(Use at your own risk!!!!)
Step-by-step Process:
- Open up VMware Player then load your backtrack VM you lost the 'root' password for, then start the virtual machine
- Click inside the VMware Player window and when the virtual machine starts to load, hit your "Esc" key a bunch of times to enter the Boot Menu
- On the VMware Player menu bar Click "Devices" then "CD/DVD" then "Connect to Disk Image File (.iso)..."
- The Choose Image window will appear. Select the original bt4.iso you used to build your VM with. After your select the .iso image, the window will close.
- In the Boot Menu window, use your arrow keys and select CD-ROM Drive (this will boot the .iso image that is attached to our virtual CD-ROM) then hit the "Enter" key
- The default bt4.iso image will boot up and eventually dump you into a root shell prompt (if using final version of bt4)
- Create a temporary directory to mount the local hard drive to
- mkdir /a
- Mount your local hard drive to the new temporary directory
- mount /dev/sda1 /a
- Now remove the hash value for root in your local hard drives /etc/shadow file
- vi /a/etc/shadow
- Remove the hash contents (should look similar to example below:)
- root:(remove contents between these colons):11111:0:99999:7:::
- Now unmount /a, disable the .iso boot image, and reboot your system
- umount /a
- Click "Devices" then "CD/DVD" then "Disable Disk Image..."
- sync; init 0
- Open up VMware Player again, load your bt4 virtual machine and login with root and NO password!
- That's it!!!
