the WNT box, it's basically a sql injection exploit, if you type anything in REGCON.EXE you can see the query in logs, the solution is in the 1988 box in the new comp.risks