you are viewing a single comment's thread
view the rest of the comments
[–] 58 points 2 years ago* (9 children)

Fun fact: A common way to get access to SYSTEM (higher than admin) privileges on Windows is the sethc exploit, where you replace sethc (the program that shows the sticky keys dialog) with command prompt, and it gets started as SYSTEM, the only thing needed is write access to System32, which can either be from an admin account or by editing the file system externally. This also allows opening a command prompt on the login screen, allowing some cursed things, like if you start explorer.exe on the login screen it combines the desktop and login screen.

  • source
  • hideshow 9 child comments
  • [–] 12 points 2 years ago (5 children)

    I did this in college with windows 7. I don't think it works on 10, but could be mistaken.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 15 points 2 years ago

    I helped an elderly man get back into his pc doing a variation of this.

    Changed the accessibility magnifier function to comman prompt. Was able to log in and create another user account after he lost access to a password.

    So not sure about that one specifically bit a variation worked on 10.

  • source
  • parent