RSS



Go Back   bit-tech.net Forums > bit-tech.net > Article Discussion

Reply
 
Thread Tools
Old 1st Mar 2007, 20:39   #1
Da Dego
Brett Thomas
 
Da Dego's Avatar
 
Join Date: Aug 2004
Location: Cleveland, OH USA
Posts: 3,906
Da Dego is on a distinguished road
Vista activation cracked by brute force

http://www.bit-tech.net/news/2007/03...y_brute_force/

Oh, wait, I own a legal copy....
__________________
"Frankly that seems overkill. iluvtrees2 arguing with spec is the intellectual equivalent of a bunny rabbit taking on a pissed-off lion." - Nexxo
Da Dego is offline   Reply With Quote
Old 1st Mar 2007, 20:44   #2
hotdog
Minimodder
 
hotdog's Avatar
 
Join Date: Feb 2007
Location: People's Republic of California
Posts: 38
hotdog is on a distinguished road
Can't wait to see how this is going to unfold. Yes, I will definitely be waiting for the dust to settle before I buy Vista.
__________________
::ASUS EAH HD4850 Crossfire::Corsair TX750W:: DFI Infinity 975X::Core 2 Duo E6600 @3.22 - Zalman CNPS9700::HP F2105 21" WS LCD::Sennheiser HD485::SB X-Fi Extreme Music::Logitech MX518 mouse-G11 KB-Z-5500::2x1GB PC6400 G Skill::
[CMS]Clan-www.constantmayhem.com [CMS]Tr|pw!r3
hotdog is offline   Reply With Quote
Old 1st Mar 2007, 20:51   #3
Buzzons
Mod Master
 
Join Date: Jul 2005
Posts: 2,085
Buzzons is on a distinguished road
It also says its a very dirty, and long arduous task.. anyone can do this for any key, its just too much effort for most.

Plus, the file has been popping up on a few sites, but differing in sizes so just would like to put a warning out -- it may have been bound with a backdoor/rootkit on some sites.
Buzzons is offline   Reply With Quote
Old 1st Mar 2007, 20:56   #4
DeX
Mube Codder
 
DeX's Avatar
 
Join Date: Jul 2002
Location: London, UK
Posts: 4,103
DeX is on a distinguished road
This is very silly of microsoft. Keys should only be validated server side that way they can see how many attempts each person makes at activation and make brute force attacks impossible. Oh dear.
__________________
Play my game: Shyguy's Cave of Death!
If you dont have the time to check your spelling and grammar, you dont have the time to post! -Liquid K9
DeX is offline   Reply With Quote
Old 1st Mar 2007, 21:05   #5
samkiller42
KEEP IT CLEAN!
 
samkiller42's Avatar
 
Join Date: Apr 2006
Location: Havant, Hampshire, England
Posts: 3,181
samkiller42 is a jewel in the roughsamkiller42 is a jewel in the roughsamkiller42 is a jewel in the roughsamkiller42 is a jewel in the rough
I certainly dont want to be a Microsoft Customer representative when the calls start flooding in, if they flood in that is, this could prove pretty costly to MS.

Sam
__________________
The Rig: i7 920 D0, Gigabyte EX58-UD5, 12GB DDR3 1600mhz, BFG GTX295, Samsung 64gb SSD, WD 640gb Black, Samsung F2 Eco 1TB, Dell 3007WFP, Windows 7 RC.
The Netbook: Samsung NC10 Black, Intel Atom, 2gb DDR2
Xbox Live: samkiller42¦PSN: samkiller42¦Bungie: samkiller42
samkiller42 is offline   Reply With Quote
Old 1st Mar 2007, 21:07   #6
Buzzons
Mod Master
 
Join Date: Jul 2005
Posts: 2,085
Buzzons is on a distinguished road
how can you validate it server side???? what happens if i do not have the internet???

this is the case with 99% of ALL key software, it is not just MS, so I dont really see how its such a big thing.
Buzzons is offline   Reply With Quote
Old 1st Mar 2007, 21:17   #7
randosome
Banned
 
Join Date: Sep 2006
Posts: 226
randosome is on a distinguished road
LMFAO - just LMFAO this is going to be an interesting few months
randosome is offline   Reply With Quote
Old 1st Mar 2007, 21:19   #8
Ramble
Ginger Nut
 
Ramble's Avatar
 
Join Date: Dec 2005
Location: Exeter, Devon/Wantage, Oxfordshire
Posts: 5,233
Ramble will become famous soon enough
You do validate server-side in Vista...
__________________
Kirk, Spock, McCoy, and Ensign Ricky are beaming down to the planet. Guess who's not coming back.
Ramble is online now   Reply With Quote
Old 1st Mar 2007, 21:20   #9
Cobalt
Multimodder
 
Join Date: Feb 2006
Location: Surrey, UK
Posts: 248
Cobalt is on a distinguished road
"Sometimes you just build an angry mouse, who takes a very big sledgehammer to your very delicate, Rube Goldberg-esque trap."

This is my favourite line of 2007 so far. So true.

Cobalt is offline   Reply With Quote
Old 1st Mar 2007, 21:24   #10
Buzzons
Mod Master
 
Join Date: Jul 2005
Posts: 2,085
Buzzons is on a distinguished road
so lets just go down the list of apps you can crack just by entering a key that cost more than Vista

3DS Max
XSI Softimage
Maya
Adobe Creative Suit

all can be cracked with a keygen.. and this is basically a long winded way of getting a keygen.. omg !! SUCH NEWS!!

oh wait... no its not.
Buzzons is offline   Reply With Quote
Old 1st Mar 2007, 21:38   #11
TomH
Bwahahahahaha
 
TomH's Avatar
 
Join Date: Nov 2002
Location: Salford
Posts: 607
TomH is on a distinguished road
Serves them right, tbqh
TomH is offline   Reply With Quote
Old 1st Mar 2007, 21:42   #12
sinizterguy
Dark & Sinizter
 
sinizterguy's Avatar
 
Join Date: Jul 2002
Location: London, UK
Posts: 5,462
sinizterguy is an unknown quantity at this point
Vista activation is not having a good time is it ?
__________________
Nothing here. Go away and dont bother me.
sinizterguy is offline   Reply With Quote
Old 1st Mar 2007, 21:42   #13
keir
S p i t F i r e
 
keir's Avatar
 
Join Date: Oct 2003
Location: Middlesbrough | UK
Posts: 3,064
keir is on a distinguished road
So if someone buys a proper copy, takes it home and cant register ( 'coz it has been too many times ) Then calls MS, they wont be able to to anything?
__________________
Latest project ¦ Project | Black-SpitFire ¦ 89% still
Move house clear out, buy my stuff! 360 Games for sale
UV . Silent . waterCooled - AMD 64 X2 4800+ . 2GB DDR400 . DFI SLi-dr . BFG 8800 GTX WC . Audigy2 ZS
keir is offline   Reply With Quote
Old 1st Mar 2007, 21:43   #14
Kipman725
When did I get a custom title!?!
 
Kipman725's Avatar
 
Join Date: Nov 2004
Location: UK
Posts: 1,753
Kipman725 is on a distinguished road
25 characters in a few hours!?!?!? normaly that would take months

Although I have only cracked passwords upto 14 characters alpha numeric with symbols that took about 1 month per pass using john the ripper under ubuntu 5.1 on an athlon 2600+ with 1gb of ram.
__________________
Sn45g game server mod My Electronics Site
Hardware: 3400+ Sempr0n, 1GB RAM, 1.28TB local storage, x1950pro,Razer Viper,M$ comfort curve 2000,L70S + 17", Fujitsu 17" CRT
Audio: HD-650's, PE congress amp, Sound Blaster AWE64, Soundblaster 24bit
Kipman725 is offline   Reply With Quote
Old 1st Mar 2007, 21:49   #15
sinizterguy
Dark & Sinizter
 
sinizterguy's Avatar
 
Join Date: Jul 2002
Location: London, UK
Posts: 5,462
sinizterguy is an unknown quantity at this point
Quote:
Originally Posted by keir
So if someone buys a proper copy, takes it home and cant register ( 'coz it has been too many times ) Then calls MS, they wont be able to to anything?
Make sure you buying it on a credit card then. Might be the only way to get your money back.

Personally, I dont think that they will screw their customers over like that.
__________________
Nothing here. Go away and dont bother me.
sinizterguy is offline   Reply With Quote
Old 1st Mar 2007, 22:07   #16
flabber
Multimodder
 
Join Date: Jan 2005
Location: Netherlands
Posts: 122
flabber is on a distinguished road
Quote:
Originally Posted by sinizterguy
Vista activation is not having a good time is it ?
Correction; Vista isn't having a good time, period.

To be honest though, I couldn't help myself but laughing my rear off. Even though I know this is pretty serious, and that people who buy the OS and find that they can't even register it is pretty bad. But the way Bit-Tech has written it, it seems like Microsoft is really falling on their own big mouths here, hehehe.

Safest Windows ever! Best security in Windows ever! No virusses for Vista!
....

pewPEWpew! Byebye to all the bigtalk, hello to reality.
Sorry Microsoft, but if you are trying to get us to believe you're doing a good job, make sure you actually áre doing a good job. We'll talk about playing suck-up after that

Too bad though... with the first screenshots of Vista I was actually excited. But the more I hear about Vista, the more it seems like hot air, wrapped in a nice XP-compatible skin
__________________
motustudio.org <---- fiddling around with Wordpress and such
- Thermaltake Mozart, DFI Lanparty UT NF4 Ultra-D
- AMD64 3800+ - XFX 7900 GT - 2Gb Corsair ram - 160Gb HD
flabber is offline   Reply With Quote
Old 1st Mar 2007, 22:12   #17
Firehed
Why not? I own a domain to match.
 
Firehed's Avatar
 
Join Date: Feb 2004
Location: An hour north of Boston
Posts: 12,576
Firehed has a spectacular aura aboutFirehed has a spectacular aura aboutFirehed has a spectacular aura about
Heh, can't pretend we didn't see it coming. Although if that's fully cracked, then how cracked is the version that... err, nevermind.

It does sound fast for a key of that length... ~808,281,277,460,000,000,000,000,000,000,000,000,0 00 possibilities assuming any character can be one of thirty-six things (which obviously it can't since then any random typing would be a valid key, so they must know quite a bit about the structure)
__________________
hire me @ eric-stern.com - web developer and php ninja
pics @ my smugmug :: Twitter @firehed :: blog @ firehed.net
40D|580EXII|285HV|AB800|70-200f/4LIS|17-50f/2.8|150f/2.8Macro|50f/1.8
MacPro @ 8x2.8GHz, 10GB FBDDR2, 3TB HD :: MBP @ 2x2.2GHz, 4GB DDR2, 320GB HD
Firehed is offline   Reply With Quote
Old 1st Mar 2007, 22:18   #18
mclean007
Officious Bystander
 
mclean007's Avatar
 
Join Date: May 2003
Location: Nodnol
Posts: 1,595
mclean007 is on a distinguished road
Quote:
Originally Posted by sinizterguy
Make sure you buying it on a credit card then. Might be the only way to get your money back.

Personally, I dont think that they will screw their customers over like that.
No way. First of all, there's a little thing called consumer rights - if you buy something that doesn't work as advertised, you have a right to a replacement or full refund. So MS can't sit back and do nothing if legitimate copies are being declined for authorisation because some clown has already stumbled on that key. Secondly, the PR fallout would be IMMENSE. MS' name would be dirt (even moreso than it is already - at least people currently generally trust MS, even if they don't like it).
Quote:
Originally Posted by DeX
This is very silly of microsoft. Keys should only be validated server side that way they can see how many attempts each person makes at activation and make brute force attacks impossible. Oh dear.
AFAIK they do, but as I understand it, this crack works by churning through keys until it finds one that MS has authorised for use on a legit copy (i.e. it finds a key which is already in circulation on the licence certificate of a genuine copy of Vista). Not much they can do to stop it tbh, short of a full recall and reissue with longer keys. I'd like to see how much that would cost them.

Realistically, if this starts to become a problem, they're just going to have to relax the licensing restrictions, in order to keep the legit purchasers who get stung (who could number MANY when this crack gets known in the wider world) from turning up at Redmond with pitchforks and flaming torches.
Quote:
Originally Posted by Kipman725
25 characters in a few hours!?!?!? normaly that would take months

Although I have only cracked passwords upto 14 characters alpha numeric with symbols that took about 1 month per pass using john the ripper under ubuntu 5.1 on an athlon 2600+ with 1gb of ram.
Yeah, but remember MS will have MILLIONS of legit codes in circulation, and probably a great many more pre-authorised on licences ready to go out. There are many possible solutions to this particular brute force.

I guess one semi-solution is to limit the number of activation requests serviced in a given time by each IP address - e.g. no more than 5 goes in a 1 hour period for any IP address. This would slow down the brute force something chronic (though I guess you could in principle use a distributed attempt from a botnet to spread the requests over many IPs), but would still allow for a couple of typos in the key, or for the (rare) situation where an IP leased to one person who has used it to activate his copy of Vista is then dropped and immediately re-leased to a second person who also needs to activate.

EDIT: I guess the point is that ANY activation / copy protection will eventually be broken, given enough effort, and MS' software will always attract that kind of effort. The best MS can hope to do is inconvenience the hackers enough that for the majority of people it isn't worth the hassle of working through the crack just to save a few £$€
__________________
Demand Naked DSL in the UK!
mclean007 is offline   Reply With Quote
Old 1st Mar 2007, 22:23   #19
Buzzons
Mod Master
 
Join Date: Jul 2005
Posts: 2,085
Buzzons is on a distinguished road
you know you can do this on XP as well? and 2k3 and ME and 2k ...
Buzzons is offline   Reply With Quote
Old 1st Mar 2007, 22:42   #20
CyberSol
1337 Pants
 
CyberSol's Avatar
 
Join Date: Oct 2004
Location: On teh interweb USA
Posts: 857
CyberSol is on a distinguished road
to bad vista isn't worth cracking...
much less buying.
__________________
CyberSol is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 16:48.
Powered by: vBulletin Version 3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.