windows operating system back door - shadow account

1. Create a shadow account

net user username $   passwd /add cannot be viewed by net user, but local users and groups can be viewed

2. Run regedit registry

Administrator account, F value is copied to ceshi account F

ceshi account, copy the F value of admin to the current F value

3. Export ceshi user registry file

4. Delete the ceshi account

5. Then import the exported registry

The ceshi account is back, and the permissions are the same as admin, only the registry can delete the account

Guess you like

Origin blog.csdn.net/qq_63283137/article/details/128820098