Computer Performance, Microsoft Windows Vista

Guy recommends :
Free Solarwinds
VM Console

Solarwinds VM Console Free Download

Find out which of your VMs are a waste of space and which VMs need more resources.



 

Windows Vista - Backdoor Logon

Windows Vista - Backdoor LogonWindows Vista Backdoor logon

You would not expect it to be easy to create a backdoor logon.  Indeed, the technique described on this page does not threaten Vista security, unless someone has a Trojan horse program to prepare the way.  Whatever you make of this technique, you have to smile at Microsoft's unintended meaning of 'Ease of access'.

How the Vista Backdoor Logon Works

This back door method exploits the 'Ease of Access' menu at the bottom of a regular Windows Vista Logon.  Normally, if you click the Icon then you get a choice of help from Narrator, Magnifier and High Contrast.  The trick is to replace the file called Magnify.exe, with a file which is really cmd.exe.  See a similar Windows 8 Backdoor login using Utilman.

Once you make the change, then when you select Magnifier from the Ease of Access dialog box, you enter the operating system at the command prompt.  The result is you can logon as the System account, without the need of a password.  One limitation is that your shell program is cmd.exe rather than explorer.  A more serious limitation is that in order to enter via this backdoor, you would need to install a Trojan horse program.  Another possibility is that you have logged on previously, and manually made the changes described below.

Rename Magnify backdoor logon

 ♦

Mission to Create an Impostor instead of Magnify.exe

The idea is to change the programme names so that the hyperlink link called 'Make items on the screen larger (Magnify)', actually points to cmd.exe.  The result is that you open a back door logon to Vista.

Preliminary Step - Deal with Permissions

Problem: You cannot rename or delete the original Magnify.exe in Windows \system32.  Even though you are an administrator, even though UAC is enabled, all you get is this message:

'You need permission to perform this action'

Solution: Take ownership of the file Magnify.exe, then change the permission for the Administrator's group to Full control.  Then rename Maginify.exe to MagnifyOld.exe.

Vista Take Ownership Windows\system32

Main Step - Create the Impostor Magnify.exe

  1. Create a new folder called Ease
  2. Copy CMD.exe ---> \Ease \cmd.exe
  3. Rename \Ease \cmd.exe ---> Magnify.exe
  4. Copy \Ease \Magnify.exe ---> Windows \system32\Magnify.exe

What you have achieved is that the old, relatively harmless, 'Magnify' becomes the more versatile cmd.exe.

Test Your 'Ease of access' Backdoor MethodVista Backdoor logon - Ease of access

  1. At the Vista Logon screen, click on Ease of access
  2. Check the box next to: Make Items on the screen Larger (Magnifier)
  3. Click 'OK'
  4. You should now find yourself at the Command Prompt
  5. Try whoami  (System account)
  6. Try regedit
  7. Feel the power!

Guy Recommends: A Free Wake-On-LAN UtilitySolarwinds Wake-On-LAN

Encouraging computers to sleep when not in use is a great idea - until you are away from your desk and need a file on that remote sleeping machine!

Wake-On-LAN really will save you that long walk to awaken a hibernating machine; however my reason for encouraging you to download this utility is just because it's so much fun sending those 'Magic Packets'.  As Wake-On-LAN (WOL) is free, see if I am right, and you get a kick from arousing those sleeping machines.  WOL also has business uses for example, wakening machines so that they can have their patches applied. 

Download your free copy of Wake-On-LAN

Modifications to the 'Ease of Access' backdoor

You could apply the same back door technique that I suggested for Magnify.exe to Narrator.exe.  Another modification is to substitute other programs for cmd.exe.  I tried explorer.exe, but that did not work for me.  However, a reader wrote in suggesting this neat technique:

After you replace magnify.exe with a copy of cmd.exe, you can get an explorer window. In the DOS windows type "explorer"
This will give you a start menu at the bottom edge of the screen. Now alt-tab to the "Desktop" and you'll see system user's desktop.

Winlogon will go full screen each time it gets focus, but alt-tabbing to "Desktop" will get you back to explorer's desktop.  If your active program loses focus and the login screen takes over, just alt-tab back to your previous app.

Summary of Vista Backdoor Logon

The idea behind this Vista backdoor logon is to re-program the Magnify or Narrator.  As a result, if you call for 'Ease of access', then you can logon by pressing Narrator or Magnifier.  With this technique, you logon as the System account without the need to supply a password.  One limitation, that I have yet to overcome, is that you have a command prompt shell rather than an Windows Explorer GUI.

If you like this page then please share it with your friends

 


Windows Vista Security:

Other Sections

 *


Custom Search

Guy Recommends: SolarWinds Free IP SLA MonitorSolarwinds IP Sla Monitor

SolarWinds IP SLA Monitor offers so much more than just uncovering network bottlenecks, the real joy is learning about router traffic.

To find out what's happening on the network between your computers and their routers, download your free copy of the of IP SLA Monitor.

Home Copyright © 1999-2012 Computer Performance LTD All rights reserved

Please report a broken link, or an error.