Unshackle: A tool to bypass Windows and Linux password logins
github.com
github.com
* Press F11 while booting
* open cmd in the rescue menu
* navigate to windows system32 folder
* rename sethc.exe to sethc.exe.backup
* copy cmd.exe to sethc.exe
* reboot and press at login 5 times shift
* add admin user
* profit
Thing that is missing is password edit of online only accounts or convert to local accountI'd heard about teens jailbreaking Chromebooks and the like recently, so it's nice to see the spirit of rebellion is still alive and well in the new generation :)
I'll just unplug your mouse / keyboard / wifi dongle and get to the USB port that it's using. Unless you are suggesting that modern computers should ship with zero USB ports.
/s (not so much)
> I'll just unplug your mouse / keyboard / wifi dongle and get to the USB port that it's using. Unless you are suggesting that modern computers should ship with zero USB ports.
PS/2 is still available for mouse/keyboard (and secure). Wifi dongles are abomination. Worst case, hotglue those into the port.
I don't see any reason to stop at my USB ports. Take a hot glue gun with you where ever you go, and glue them all shut as soon as you find them. Help make the world a better place.
Besides manipulating executables, the adversary could simply modify or read the user database in C:\Windows\System32\config\SAM. [1]
Alternatively, patch routines directly in memory [2]
Linux can be setup to verify an immutable userland via secure boot + dm-verity. I think it's used in some google devices (chromebooks?).
First set of changes already in flight for the next Windows 11 stable release.
ps. I stand corrected - probably something similar still works: https://4sysops.com/archives/reset-a-windows-11-password-and...
IF you're booting I used to use vim to just edit the shadow file. Or simply passwd to set the password to something.
How does it cope with encrypted drives?
Booting from USB with grub4dos, patching the .dll then continuing booting and you could login as the original user but without (or with "any") password:
http://reboot.pro/index.php?showtopic=18588
There are (were) derivatives to be run from a WinPE, but any hex editor that could access the .dll would have done.
Let's say that it was a poor man's Konboot, that has (or at least used to have) a similar approach, but patching files in memory.
What is (was) elegant in the grub4dos PassPass is (was) that you booted to grub4dos, ran the batch and then continue booting to the "normal" OS.
An attacker might get 10 good tries before continuing becomes pointless, so unless the PIN is one of 1234 4321 0000 1111 2222 you're probably safe.
Note: TPM2.0 allows alphanumerical PINs but I think you need a group policy for Windows to allow it.
[1]: https://support.microsoft.com/en-us/windows/turn-on-device-e...
Of course, that won't work on a LUKS encrypted system.
Has it stopped working?
idk why this made the frontpage other than beeing interesting
If you have access to the bootloader's kernel command line, you don't need the USB stick, either.
What this doesn't do is get you access to an encrypted filesystem, unless the encryption password happens to be written somewhere in the unencrypted partition. That happens unsurprisingly often.
>Tested on : >Windows 10 pro x64
>Linux bypass is still under development.
It also states under Usage: Choose your OS (Windows or Linux).
You can't say until using it which aspect of Linux support is under development.
Its not big project, you can pretty quickly browse through the code and see that there is zero linux support