Re: Big Problem w/ Admin accounts locked out

Tech-Archive recommends: Fix windows errors by optimizing your registry



Server 2003 DCs
are pretty secure even when you have physical access. Have you ever
successfully hacked a 2003 server box?

Legitimatly this is called "Domain Administrator Password Recovery". It is
intentionaly difficult to do but the process is known and works. Call
Microsoft PSS before you make this impossible and backup restoration becomes
your only option.
--
/kj
"Dan" <dan.zitting@xxxxxxxxx> wrote in message
news:1163870434.250817.5930@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Oh yea, thanks for that. I tried loginrecovery.com. They said the
password was too secure to recover. The other says it won't work on a
domain controller in the FAQ. I researched several other crack tools
but it actually appears (somewhat to my surprise) that Server 2003 DCs
are pretty secure even when you have physical access. Have you ever
successfully hacked a 2003 server box? Based on everything I'm reading
in the fine print, none of these tools are going to work.


On Nov 18, 9:05 am, "cjobes" <cjo...@xxxxxxxxxxxxx> wrote:
Before you do that, why don't you give it a try with one of the links I
gave
you.

--
Claus"Dan" <dan.zitt...@xxxxxxxxx> wrote in
messagenews:1163864857.067320.307950@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Thanks for all of the help, I can't tell you how much I appreciate it.
I did some serious research and tried booting into directory restore
mode and logging as Administrator but the original password again did
not take. So, I am getting the feeling I am hosed. I guess I will do
exactly that trying to call Microsoft but I'm afraid my fears of
spending my weekend reinstalling are coming true.

On Nov 17, 11:54 pm, "kj" <k...@xxxxxxxxxxx> wrote:
Yes it does, and I'm a little reluctant to post the process here. If
you
think you know what the DSRM password is, I would suggest placing a
call
to
Microsoft PSS using the bonehead boss's credit card.

--
/kj"Dan" <dan.zitt...@xxxxxxxxx> wrote in
messagenews:1163831416.315919.219320@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

I get a lockout eventually with my account and it resets later but
not
with the administrator account. It does not lockout. How does the
restore mode password thing work? Would it use the Admin password
from
when we originally setup the box?

On Nov 17, 11:08 pm, "kj" <k...@xxxxxxxxxxx> wrote:
If you know the active directory restore mode password you can
reset
the
domain administrator password.

Also, are you getting a lockout error on login or bad password?

--
/kj"Dan" <dan.zitt...@xxxxxxxxx> wrote in
messagenews:1163823645.286073.65580@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

I've tried them every different case combination I can think
of...
no
luck. I guess it is cracking for me. Is there any way this could
have
happened other than he just forgot the password? Would anything
cause
this kind of lockout?

Merv Porter [SBS-MVP] wrote:
Have you tried the new passwords in uppercase (in case he had
the
caps
lock
key on when he changed the passwords)?

Maybe some help here...

Forgot the Administrator's Password? - Reset Domain Admin
Password
in
Windows Server 2003 AD.
http://www.petri.co.il/reset_domain_admin_password_in_windows_server_...

--
Merv Porter [SBS-MVP]
============================

"Dan" <dan.zitt...@xxxxxxxxx> wrote in message
news:1163821209.991303.288260@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Unfortunately, I sure can't login with either the old or what
I'm
told
he's 100% sure are the new passwords. I can only log in at
this
point
using remote desktop with a power user (not admin) account.

Merv Porter [SBS-MVP] wrote:
Can you log into the server (directly at the console) using
either
the
new
or old credentials?

--
Merv Porter [SBS-MVP]
============================

"Dan" <dan.zitt...@xxxxxxxxx> wrote in message
news:1163808641.044704.273440@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello all,
I have a system where my manager decided he was afraid we
had
a
potiential security problem so he says he went into SBS
using
his
account (which has Domain Admin rights) to Server
Management -->
Users,
right-clicked his and each of the other domain admin
accounts
and
changed the passwords. He also changed the Administrator
password
in
this same manner. He then disconnected his remote desktop
session
and
now for some reason we can't login with any domain admin
accounts
or
the Administrator account. We do have a power user account
that
can
login but with it's lower privileges, we can't do anything
with
the
domain admin accounts.

If there is any way to get back into those accounts I would
greatly,
greatly appreciate any help. I'm terrified I see a
reinstall
in
my
future right now.- Hide quoted text -- Show quoted text -



.



Relevant Pages

  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... you have risen to an Administrator this would be a given. ... server and run all LOB apps on these. ... If there are no encrypted files, just reset the DSRM account ...
    (microsoft.public.windows.server.sbs)
  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... Teneo> Interesting post and Im now gonna be a party pooper... ... connections) before cutting power to the server and to the Internet ... If there are no encrypted files, just reset the DSRM account ... and try old domain Administrator account's passwords. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote desktop: cannot copy files why still not working
    ... I created a new user on the XP box, set as an administrator ... this new user account is local to the XP system, ... In my environment, when I do an RDP connection to a server, I first log ... member of the local administrators group on the server. ...
    (microsoft.public.windows.server.security)
  • Re: Remote desktop: cannot copy files why still not working
    ... this new user account is local to the XP system, and a member of the local administrator's group on that workstation. ... In my environment, when I do an RDP connection to a server, I first log on to the xp workstation using my regular, non-privileged domain account, run mstsc, and then logon to the server using a domain account that is a member of the local administrators group on the server. ... In addition, I frequently use runas to run privileged applications on the workstation using my "administrator" account, and have found that files cannot be copied between those applications and anything running under the credentials of my regular account - even though my administrator account actually does have full access to everything on the workstation - just not through my regular account's view of that workstation. ...
    (microsoft.public.windows.server.security)
  • Re: Shared Fax device not available anymore after reboot server!?!
    ... the error message one by one to the Newsgroup for accurate research. ... You can send fax by using Administrator account. ... after the reboot of the server no account is able to fax anaymore. ...
    (microsoft.public.windows.server.sbs)