Jump to content

Recommended Posts

Posted

Hi everyone,

 

A delightful student at my school has managed to reset the local admin password by performing the sethc.exe hack which brings up a command prompt at the login page when activating sticky keys (shift 5 times) in windows 7.

 

Luckily my technician caught him doing it on monitoring software.

 

Anyone know how to prevent this? Can I just put a machine policy on to prevent sticky keys?

Posted
We had the same thing happen, luckily the student didn't do anything malicious! We've disabled sticky keys and got a script running on start up to check the file size of sethc.exe as per the attached post. I believe we also disabled start up repair.
  • 1 month later...
Posted
Cheers. Is there a security risk wirh F8 boot menu? I tried and it asks for admin credentials. I'm guessing you used "bcdedit /set {bootmgr} displaybootmenu no"?
Posted

Well we never use safe mode or setup repair...it's quicker to image the machine as a rule so I just disabled it.

 

I believe one way of gaining access to perform this 'hack' is by entering setup repair. I have also disabled the accessibility options button on the logon screen.

 

No doubt they will still find a way round it all

Posted

Computer Configuration > Windows settings > Security settings > File System select new and point to c:\windows\system32\Utilman.exe

 

Change permissions on USERS, SYSTEM and Administrator to DENY.

 

Apply GPO and reboot PC's. The button is still visible but doesn't do anything when clicked.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...