# Forgot Windows login password!

**URL:** <https://boards.straightdope.com/t/forgot-windows-login-password/216797>\
**Category:** Factual Questions\
**Created:** [December 3, 2003, 9:59pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797 "2003-12-03T21:59:55Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kansas\_Man](https://avatars.discourse-cdn.com/v4/letter/k/eada6e/32.png) [@Kansas\_Man](https://boards.straightdope.com/u/Kansas_Man)\
**Post date:** [December 3, 2003, 9:59pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/1 "2003-12-03T21:59:55Z")

</div>

My friend forgot his Windows 2000 login password. This is the password that they ask for when you turn on the PC and before Windows starts.

Is there any way to reset this password? He has his original CD.

Thanks.

---

<div class="post-metadata">

**Author:** ![infra\_dig](https://avatars.discourse-cdn.com/v4/letter/i/858c86/32.png) [@infra\_dig](https://boards.straightdope.com/u/infra_dig)\
**Post date:** [December 3, 2003, 10:06pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/2 "2003-12-03T22:06:00Z")

</div>

I may be running an older system, but if your boot allows you to enter in Dos mode you can delete the .pwd files and start over.

---

<div class="post-metadata">

**Author:** ![infra\_dig](https://avatars.discourse-cdn.com/v4/letter/i/858c86/32.png) [@infra\_dig](https://boards.straightdope.com/u/infra_dig)\
**Post date:** [December 3, 2003, 10:17pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/3 "2003-12-03T22:17:49Z")

</div>

Here’s the Microsoft Advanced Search page [http://support.microsoft.com/default.aspx?scid=fh;EN-US;kbhowto&sd=GN&ln=EN-US&FR=0](http://support.microsoft.com/default.aspx?scid=fh;EN-US;kbhowto&sd=GN&ln=EN-US&FR=0)

---

<div class="post-metadata">

**Author:** ![infra\_dig](https://avatars.discourse-cdn.com/v4/letter/i/858c86/32.png) [@infra\_dig](https://boards.straightdope.com/u/infra_dig)\
**Post date:** [December 3, 2003, 10:21pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/4 "2003-12-03T22:21:35Z")

</div>

And specifically [http://support.microsoft.com/default.aspx?scid=kb;en-us;258289](http://support.microsoft.com/default.aspx?scid=kb;en-us;258289)

---

<div class="post-metadata">

**Author:** ![Madness2MyMethod](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Madness2MyMethod](https://boards.straightdope.com/u/Madness2MyMethod)\
**Post date:** [December 3, 2003, 10:41pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/5 "2003-12-03T22:41:23Z")

</div>

Are we talking about a boot-up password, or an actual Windows login password? You say before Windows starts, do you mean before Windows begins loading or once it has loaded? If it’s a boot-up password (before Windows begins loading, in other words as soon as you power up the PC), you are in luck because the password is stored in CMOS, and most motherboards allow you to reset the CMOS settings by shorting two points on the motherboard, or by taking the CMOS battery out and leaving it out for about 8 hours.

But if it’s a Windows login password…well that’s a bit tougher because Windows 2000, a network operating system, was built with security in mind. In other words, don’t forget your password. BUT, since your friend is obviously not very computer literate, I assume he did not know to disable the default system Administrator account, and unremovable Administrator account. So try logging on as just “Administrator” then from there you can modify all other accounts.

---

<div class="post-metadata">

**Author:** ![Kansas\_Man](https://avatars.discourse-cdn.com/v4/letter/k/eada6e/32.png) [@Kansas\_Man](https://boards.straightdope.com/u/Kansas_Man)\
**Post date:** [December 4, 2003, 2:20pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/6 "2003-12-04T14:20:49Z")

</div>

Thanks for the replies. I will pass along the info and let you know how it goes.

---

<div class="post-metadata">

**Author:** ![tourbot](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@tourbot](https://boards.straightdope.com/u/tourbot)\
**Post date:** [December 4, 2003, 3:06pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/7 "2003-12-04T15:06:09Z")

</div>

There are several utilities out there for resetting a Win2k or XP password. [This site](http://www.petri.co.il/forgot_administrator_password.htm) lists several of the better ones.

---

<div class="post-metadata">

**Author:** ![5cents](https://avatars.discourse-cdn.com/v4/letter/5/46a35a/32.png) [@5cents](https://boards.straightdope.com/u/5cents)\
**Post date:** [December 4, 2003, 5:31pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/8 "2003-12-04T17:31:43Z")

</div>

> [@](#):
>
> \*Originally posted by Madness2MyMethod \*  
> **But if it’s a Windows login password…well that’s a bit tougher because Windows 2000, a network operating system, was built with security in mind.**

Tee Hee Hee. Ha Ha Ha Ha Ha Ha! Oh my, I haven’t had such a good laugh in a while.

Windows 2000 has more security features than Windows 95/98/Me, which isn’t saying much since those versions had no security. However, Windows 2000 security is still pretty weak, unless you are very careful.

Just one silly example:

The login screen saver (you know, the one that comes up if you aren’t logged on, and you let the computer sit idle for 5 or 10 minutes) runs with full privileges (actually higher than admin). The screen saver is just a program residing on the hard drive, and if your PC is setup with a FAT filesystem (very common, since it is easier to recover if something goes wrong), that file is completely unprotected. Change that file to, say, cmd.exe, reboot, go for a coffee, and when you return, voila! instant higher-than-admin-privilege shell.

---

<div class="post-metadata">

**Author:** ![autobulb](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@autobulb](https://boards.straightdope.com/u/autobulb)\
**Post date:** [December 5, 2003, 1:42am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/9 "2003-12-05T01:42:30Z")

</div>

Haha, god bless microsoft.

---

<div class="post-metadata">

**Author:** ![Madness2MyMethod](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@Madness2MyMethod](https://boards.straightdope.com/u/Madness2MyMethod)\
**Post date:** [December 5, 2003, 4:09pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/10 "2003-12-05T16:09:48Z")

</div>

> [@](#):
>
> \*Originally posted by 5cents \*  
> \*\*Tee Hee Hee. Ha Ha Ha Ha Ha Ha! Oh my, I haven’t had such a good laugh in a while.
> 
> Windows 2000 has more security features than Windows 95/98/Me, which isn’t saying much since those versions had no security. However, Windows 2000 security is still pretty weak, unless you are very careful.
> 
> Just one silly example:
> 
> The login screen saver (you know, the one that comes up if you aren’t logged on, and you let the computer sit idle for 5 or 10 minutes) runs with full privileges (actually higher than admin). The screen saver is just a program residing on the hard drive, and if your PC is setup with a FAT filesystem (very common, since it is easier to recover if something goes wrong), that file is completely unprotected. Change that file to, say, cmd.exe, reboot, go for a coffee, and when you return, voila! instant higher-than-admin-privilege shell. \*\*

Oh please. Set aside your nerdish tendencies for one minute and realize this guy needed help, and I provided it. I know you relish the opportunity to flame microsoft, but please, do it in another post. I didn’t say windows was the end all be all of OS security. Everybody knows it has security loopholes, hence the need for service packs. I simply said it was built with SECURITY IN MIND, meaning it was one of their goals. Everybody knows there is no such thing as “total security”, only degrees of security. But since we’re on the subject, windows 2000 is a network OS, and any sensible network admin is going to require its hosts to use the NTFS file system, not FAT, like some home users might use. Of course the more security you want, the more careful you have to be. Duh. That is the case with a lot of things. Or were you just trying to show off?

> [@](#):
>
> Tee Hee Hee. Ha Ha Ha Ha Ha Ha!

I think this speaks for itself.

---

<div class="post-metadata">

**Author:** ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)\
**Post date:** [December 5, 2003, 4:49pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/11 "2003-12-05T16:49:45Z")

</div>

> [@](#):
>
> \*Originally posted by infra dig \*  
> \*\*I may be running an older system, but if your boot allows you to enter in Dos mode you can delete the .pwd files and start over. \*\*

All of the win9.x operating systems (95, 98, ME) boot DOS first then use DOS to load Windows. All NT operating systems (NT 4, 2000, XP) use the NT loader. You can’t boot DOS mode on NT.

If your drive is FAT32 then you can boot from a win98 DOS floppy.

There are ways into NTFS systems but they are a bit trickier.

---

<div class="post-metadata">

**Author:** ![5cents](https://avatars.discourse-cdn.com/v4/letter/5/46a35a/32.png) [@5cents](https://boards.straightdope.com/u/5cents)\
**Post date:** [December 6, 2003, 5:44am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/12 "2003-12-06T05:44:40Z")

</div>

> [@](#):
>
> \*Originally posted by Madness2MyMethod \*  
> **Oh please. Set aside your nerdish tendencies for one minute and realize this guy needed help, and I provided it. I know you relish the opportunity to flame microsoft**

Nay, I was flaming you, for implying that Windows 2000 was very secure - to wit “In other words, don’t forget your password”.

---

<div class="post-metadata">

**Author:** ![5cents](https://avatars.discourse-cdn.com/v4/letter/5/46a35a/32.png) [@5cents](https://boards.straightdope.com/u/5cents)\
**Post date:** [December 6, 2003, 6:01am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/13 "2003-12-06T06:01:42Z")

</div>

Sorry to break this into two posts … clicked submit instead of preview.

> [@](#):
>
> \*Originally posted by Madness2MyMethod \*  
> **But since we’re on the subject, windows 2000 is a network OS, and any sensible network admin is going to require its hosts to use the NTFS file system, not FAT, like some home users might use.**

NT/2K (but not generally XP) are often setup with a small-ish FAT partition for booting (including all OS files), and a large NTFS partition for everything else. The reason for this is ease of recovery. I have seen this at places that should know better - software companies, hospitals, universities, banks, you name it. I’m not talking about small rural hospitals or 1-branch banks, either.

---

<div class="post-metadata">

**Author:** ![Boo\_Boo\_Foo](https://avatars.discourse-cdn.com/v4/letter/b/e274bd/32.png) [@Boo\_Boo\_Foo](https://boards.straightdope.com/u/Boo_Boo_Foo)\
**Post date:** [December 6, 2003, 6:13am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/14 "2003-12-06T06:13:36Z")

</div>

Here is a very interesting and entertaining thread I started on this very subject back in February…

[http://boards.straightdope.com/sdmb/showthread.php?s=&threadid=165709](http://boards.straightdope.com/sdmb/showthread.php?s=&threadid=165709)

Essentially I was involved in power wars between a father and son over login usage on a Windows XP machine.

Here is a quote from the thread which is pertinent to the question in the OP…

> [@](#):
>
> \*\*However, for those of you who are interested, tonight I performed a test on one of my Windows 2000 “Advanced Server” machines which act as a redundant on line database server.
> 
> These are the steps I performed to “crack” the Password system. It was so dead easy it’s bloody frightening…
> 
> (1) I shutdown the computer…
> 
> (2) I placed a 1995 MS-DOS Boot Disk in the A: drive.
> 
> (3) The system booted under DOS and I logged onto C: drive at a DOS prompt level.
> 
> (4) cd C:\WINNT\System32\Config
> 
> (5) I renamed “sam” to “sam.bak” _(Note: the file is simply titled “sam” with no extension. It’s not “sam.dll” or something like that. It’s purely just plain out “sam”.)_
> 
> (6) I removed the DOS boot disk and rebooted the machine. Windows 2000 Advanced Server reloaded.
> 
> (7) The system offered my normal “username” as my log in option. It no longer worked. None of my “user defined” logins worked either. I then attempted to log in as “Administrator” WITHOUT a password and I got in easy as pie.
> 
> (8) I had full “administration” rights and I could do whatever I wanted - including rebuilding a user login database if I so wanted.
> 
> (9) I chose not to change a thing… but I noticed that the OS had created a NEW “sam” file (a default “sam” file it would appear) and I could NOT rename or copy sam.bak over the new “sam” file - I assume this is because it’s a mission critical file to WIN2K and XP, so I merely performed the DOS boot once again and did the file rename at a DOS prompt level.
> 
> (10) Upon rebooting the machine once more, all of my previous user logins were working and visible once again in the “User Accounts” software interfaces.
> 
> So there ya go… pretty bloody big hole don’tchya think?
> 
> Also, it’s worth noting, the machines I use are really well made IBM Netvista’s and Netfinity’s. Believe it or not, and I’ve checked this guys, the proprietary IBM BIOS doesn’t even allow you to disable the A: drive as a bootable device. Possibly this is achieved at the motherboard jumper switch level - but certainly not at bootup BIOS time.\*\*

Hope that helps…

---

<div class="post-metadata">

**Author:** ![The\_MacDairmuid](https://avatars.discourse-cdn.com/v4/letter/t/a87d85/32.png) [@The\_MacDairmuid](https://boards.straightdope.com/u/The_MacDairmuid)\
**Post date:** [December 6, 2003, 6:48am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/15 "2003-12-06T06:48:54Z")

</div>

**KansasMan** , [this utility](http://home.eunet.no/~pnordahl/ntpasswd/cd030426.zip) works very well. It is called the _Offline NT Password & Registry Editor_. It is a bootable CD image which when booted allows you to reset most NT passwords (It WON’T reset your Active Directory Admin password). It’s listed on the page **Tourbot** recommended.

I’ve used this one many times, it works beautifully. If you haven’t already recovered the password, download this utility and be done with it.

---

<div class="post-metadata">

**Author:** ![autobulb](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@autobulb](https://boards.straightdope.com/u/autobulb)\
**Post date:** [December 6, 2003, 6:52am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/16 "2003-12-06T06:52:12Z")

</div>

Hmm… how would he access NTFS partitions with a DOS bootdisk? I haven’t tried with that specific boot disk but when I needed to examine my drives in a DOS environment it could not access my drives at all. Of course, there are special loaders that can be made with a floppy or CD (I used one to upgrade my DVD drive’s firmware) and my drives WERE accessible so I’m assuming the flaw is just as bad, you just need a specific loader.

Also, is the SAM file used the same way for XP? I want to try this out myself…

---

<div class="post-metadata">

**Author:** ![Armilla](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@Armilla](https://boards.straightdope.com/u/Armilla)\
**Post date:** [December 6, 2003, 11:34am UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/17 "2003-12-06T11:34:43Z")

</div>

The “vulnerability” posted by **5cents** isn’t actually a specific Windows vulnerability, it’s part of the same class of vulnerability as the one **Boo Boo Foo** posted - something that _all_ computers irrespective of operating system can fall prey to.

Contrary to the popular myth perpetrated by people like **5cents** the Linux kernel actually does _not_ have the ability to automatically incarnate as an armoured robot with a power sword in order to defend its hardware from hackers. Unbelievable, but true.

To access NTFS partitions from a DOS boot there’s the [NTFSDOS](http://www.sysinternals.com/ntw2k/freeware/ntfsdos.shtml) utility from SysInternals (and there’s plenty of other useful stuff there too). DOS does not normally have the ability to read an NTFS partition, so it needs a little extra help like this.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 6, 2003, 3:58pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/18 "2003-12-06T15:58:50Z")

</div>

Any OS cannot protect itself when the machine is booted from another OS. That irrefutable fact is central to any discussion.

Sure it could possibly encrypt stuff to make it tougher for the alternate OS to break in, but that’s only changing the size of the challenge, not its fundamental do-ability.

A Linux OS can be cracked by another copy of Linux or a Windows and vice versa. Once it’s not in control, the installed OS is just a large inert lump of data to be massaged (or raped) as you desire.

The fault in using a small DOS partition on an otherwise-NTFS machine is that it places critical system files within easy reach of another easy-to-use and widely available OS – DOS.

Installing NT that way might have been sound advice when it was brand new and not many offline NTFS tools were available and most workstations were still Win98. But in today’s world it’s bordering on negligent to set up a commercial box that way.

---

<div class="post-metadata">

**Author:** ![5cents](https://avatars.discourse-cdn.com/v4/letter/5/46a35a/32.png) [@5cents](https://boards.straightdope.com/u/5cents)\
**Post date:** [December 6, 2003, 6:56pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/19 "2003-12-06T18:56:55Z")

</div>

> [@](#):
>
> \*Originally posted by Armilla \*  
> **The “vulnerability” posted by 5cents isn’t actually a specific Windows vulnerability**

It isn’t? So do other operating systems run screensavers at administrative permission? Which ones?

> [@](#):
>
> Contrary to the popular myth perpetrated by people like **5cents** the Linux kernel actually does _not_ have the ability to automatically incarnate as an armoured robot with a power sword in order to defend its hardware from hackers.

Can you please show me where I mentioned linux? I can’t see it.

> [@](#):
>
> To access NTFS partitions from a DOS boot

Can you please show me where I mentioned DOS boot? I can’t see it, either.

The exploit I showed requires that the boot partition be FAT, and that you have some access to the machine (left logged in unattended, or guest, or whatever). That’s all. It doesn’t require anything else. You only need to bring yourself.

---

<div class="post-metadata">

**Author:** ![5cents](https://avatars.discourse-cdn.com/v4/letter/5/46a35a/32.png) [@5cents](https://boards.straightdope.com/u/5cents)\
**Post date:** [December 6, 2003, 6:58pm UTC](https://boards.straightdope.com/t/forgot-windows-login-password/216797/20 "2003-12-06T18:58:06Z")

</div>

> [@](#):
>
> \*Originally posted by LSLGuy \*  
> **Any OS cannot protect itself when the machine is booted from another OS.**

Read my message again. I just reboot NT/2K. No other OS involved.

[Next page](https://boards.straightdope.com/t/forgot-windows-login-password/216797.md?page=2)
