• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Stupidest Thing Ever

Ryetoast

n00b
Joined
May 2, 2006
Messages
29
I just found out about the stupidest thing in windows. How to change user password Basically if you leave your computer unlocked anyone can change your password.

They don't even need to know your old one to change it. And with this link someone can change your admin password to what ever they want, with out even needing to know your original password. I am baffled that someone can do this so easily, and my question is can you do this in windows vista? If you can that would be very stupid and makes me second guess about vistas security. I've never heard about this until now and its just retarded.
 
Physical access to a PC is just as much a security issue as remote/network-based attacks. If you believe there's any foul play to be had *at* your computer, don't leave it logged in when you're away. Simple.
 
you can also use a boot cd or boot disk with a password changing utility on it..
my mom's friend had a computer and one of her grandkids put a password on the admin account and "forgot" it.. so i sent my mom a program to put on a disk, and she was able to figure it out...
 
Reminds me of how you could click "Cancel" on the password prompts for 98 and such. Not quite as bad though - remember kids, always lock your boxen when you walk away! ;)
 
... Basically if you leave your computer unlocked anyone can change your password.

See that emboldened word there? That's where your argument falls down. Not 'anyone' can do it. Only those people who have obtained and understood the technical procedures necessary can do it!

Simple fact is that the majority of people don't ever go looking for such instructions, and of those who do not everyone follows them adequately to be able to carry out the procedures. Only the more competent and dedicated people wanting to perform such and act will be able to obtain and use the available help.

Simple next fact? Capability to circumvent passwaords has to be available, for the benefit of systems administrators mainly! Plenty of users out there who put passwords in place and then forget them. systems admins shouldn't have to reload the system from scratch when that happens!

Simple third fact? If the stuff on your PC is sensitive enough to warrant serious protection then you shouldn't be relying upon passwords alone as your means of protection. Passwords are only protection against casual intrusions, not against the predations of people who are etermined to get access to your system no matter what it takes!
 
If you leave your house unlocked when you go away on vacation, anyone can break in and rob you.

*sighs* Another "Hey, look how cool I am, I hate Microsoft. Where's my cookie?" thread. :rolleyes:
 
Simple fact is that the majority of people don't ever go looking for such instructions, and of those who do not everyone follows them adequately to be able to carry out the procedures

Yep. At your home, who on earth cares?
At your business, the only people that would know about this (generally) is going to be the IT staff. And the IT staff have no reason to be getting into your stuff. The IT staff already have Administrative access and can care less about this.

The first you linked to, you omitted a detail:
To change a user's password at the command prompt, log on as an administrator and type:

Now, unless the Administrator account doesn't have a password set, and can be booted to Safe Mode, this isn't an option. Home users generally don't care about this, and Business users' IT Departments generally have the Administrator account password protected to start with.

The second you linked to relies on the same stuff I just mentioned. You have to have access to begin with, know an established user's account and password, etc.

But like Catweazle said, this isn't a "flaw". It is put there so IT folks can help people get their passwords back after they forget them.
 
If you leave your house unlocked when you go away on vacation, anyone can break in and rob you.

*sighs* Another "Hey, look how cool I am, I hate Microsoft. Where's my cookie?" thread. :rolleyes:


But isnt that how it is nowadays with the youngsters?

They werent probably even born yet when we were using Win 3.11
 
But like Catweazle said, this isn't a "flaw". It is put there so IT folks can help people get their passwords back after they forget them.
Oh c'mon. Users never forget their passwords. That just doesn't happen.
They werent probably even born yet when we were using Win 3.11
I still fondly remember the Program Manager, and how great it was to upgrade to IE 3.02...completely with animated icons. Woot!
 
Basically if you leave your computer unlocked anyone can change your password.
If I leave my computer unlocked and walk away, changing my password would be the least of my worries. They have full access to your machine at that time.

What is more interesting is this:
Non-administrators receive a "System error 5 has occurred. Access is denied" error message when they attempt to change the password.
If you are not an admin, there is much less damage to be done :)
 
I have a bootable CD that can reset anyones password witout even know their password. I can change anyones password and reset it even Administrator. its quite useful
 
What is more interesting is this:
Non-administrators receive a "System error 5 has occurred. Access is denied" error message when they attempt to change the password.
I know. Funny how people take articles out of context in order to knock on Microsoft all the time.

I have a bootable CD that can reset anyones password witout even know their password. I can change anyones password and reset it even Administrator. its quite useful

Good for you! Do you want a sticker on your resume or something? :D
 
Ok, I understand what all of you guys are getting at. I do lock my computer here at college as much as possible, and luckily the one who changed my password was a friend of mine so it doesn't really matter.

I don't hate windows, I have been using it my whole life since the 3.1 days. I remember on one of my first computers I actually deleted the Program Manager and the computer would never boot into windows again. Also getting an error about needing a Video Accelerator to play some star wars game, and being a kid at the time I had no idea what it was talking about.

Thinking about it know this was kind of stupid to post about, but I was a little pissed off that someone could change your password that easily. Living at a college where many of the students will know how to do this or can find out with a simple google search, I 'm just going to have to really remember to lock my computer whenever I leave my room.
 
Back
Top