MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides  
Homepage Register FAQ Members Mark Forums Read Advertise Marketplace FPSowned


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > Discussions > General Chat
Reload this Page How To: Become the SYSTEM user in Windows XP! You can do ANYTHING!
General Chat All off-topic discussions go here.

Reply
 
LinkBack Thread Tools
How To: Become the SYSTEM user in Windows XP! You can do ANYTHING!
(#1)
Old
Dragonshadow's Avatar
Dragonshadow is Offline
KuRIoS Wannabe
Legendary User
Rep Power: 7
Reputation: 886
Dragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to behold
 
Posts: 1,944
Join Date: Apr 2007
Location: In the shadows...
How To: Become the SYSTEM user in Windows XP! You can do ANYTHING! - 02-25-2008

THIS DOES NOT WORK IN VISTA
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

In Windows XP, the system run level is higher than administrator, and has full control of the operating system and it’s kernel. When you hit Ctrl+Alt+Tab and get to the task manager process list, you will see that the System User controls several processes



Most System processes are required by the operating system, and cannot be closed, even by an Administrator account. Attempting to close them will result in a error message.Under normal circumstances, a user cannot run code as System, only the operating system itself has this ability, but by using the command line, we will trick Windows into running our desktop as System, along with all applications that are started from within.

Changing your administrator password on Windows XP, may be necessary at times depending on the scenario. One such technique, with a full desktop available to you is also possible.

--------------------------------------------------------------------------------------------------

Lets get rolling:

Open up command prompt and type:

Code:
at
If it responds with an “access denied” error, then we are out of luck, and you’ll have to try another method of privilege escalation; if it responds with “There are no entries in the list” (or sometimes with multiple entries already in the list) then we are good. Access to the at command varies, on some installations of Windows, even the Guest account can access it, on others it’s limited to Administrator accounts.

--------------------------------------------------------------------------------------------------

If you can use the at command, which is basically a task scheduler, then enter a command similar to something like mine:

Code:
at 23:27 /interactive "cmd.exe"


the time is usually a minute (or two) ahead of your present time in the 24 hours format

--------------------------------------------------------------------------------------------------

When the system clock reaches the time you set, then a new command prompt will magically run. The difference is that this one is running with system privileges (because it was started by the task scheduler service, which runs under the Local System account). It should look like this:




You’ll notice that the title bar has changed from cmd.exe to svchost.exe (which is short for Service Host).

--------------------------------------------------------------------------------------------------

End the current Explorer.exe. [hit ctrl+alt+del->task manager->processes]

--------------------------------------------------------------------------------------------------

At the system command prompt, enter in the following:

Code:
explorer.exe
--------------------------------------------------------------------------------------------------

Voila! …user System logged in!



--------------------------------------------------------------------------------------------------

Look At The Stuff you can do!



--------------------------------------------------------------------------------------------------

Log out to get back to your normal user login

--------------------------------------------------------------------------------------------------

TO FIX: Open the services control panel (Start > Run > services.msc) and disable the Task Scheduler service.


Imagine the things (h4x) we could do with this?

I wonder if we could prevent warden from even running?


----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

[Only registered and activated users can see links. ]



Last edited by Dragonshadow; 02-26-2008 at 01:19 PM..
Reply With Quote

Donate to remove ads.
(#2)
Old
Phygar's Avatar
Phygar is Offline
Contributor
Rep Power: 3
Reputation: 268
Phygar is a jewel in the roughPhygar is a jewel in the roughPhygar is a jewel in the rough
 
Posts: 877
Join Date: Nov 2007
Location: 34°48'51N 107°16'30W
02-25-2008

Guys you gotta do it it's awesome!
Reply With Quote
(#3)
Old
Predatorpunk's Avatar
Predatorpunk is Offline
Master Sergeant
Rep Power: 2
Reputation: 27
Predatorpunk is on a distinguished road
 
Posts: 78
Join Date: Oct 2007
Location: My Computer
02-25-2008

With my luck, I wouldnt get to be SYSTEM. my comp would log me in as EPIC - FAIL and i would die as my comp explodes and laughs in my face.



Reply With Quote
(#4)
Old
Haq's Avatar
Haq is Offline
Knight-Lieutenant
Rep Power: 2
Reputation: 18
Haq is on a distinguished road
 
Posts: 307
Join Date: Jul 2007
02-25-2008

SONOFA....

HOLY Hell! I can't believe this worked!

This HAS to be hot-fixed sometime soon...

Is there a keyboard shortcut for a cmd prompt?

EDIT: I can't rep this post, otherwise I would...but still, a HUGE Thank You for this!



Last edited by Haq; 02-25-2008 at 08:16 PM..
Reply With Quote
(#5)
Old
Dragon[Sky]'s Avatar
Dragon[Sky] is Offline
Anti-social Engineer
Legendary User
Rep Power: 7
Reputation: 824
Dragon[Sky] is a splendid one to beholdDragon[Sky] is a splendid one to beholdDragon[Sky] is a splendid one to beholdDragon[Sky] is a splendid one to beholdDragon[Sky] is a splendid one to beholdDragon[Sky] is a splendid one to beholdDragon[Sky] is a splendid one to behold
 
Posts: 1,409
Join Date: Apr 2007
Location: Psychedelic Skies
02-25-2008

Quote:
Originally Posted by Haq View Post
SONOFA....

HOLY Hell! I can't believe this worked!

This HAS to be hot-fixed sometime soon...

Is there a keyboard shortcut for a cmd prompt?

EDIT: I can't rep this post, otherwise I would...but still, a HUGE Thank You for this!
Windows button + R for Run, cmd.
In case Run is disabled.



Reply With Quote
(#6)
Old
Dragonshadow's Avatar
Dragonshadow is Offline
KuRIoS Wannabe
Legendary User
Rep Power: 7
Reputation: 886
Dragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to behold
 
Posts: 1,944
Join Date: Apr 2007
Location: In the shadows...
02-25-2008

Quote:
Originally Posted by Haq View Post
SONOFA....

HOLY Hell! I can't believe this worked!

This HAS to be hot-fixed sometime soon...

Is there a keyboard shortcut for a cmd prompt?

EDIT: I can't rep this post, otherwise I would...but still, a HUGE Thank You for this!
Can't rep? :< why not :O

j/k tis ok lol


Reply With Quote
(#7)
Old
Dark Soul's Avatar
Dark Soul is Offline
Contributor
Rep Power: 1
Reputation: 117
Dark Soul will become famous soon enoughDark Soul will become famous soon enough
 
Posts: 766
Join Date: Dec 2007
Location: AscentOS Dev PC
02-26-2008

There is a video about this:
[Only registered and activated users can see links. ]



PHP Coder, Contact me via PMs if you need a Script made
Reply With Quote
(#8)
Old
tomch's Avatar
tomch is Offline
Master Sergeant
Rep Power: 2
Reputation: 5
tomch is an unknown quantity at this point
 
Posts: 82
Join Date: May 2007
Location: MA
02-27-2008

wow thats pretty sick
Reply With Quote
(#9)
Old
Dragonshadow's Avatar
Dragonshadow is Offline
KuRIoS Wannabe
Legendary User
Rep Power: 7
Reputation: 886
Dragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to behold
 
Posts: 1,944
Join Date: Apr 2007
Location: In the shadows...
02-28-2008

Thanks ^^

filler


Reply With Quote
(#10)
Old
bigow's Avatar
bigow is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 1
Reputation: 1
bigow is an unknown quantity at this point
 
Posts: 9
Join Date: Mar 2008
03-11-2008

Awesome, this will really come in handy
Reply With Quote
(#11)
Old
Dragonshadow's Avatar
Dragonshadow is Offline
KuRIoS Wannabe
Legendary User
Rep Power: 7
Reputation: 886
Dragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to beholdDragonshadow is a splendid one to behold
 
Posts: 1,944
Join Date: Apr 2007
Location: In the shadows...
03-13-2008

Thanks for the free bump,

Now its my turn


Reply With Quote
(#12)
Old
Obex's Avatar
Obex is Offline
Knight-Champion
Rep Power: 2
Reputation: 37
Obex is on a distinguished road
 
Posts: 515
Join Date: Feb 2007
Location: A damn good question
03-13-2008

My school disabled run Cmd task manager source coad and right click

ftl


Science has not yet taught us if madness is or is not the sublimity of the intelligence.
Reply With Quote
(#13)
Old
bigow's Avatar
bigow is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 1
Reputation: 1
bigow is an unknown quantity at this point
 
Posts: 9
Join Date: Mar 2008
03-14-2008

Quote:
Originally Posted by Obex View Post
My school disabled run Cmd task manager source coad and right click

ftl
Can you create shortcuts? If so make a shortcut, when it says type the path of the location type cmd and then call it whatever you want. This will create a shortcut that will open the cmd prompt as well.

It's what I used to use at work when wanted to much around with work computers.

If you can't right click you can usually create shortcuts from the file drop down menu.

Oh and you can also open a document, notepad etc type cmd.exe and then save as *.bat where * is anything then double click on it

Last edited by bigow; 03-14-2008 at 02:20 PM..
Reply With Quote
(#14)
Old
Obex's Avatar
Obex is Offline
Knight-Champion
Rep Power: 2
Reputation: 37
Obex is on a distinguished road
 
Posts: 515
Join Date: Feb 2007
Location: A damn good question
03-14-2008

Quote:
Originally Posted by bigow View Post
Can you create shortcuts? If so make a shortcut, when it says type the path of the location type cmd and then call it whatever you want. This will create a shortcut that will open the cmd prompt as well.

It's what I used to use at work when wanted to much around with work computers.

If you can't right click you can usually create shortcuts from the file drop down menu.

Oh and you can also open a document, notepad etc type cmd.exe and then save as *.bat where * is anything then double click on it
i have done this it tells me CMD is disabled on the networks we cant make shortcuts CMD pops up but it just says "CMD has been disabled on these computers"


Science has not yet taught us if madness is or is not the sublimity of the intelligence.
Reply With Quote
(#15)
Old
bigow's Avatar
bigow is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 1
Reputation: 1
bigow is an unknown quantity at this point
 
Posts: 9
Join Date: Mar 2008
03-14-2008

Hmm, looks like you fresh out of luck then your IT department is a lot cleverer than mine
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321