Lost Administrator Password

I have a job site where one employee has seemed to changed my Administrator Password on a Win2000 machine. Does anybody know how he might have pulled it off and what I need to do the same so I can see if he does it again. ...




Topic Options
#102431 - 06/24/02 05:14 PM Lost Administrator Password
shoe1 Offline
stranger

Registered: 06/24/02
Posts: 4
I have a job site where one employee has seemed to changed my Administrator Password on a Win2000 machine. Does anybody know how he might have pulled it off and what I need to do the same so I can see if he does it again.

Thanks
Shoe1 frown

Top
Advertisement
#102447 - 06/24/02 08:33 PM Re: Lost Administrator Password
Davros Offline
enthusiast

Registered: 03/21/02
Posts: 347
Loc: Houston, Texas
Either he got your admin password somehow, or he used a hack proggie. There's several little programs that allow you to change the admin password. One is called Locksmith from Winternals and allows you to change the password to anything you want, but you need to mount the system drive from another OS session to do it. Search the workstations to see if Locksmith was installed in any of them. Another is a linux floppy disk, where you boot with your W2K cd, and press F6 to load other drivers, and put the floppy in. It changes the password to 1234.

I suggest you change the boot order to hard drive first, lock the case, password the CMOS, and set GPO's to restrict network access as tight as you can. Also set a GPO to prevent access to the CD or floppy by anyone but admins on that machine. And make sure you check to see who is watching when entering your password, and keep the server consoles locked when you are away from it.

Another thing you may consider is adding a syskey password. Only problem is that attempts to change the password can corrupt AD, so you will not be able to boot at all, and will have to restore AD from backup. Better would be to add a power on password in CMSO.

You can audit account management and filter the audit logs for changes to the admin account. This would catch him if he stole your admin password somehow, but won't work if he's using one of those hacks.

Top
#102450 - 06/24/02 08:56 PM Re: Lost Administrator Password
pbuckne Offline
member

Registered: 10/25/01
Posts: 148
I agree with the watching your back part, corp I used to work for had great security, or so we thought. I found a week old network level admin password lying on a slip of paper in the floor... Needless to say the password was changed... again.

Top
#102504 - 06/25/02 04:06 PM Re: Lost Administrator Password
shoe1 Offline
stranger

Registered: 06/24/02
Posts: 4
Thats great advise and I will put it to good use. I have to admit I don't have experience with linux and that answer is definitly a new one to me. Thanks all for replying. Always look here first for professional help when needed.
Shoe

Top
#102729 - 06/28/02 01:42 AM Re: Lost Administrator Password
Igor Offline
enthusiast

Registered: 07/24/99
Posts: 382
You can also get a bick stick and beat the password out of they guy who changed it.
Or just ask him to tell it to you and then get the stick out so he never attempts to steal it again.

Top
#104295 - 07/15/02 10:32 PM Re: Lost Administrator Password
Xelerated Offline
newbie

Registered: 07/09/02
Posts: 32
There are several Linux boot disks out there for download that will change any NT password on the local machine (local being the one they can get to physically and boot with the floppy)
Change the BIOS's to have an admin password, make the floppy not bootable via the bios, sure its not going to STOP anyone, but may make it not worth their while, especially if they have a chance of getting walked in on with the case open. (i think ntbootdisk.com has this disk too, the linux disk that is)

Top
#105198 - 07/22/02 10:34 PM Re: Lost Administrator Password
vern2 Offline
stranger

Registered: 07/22/02
Posts: 16

Top


Forums
Windows Support Forums
Everything New Technology
Legacy OS
Hardware
Software
Games
Networking
Customization & Tweaking
Security

Linux Support Forums
Everything Linux
Linux Hardware
Linux Software
Linux Games
Linux Networking
Linux Customization & Tweaking
Linux Security

Apple Support Forums
Everything Apple
Recent Topics
What version of Linux is this?
by DxxLinux
Yesterday at 07:59 PM
Anything like HyperCam?
by Luckycharm8989
12/11/09 02:08 PM
Thank you for your help
by guaiguai
12/11/09 07:29 AM
What the problem is?
by guaiguai
12/11/09 05:09 AM
Need an database for Dictionary
by shaanspecial
12/09/09 10:19 AM
Who's Online
1 Registered (Philipp), 251 Guests and 34 Spiders online.
Key: Admin, Global Mod, Mod
Forum Stats
91328 Members
24 Forums
58881 Topics
189392 Posts

Max Online: 1079 @ 03/12/08 01:36 PM

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22