Hack Administrator From Guest Account






Press the shift key 5 times and the sticky keys dialog up.This shows works even in the login screen. But if we replace the sethc.exe which is responsible for dialogue with cmd.exe sticky keys, and then call sethc.exe pressing the Shift key five times in the logon screen, which from a command prompt with privileges the administrator, because no user has logged on. From there you can hack the administrator password, even from a guest account.
Prerequisites
Guest account with write access to system 32.
Here is how to do that - 
  • Go to C:/windows/system32
  • Copy cmd.exe and paste it on desktop
  • rename cmd.exe to sethc.exe
  • Copy the new sethc.exe to system 32,when windows asks for overwriting the file,then click yes.




Now quit your guest account and select the user window, press the Shift key five times. 

Instead of sticky Key dialog confirmation, the command prompt with full administrator privileges is open.





Now type “ NET USER ADMINISTRATOR aaa” where “aaa” can be any password you like and press enter.

You will see “ The Command completed successfully” and then exit the command prompt and login into administrator with your new password.
Congrats You have hacked admin from guest account.
Further..
Also, you can further create a new user at the command prompt by typing “NET USER XERO /ADD” where “XERO” is the username you would like to add with administrator privileges. Then hide your newly created admin account by - 
Go to registry editor and navigate to this key 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Here create a new DWORD value, write its name as the “user name” that u created for your admin account and live with your admin account forever.