Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 16, 2000 12:00 AM

How to Recover Lost Administrator Passwords

Windows IT Pro
InstantDoc ID #9528
Rating: (2)

Now and then many of you find yourselves in the unfavorable position of having to retrieve an NT system's lost Administrator account password. I can't even count the number of "help me!" messages I've received in this regard.

As I tell those of you who email me for help in this situation, there a couple of different approaches you can take, depending on your exact position. In any event you have two basic choices when recovering an Administrator password: you must either crack it or forcefully reset it to something known. It seems obvious to me that resetting the password will take much less time that brute force cracking, so it's a more cost affective way to handle the situation.

If you do want to brute force the password to see what it was set to, then you must obtain a copy of the system's SAM database and use a tool such as L0phtcrack to brute force crack the password. To get a copy of the SAM database, use NTFSDOS or a Linux boot disk with NTFS drivers on it. Either of those tool will allow you to boot a system from floppy and then read the installed NTFS partitions. You can find NTFSDOS at Winternals (http://www.winternals.com,) while Linux boot disks are available at various sites such as Ken Pfiel's NT Toolbox Web site (http://www.nttoolbox.com).

But if you've got access to the SAM database, then why not just reset the Administrator password to something known and be done with it? In that scenario, you can use NT Locksmith, also available at the Winternals Web site. Of course Locksmith costs money, so if you must have a cost-free way out of password recovery, then use a Linux boot disk that comes with a tool that can perform that action.

The Linux boot disk available for download at The NT Toolbox comes with the ability to reset an NT system's Administrator password, and its completely free of charge. Of course you get what you pay for, so don't expect a ton of documentation and an experience professional waiting for you to call for help. When it comes to support you'll have to wing it. But don't worry, using the boot disk to reset a password is much easier and quicker than re-installing NT, so it's worth any problems you may encounter.

I think every security administrator should have a copy of a Linux boot disk like the one at NT Toolbox. Be sure to download a copy, and don't forget to have a floppy disk available. Once you download the zip file, just unzip it and run the included executable file to create the actual floppy-based boot disk. While you're at The NT Toolbox be sure to check out the other great security-related tools available for download

Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    7 years ago
    May 12, 2005

    Forgot your username/password

  • Anonymous User
    7 years ago
    Mar 21, 2005

    BOO I'M A TURTLE!!!

  • Jin
    8 years ago
    Jun 15, 2004

    Your Comments (required): This is nothing but Great !!!

  • Mak
    9 years ago
    Dec 18, 2003

    Do Linux Boot disks word with Compaq RAID Arrays?

  • Ali
    9 years ago
    Dec 10, 2003

    I can replace (substitute)SAM file and so change password of administrator?
    is it true?

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.