<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sidestepping Windows Login Credentials</title>
	<atom:link href="http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/</link>
	<description>Y2K compliant.</description>
	<lastBuildDate>Sat, 03 Dec 2011 15:32:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Hans Kokx</title>
		<link>http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/comment-page-1/#comment-563</link>
		<dc:creator>Hans Kokx</dc:creator>
		<pubDate>Tue, 06 Sep 2011 23:56:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.hadak.org/?p=175#comment-563</guid>
		<description>Yes, Steve, but you need to keep in mind: this post isn&#039;t about a third party utility to edit/change/remove your password, this is about the inherent security flaw of the Windows login process.  I challenge you to find a single user who a) knows how to encrypt their drive and b) has encrypted their drive that isn&#039;t an industry professional.

This is not the most effective way of getting into a box, and it isn&#039;t supposed to be a howto for hacking a computer, but rather a call to arms for Microsoft to fix some of the glaring security holes that has made their OS such a tragic example of how not to be a secure OS over the past 25 years.</description>
		<content:encoded><![CDATA[<p>Yes, Steve, but you need to keep in mind: this post isn&#8217;t about a third party utility to edit/change/remove your password, this is about the inherent security flaw of the Windows login process.  I challenge you to find a single user who a) knows how to encrypt their drive and b) has encrypted their drive that isn&#8217;t an industry professional.</p>
<p>This is not the most effective way of getting into a box, and it isn&#8217;t supposed to be a howto for hacking a computer, but rather a call to arms for Microsoft to fix some of the glaring security holes that has made their OS such a tragic example of how not to be a secure OS over the past 25 years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Bostedor</title>
		<link>http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/comment-page-1/#comment-562</link>
		<dc:creator>Steve Bostedor</dc:creator>
		<pubDate>Mon, 05 Sep 2011 16:38:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.hadak.org/?p=175#comment-562</guid>
		<description>A much easier way to get access to a Windows box that you have access to physically.  http://www.pogostick.net/~pnh/ntpasswd/

Any operating system can be rooted pretty easily as long as you have physical access to the unencrypted drive.

If you encrypt your hard drive with EFS, your hack won&#039;t work.</description>
		<content:encoded><![CDATA[<p>A much easier way to get access to a Windows box that you have access to physically.  <a href="http://www.pogostick.net/~pnh/ntpasswd/" rel="nofollow">http://www.pogostick.net/~pnh/ntpasswd/</a></p>
<p>Any operating system can be rooted pretty easily as long as you have physical access to the unencrypted drive.</p>
<p>If you encrypt your hard drive with EFS, your hack won&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/comment-page-1/#comment-314</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Tue, 05 Oct 2010 02:53:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.hadak.org/?p=175#comment-314</guid>
		<description>Another interesting trick is to edit the registry and change the login screensaver to explorer.exe.</description>
		<content:encoded><![CDATA[<p>Another interesting trick is to edit the registry and change the login screensaver to explorer.exe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hans Kokx</title>
		<link>http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/comment-page-1/#comment-73</link>
		<dc:creator>Hans Kokx</dc:creator>
		<pubDate>Thu, 15 Jul 2010 18:18:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.hadak.org/?p=175#comment-73</guid>
		<description>True.  Keep in mind, if you can touch it: you can own it.  Nothing is immune from being cracked, however this is a silly mistake for Microsoft to make.</description>
		<content:encoded><![CDATA[<p>True.  Keep in mind, if you can touch it: you can own it.  Nothing is immune from being cracked, however this is a silly mistake for Microsoft to make.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pritpaul</title>
		<link>http://www.hadak.org/2010/02/21/howto-pwn-any-windows-box-you-can-touch/comment-page-1/#comment-72</link>
		<dc:creator>Pritpaul</dc:creator>
		<pubDate>Thu, 15 Jul 2010 17:55:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.hadak.org/?p=175#comment-72</guid>
		<description>How is this different from mounting a Linux partition and changing the root password in /etc/passwd to a password of your choice?  You can pretty easily root any system you have physical access to unless the drive is encrypted (and even then you could wipe and install a new OS).</description>
		<content:encoded><![CDATA[<p>How is this different from mounting a Linux partition and changing the root password in /etc/passwd to a password of your choice?  You can pretty easily root any system you have physical access to unless the drive is encrypted (and even then you could wipe and install a new OS).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

