated reports of it also working in earlier versions of iOS 4.3. What the flaw allows: As you can see in the video above, a Smart Cover can essentially unlock an iPad 2. The [...]]]></description>
			<content:encoded><![CDATA[<p>Anyone with a Smart Cover can break into your “password-protected” iPad 2. This issue occurs in iOS 5, but we’re hearing uncorroborated reports of it also working in earlier versions of iOS 4.3.<br />
<iframe width="500" height="315" src="http://www.youtube.com/embed/NLgQ22naQhE" frameborder="0" allowfullscreen></iframe></p>
<p><strong>What the flaw allows:</strong></p>
<p>As you can see in the video above, a Smart Cover can essentially unlock an iPad 2. The person who unlocks your iPad 2 will not have complete access to your iPad, but will be able to gain entrance to whatever you locked your iPad 2 on. If your iPad 2 went to sleep in Mail, Safari, Messages, Contacts, or Maps, you can imagine the sorts of personal information that can be viewed on your iPad. If you left your iPad 2 on its Home screen, the person can view which applications you have on your device, control media from the multitasking bar, but not much else.</p>
<p><strong>How to re-create it:</strong></p>
<p>1) Lock a password protected iPad 2</p>
<p>2) Hold down power button until iPad 2 reaches turn off slider</p>
<p>3) Close Smart Cover</p>
<p>4) Open Smart Cover</p>
<p>5) Click cancel on the bottom of the screen</p>
<p>(src:<a href="http://9to5mac.com/2011/10/20/anyone-with-a-smart-cover-can-break-into-your-ipad-2/" title="9to5mac" target="_blank">9to5mac.com</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/bypass-ipad-2-passcode-with-a-smart-cover/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hard Drive Master Passwords</title>
		<link>http://www.whatsmypass.com/hard-drive-master-passwords</link>
		<comments>http://www.whatsmypass.com/hard-drive-master-passwords#comments</comments>
		<pubDate>Sun, 16 Oct 2011 08:13:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Password Info]]></category>
		<category><![CDATA[Privilege Escalation]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1278</guid>
		<description><![CDATA[Here&#8217;s a small compilation of passwords. If you have any to add please email us. We also can crack DELL HDD passwords for $10 ::Here:: SEAGATE -&#62; “Seagate” +25 spaces MAXTOR series N40P -&#62; “Maxtor INIT SECURITY TEST STEP ” +1 or +2 spaces series N40P -&#62; “Maxtor INIT SECURITY TEST STEP F” series 541DX -&#62; [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a small compilation of <a href="http://ipv5.wordpress.com/2008/04/14/list-of-hard-disk-ata-master-passwords/" target="_blank">passwords</a>. If you have any to add please email us. We also can crack DELL HDD passwords for $10 <a href="http://www.whatsmypass.com/bios-password-recovery-service">::Here::</a></p>
<p><strong>SEAGATE</strong> -&gt; “Seagate” +25 spaces</p>
<p><strong>MAXTOR</strong><br />
series N40P -&gt; “Maxtor INIT SECURITY TEST STEP ” +1 or +2 spaces<br />
series N40P -&gt; “Maxtor INIT SECURITY TEST STEP F”<br />
series 541DX -&gt; “Maxtor” +24 spaces<br />
series Athena (D541X model 2B) and diamondmax80 -&gt; “Maxtor”</p>
<p><strong>WESTERN DIGITAL</strong> -&gt; “WDCWDCWDCWDCWDCWDCWDCWDCWDCWDCWD”</p>
<p><strong>FUJITSU</strong> -&gt; 32 spaces</p>
<p><strong>SAMSUNG</strong> -&gt; “ttttttttttttttttttttttttttttttttt” (32 times t)</p>
<p><strong>IBM</strong><br />
series DTTA -&gt; “CED79IJUFNATIT” +18 spaces<br />
series DJNA -&gt; “VON89IJUFSUNAJ” +18 spaces<br />
series DPTA -&gt; “VON89IJUFSUNAJ” +18 spaces<br />
series DTLA -&gt; “RAM00IJUFOTSELET” +16 spaces<br />
series DADA-26480 (6,4gb) -&gt; “BEF89IJUF__AIDACA” +15 spaces</p>
<p><strong>HITACHI</strong> series DK23AA, DK23BA and DK23CA -&gt; 32 spaces</p>
<p><strong>TOSHIBA</strong> -&gt; 32 spaces</p>
<p>For xbox hdds try “XBOXSCENE” or “TEAMASSEMBLY” too</p>
<p>There is also some software available to reset the password called <a href="http://hddguru.com/software/2005.10.02-MHDD/" target="_blank">MHDD</a>, another suggested program is <a href="http://www.rockbox.org/atapwd.zip" target="_blank">ATAPWD</a>. A Commercial tool from <a href="http://www.hddunlock.com/download/" target="_blank">HDDLock</a> claims to unlock drives and prices <a href="http://www.hddunlock.com/purchase/" target="_blank">vary</a> with drive size.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/hard-drive-master-passwords/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Password Reset CD</title>
		<link>http://www.whatsmypass.com/password-reset-cd</link>
		<comments>http://www.whatsmypass.com/password-reset-cd#comments</comments>
		<pubDate>Fri, 07 Oct 2011 14:46:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Password Info]]></category>
		<category><![CDATA[Privilege Escalation]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1286</guid>
		<description><![CDATA[Looks like pcloginnow.com is now offering their password reset CD for free on their site. Click the image to download it. PCLoginNow is an easy-to-use tool to reset local administrator and other accounts passwords on Windows system. No need to reinstall the system. It resets Windows passwords and Windows security settings instantly. All version of [...]]]></description>
			<content:encoded><![CDATA[<p>Looks like <a href="http://www.pcloginnow.com/" title="http://www.pcloginnow.com/" target="_blank">pcloginnow.com</a> is now offering their password reset CD for free on their site. Click the image to download it.<br />
<center><a href="http://www.pcloginnow.com/download/PCLoginNow_Full.exe" title="PCLoginNow_Full.exe" target="_blank"><img src="http://www.pcloginnow.com/images/box_only.jpg" alt="" /></a></center><br />
<br />PCLoginNow  is an easy-to-use tool to reset local administrator and other accounts passwords on Windows system. No need to reinstall the system. It resets Windows passwords and Windows security settings instantly. All version of Windows are completely supported.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/password-reset-cd/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OS X Lion bugs allow changing local user passwords and viewing shadow files</title>
		<link>http://www.whatsmypass.com/os-x-lion-bugs-allow-changing-local-user-passwords-and-viewing-hash</link>
		<comments>http://www.whatsmypass.com/os-x-lion-bugs-allow-changing-local-user-passwords-and-viewing-hash#comments</comments>
		<pubDate>Tue, 20 Sep 2011 13:55:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1265</guid>
		<description><![CDATA[The latest version of OS X Lion allows any user to easily change the password of any local account, due to permissions oversights on Apple&#8217;s part. The news comes less than a month after another Lion vulnerability that let users bypass LDAP without a password gained notoriety. Originally reported by Defence in Depth blogger Patrick [...]]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://news.hitb.org/sites/default/files/styles/large/public/field/image/5974823525_071b06d1b4_z.jpg" alt="http://www.flickr.com/photos/rubendomfer/5974823525/" title="Credit: Ruben Domfer (Flickr) "></a></center></p>
<p>The latest version of OS X Lion allows any user to easily change the password of any local account, due to permissions oversights on Apple&#8217;s part. The news comes less than a month after another Lion vulnerability that let users bypass LDAP without a password gained notoriety.</p>
<p>Originally reported by Defence in Depth blogger Patrick Dunstan, the root of the newly discovered problem in Mac OS X 10.7 is tied to the user-specific shadow files used in modern OS X platforms. These files are essentially hash databases and contain, among other things, the user&#8217;s encrypted passwords. Ideally, they should be accessible only via high-privilege accounts.</p>
<p>According to Dunstan, Apple dropped the ball in terms of how Lion handles privilege. &#8220;Whilst non-root users are unable to access the shadow files directly, Lion actually provides non-root users the ability to still view password hash data,&#8221; Dunstan wrote. &#8220;This is accomplished by extracting the data straight from Directory Services.&#8221; Any user can accomplish this trick by simply invoking the directory services listing using the /Search/ path &#8212; for example, $ dscl localhost -read /Search/Users/bob (where &#8220;bob&#8221; is the username). This causes Lion OS X to spew out the contents of Bob&#8217;s shadow hash file, including data that can be used to crack Bob&#8217;s password with a simple script, such as a Python script written by Dunstan.</p>
<p>Source: <a href="http://www.infoworld.com/t/password-security/os-x-lion-bugs-let-hackers-view-change-local-user-passwords-173463" rel="nofollow" target="_blank">Info World</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/os-x-lion-bugs-allow-changing-local-user-passwords-and-viewing-hash/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The new threat</title>
		<link>http://www.whatsmypass.com/the-new-threat</link>
		<comments>http://www.whatsmypass.com/the-new-threat#comments</comments>
		<pubDate>Sat, 12 Feb 2011 17:58:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1145</guid>
		<description><![CDATA[Programmable embedded devices have the capability of being detected as a HID device , just like a keyboard or mouse. So if you have physical access and a minute alone you can compromise a system with something the size of your thumb. The possibilities are endless, HTTP/FTP download, injecting binaries into debug or Powershell etc.. [...]]]></description>
			<content:encoded><![CDATA[<p>Programmable embedded devices have the capability of being detected as a HID device , just like a keyboard or mouse. So if you have physical access and a minute alone you can compromise a system with something the size of your thumb. The possibilities are endless, HTTP/FTP download, injecting binaries into debug or Powershell etc.. Also this device is cross platform which means Windows,Linux,UNIX and Apple are all vulnerable.</p>
<p>Here&#8217;s an example project we made for a Windows7 box that adds a new Admin user to the system and hides that user from the logon screen. the whole process takes about 16 seconds , with most of the time taken by the device being detected as a keyboard and the driver installed. The device costs about $20 and can be found <a href="http://www.pjrc.com/teensy/">here</a></p>
<p><center><iframe title="YouTube video player" width="475" height="390" src="http://www.youtube.com/embed/MyG3x7HHwwA" frameborder="0" allowfullscreen></iframe></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/the-new-threat/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Make calls from locked iPhone 4s</title>
		<link>http://www.whatsmypass.com/make-calls-from-locked-iphone-4s</link>
		<comments>http://www.whatsmypass.com/make-calls-from-locked-iphone-4s#comments</comments>
		<pubDate>Tue, 26 Oct 2010 01:39:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Privilege Escalation]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1096</guid>
		<description><![CDATA[A security hole in iPhone 4 software allows you to make a call after dialing a few pound signs and timing a few others as found by a MacForums member. When your iPhone is locked with a passcode tap Emergency Call, then enter a non-emergency number such as ###. Next tap the call button and [...]]]></description>
			<content:encoded><![CDATA[<p>A security hole in iPhone 4 software allows you to make a call after  dialing a few pound signs and timing a few others as found by a <a href="http://forums.macrumors.com/showthread.php?t=1035879">MacForums member</a>.</p>
<blockquote><p>When your iPhone is locked with a passcode tap Emergency  Call, then enter a non-emergency number such as ###. Next tap the call  button and immediately hit the lock button. It should open up the Phone  app where you can see all your contacts, call any number, etc.</p></blockquote>
<p>A very similar security flaw discovered on the iPhone that we <a href="http://www.whatsmypass.com/bypass-iphone-password-screen-to-make-calls">blogged about</a> in 2008 that allowed people to easily bypass the lock screen to access mail, contacts and bookmarks. Apple later acknowledged the bug and issued a software update patching the issue.</p>
<p>An Apple spokeswoman&#8217;s response regarding the security flaw:<br />
<em>“We’re aware of this issue and we will deliver a fix to customers as part of the iOS 4.2 software update in November.”</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/make-calls-from-locked-iphone-4s/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Change your password with sticky keys</title>
		<link>http://www.whatsmypass.com/change-your-password-with-sticky-keys</link>
		<comments>http://www.whatsmypass.com/change-your-password-with-sticky-keys#comments</comments>
		<pubDate>Wed, 18 Aug 2010 22:56:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Administrator]]></category>
		<category><![CDATA[Internet Explorer Passwords]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows PE]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=1007</guid>
		<description><![CDATA[Forgot the administrator password? There are many ways to access a Windows installation if you forgot the administrator password. Today I’ll show you another procedure to reset the Windows password by replacing the Sticky Keys application. This program allows you to use the function keys SHIFT, CTRL, ALT, or the Windows key by typing one [...]]]></description>
			<content:encoded><![CDATA[<p>Forgot the administrator password? There are many ways to access a Windows installation if you forgot the administrator password. Today I’ll show you another procedure to reset the Windows password by replacing the Sticky Keys application. This program allows you to use the function keys SHIFT, CTRL, ALT, or the Windows key by typing one key after the other instead of pressing them simultaneously with the second key. The main advantage of this password reset method is that you don’t need third-party software; another plus is that it is easy to carry out because no Registry hack is required, as when you offline enable the built-in administrator.</p>
<p>Please note that resetting the password from an account other than  the corresponding user account always means that the user loses the  credentials stored in the Windows  Vault, stored  Internet Explorer passwords, and files that you encrypted with the  Encrypting File System (EFS). Of course, if you have a backup of these  credentials, you can restore them; likewise, if you have exported the  private EFS key, you can import it again after you have reset the  password.</p>
<p>Like with all other solutions that allow you to reset the Windows  password without having an account on the corresponding computer, you  have to boot from a second operating system and access the Windows  installation while it is offline.</p>
<p>You can do this with a bootable  Windows PE USB stick or by using Windows RE. You can start Windows  RE by booting the Windows Vista or Windows 7 setup DVD and then  selecting “Repair” instead of “Install Windows.”</p>
<p> By the way, you can’t use the Windows XP boot CD for this purpose  because its Recovery Console will ask for a password for the offline  installation. However, you can use a Vista or Windows 7 DVD to reset a  forgotten Windows administrator password on Windows XP.</p>
<p>This works because Windows RE, which is based on Vista or Windows 7,  will let you launch a command prompt with access to an offline  installation without requiring a password.<br />
<span id="more-1007"></span></p>
<h2>To reset a forgotten administrator password, follow these steps:</h2>
<ol>
<li>Boot from Windows PE or Windows RE and access the command prompt.</li>
<li>Find the drive letter of the partition where Windows is installed.  In Vista and Windows XP, it is usually C:, in Windows 7, it is D: in  most cases because the first partition contains Startup Repair. To find  the drive letter, type C: (or D:, respectively) and search for the  Windows folder. Note that Windows PE (RE) usually resides on X:.</li>
<li>Type the following command (replace “c:” with the correct drive  letter if Windows is not located on C:):<br />
<strong>copy c:\windows\system32\sethc.exe c:\<br />
</strong>This creates a copy of sethc.exe to restore later.</li>
<li>Type this command to replace sethc.exe with cmd.exe:<br />
<strong>copy /y c:\windows\system32\cmd.exe  c:\windows\system32\sethc.exe</strong></li>
<li>Reboot your computer and start the Windows installation where you  forgot the administrator password.</li>
<li>After you see the logon screen, press the SHIFT key five times.</li>
<li>You should see a command prompt where you can enter the following  command to reset the Windows password (see screenshot above):<br />
<strong>net user <em>you_user_name new_password<br />
</em></strong>If you don’t know your user name, just type <strong>net  user </strong>to list the available user names.</li>
<li>You can now log on with the new password.</li>
</ol>
<p>I recommend that you replace sethc.exe with the copy you stored in  the root folder of your system drive in step 3. For this, you have to  boot up again with Windows PE or RE because you can’t replace system  files while the Windows installation is online.</p>
<p>Via: <a href="http://4sysops.com/archives/forgot-the-administrator-password-the-sticky-keys-trick/">4sysops.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/change-your-password-with-sticky-keys/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Kon Boot 1.1</title>
		<link>http://www.whatsmypass.com/kon-boot-1-1</link>
		<comments>http://www.whatsmypass.com/kon-boot-1-1#comments</comments>
		<pubDate>Mon, 10 May 2010 09:08:13 +0000</pubDate>
		<dc:creator>Dev Team</dc:creator>
				<category><![CDATA[cracking]]></category>
		<category><![CDATA[Privilege Escalation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[kon-boot]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[USD]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.whatsmypass.com/?p=935</guid>
		<description><![CDATA[We reviewed Kon Boot 1.0 last year HERE which was a great breakthrough program that allowed you to boot into a Windows machine and bypass the logon screen without entering a password. To accomplish this, Kon Boot hooks the bios on the fly subverting the Windows kernel authentication temporarily and allowing you access. Since this [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://img718.imageshack.us/img718/1199/konboot11.png" alt="Kon Boot 1.1" /><br />
We reviewed Kon Boot 1.0 last year <a href="http://www.whatsmypass.com/bypass-windows-logon-password">HERE</a> which was a great breakthrough program that allowed you to boot into a Windows machine and bypass the logon screen without entering a password. To accomplish this, Kon Boot hooks the bios on the fly subverting the Windows kernel authentication temporarily and allowing you access. Since this is a temporary process the computer is back to normal when you reboot. This allowed you to access the computer without having to take the time to reset the password or crack it, and it left the computer untouched. Now, a year later, Kon Boot v1.1 has been released with new features, such as booting from floppy,CD, or usb, privilege escalation support which allows you to gain SYSTEM privileges from ANY account on the system. For example, you can boot from Kon Boot and log in as Guest and run &#8216;Net User&#8217; command to add a new user,reset admin passwords etc as SYSTEM </p>
<p>It also has a bunch of new bug fixes/updates.</p>
<ol>
<li>- Added 64-bit environment support</li>
<li>- Added USB support tools (grldr, klmemusb)</li>
<li>- Added debugging code to make it easier to track down various compatibility problems</li>
<li>- Fixed bug in Windows 7 support failures</li>
<li>- Removed Linux support</li>
<li>- Many performance improvements to source code</li>
<li>- Improved BIOS support by reducing code size significantly</li>
</ol>
<p>Unfortunately it is no longer free. But for a meager price of $15.99 for a personal license, it gives you free updates and support for a period of 6 months. You can still use it without restrictions after that period.<br />
They also offer a commercial license, for $75.99 with 1 year of support and updates, allowing you to use on business environment.<br />
To purchase Kon Boot v1. 1,visit their website <a href="http://www.kryptoslogic.com/?area=2&#038;item=2">http://www.kryptoslogic.com</a></p>
<p>We are also giving away 10 personal licenses this week to some lucky readers!!! More details to come!!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.whatsmypass.com/kon-boot-1-1/feed</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
	</channel>
</rss>

