Create a hidden superuser for Windows

in #windows4 years ago

I think everyone is familiar with regedt32 in windows, but they cannot set permissions on the registry key. The biggest advantage of regedt32.exe is the ability to configure the registry key. Permissions The nt / 2000 / xp account information is under the HKEY_LOCAL_MACHINESAMSAM registry key, but other users, except the SYSTEM user SYSTEM, have no right to see the internal information, so I first use the regedt32.exe to set the SAM key for me and "Full control and permissions. This will read and write the information in the SAM key.

image.png

The specific steps are as follows:

  1. Suppose we log in to the broiler with the terminal service as superuser administrator. First create an account in the command line or in the account manager: hacker $, here Create this account under the command line hacker of the net user $ 1234 / add
  2. At startup / run, type: regedt32.exe and press Enter to run regedt32.exe.
    3, point "permissions" will pop up to add the account when you log in to the security bar, here I am registered as an administrator, so I will add administrator, and Set the permissions to "Full Control". Here you need to explain: it is better to add the account you are logged in to or the group where the account is located, and not modify the original account or group, otherwise it will present a number of unnecessary problems. If you hide the super user, you can delete the account you added here.
    4, then click "Start" → "Run" and enter "regedit.exe" Type to start the registry editor regedit.exe. Open the key: HKEY_LOCAL_MAICHINESAMSAMDomainsaccountusernameshacker $ "
  3. Copy the value of key "F" under element 000001F4 of the superuser and override the value of key "F" under element 00000409 of hacker $, and then combine 00000409.reg with the hacker.reg.
  4. Run net user hacker $ / del at the command line to remove hacker $: net user hacker $ / del
  5. Press F5 in the regedit.exe window to update. Then hit file: import the registry file and import the modified hacker.reg into the registry.
  6. At this point, the hidden superuser $ hacker was built, and then regedit.exe was closed. In the regedt32.exe window, change the permission of the HKEY_LOCAL_MACHINESAMSAM key back to the original state (just remove the added account manager).
    9, Note: Once the hidden superuser is created, the user in the account manager cannot see the hacker $, and the command line cannot be seen with the command <quo; net user "but after superuser is set, you can't change password again, if you use net user command to change hacker $ password, hidden superuser will be seen in account manager and cannot be removed.

Coin Marketplace

STEEM 0.20
TRX 0.13
JST 0.029
BTC 67241.85
ETH 3492.89
USDT 1.00
SBD 2.68