Vista Activation Cracked By Brute Force


Recommended Posts

Holy smokes! :blink: This could be bad for Microsoft. I'm sure there is SOMETHING they can do.

IT LOOKS LIKE Microsoft's unhackable OS activation malware has been hacked.

There is an active thread at the Keznews forums (account needed), and a summary on its main page about the crack.

It is a simple brute force attack, dumb as a rock that just tries keys. If it gets one, you manually have to check it and try activation. Is is ugly, takes hours, is far from point and click, but it is said to work. I don't have any Vista installs because of the anti-user licensing so I have not tested it personally.

The method of attack has got to be quite troubling for MS on many grounds. The crack is a glorified guesser, and with the speed of modern PCs and the number of outstanding keys, the 25-digit serials are within range. The biggest problem for MS? If this gets widespread, and I hope it will, people will start activating legit keys that are owned by other people

It won't take long for boxes bought at retail to be activated before they are bought, and the people who plunk down money for the mal^h^h^hsoftware for real get 'you are a filthy pirate' messages. Won't that be a laugh riot at the MS phone banks in Bangalore.

So, what do you do? There is really no differentiating between a legit copy with a manually typed in wrong key and a hack attempt. Sure MS can throttle this by limiting key attempts to one a minute or so on new software, but the older variants are already burnt to disk. The cat is out of the bag.

The code is floating, the method is known, and there is nothing MS can do at this point other than suck it down and prepare for the problems this causes. To make matters worse, MS will have to decide if it is worth it to allow people to take back legit keys that have been hijacked, or tell customers to go away, we have your money already, read your license agreement and get bent, we owe you nothing.

This is ugly for MS, and if it allows you to take back your legit keys, how long do you think it will take before people catch on to the fact that you can call in and hijack already purchased keys once you generate one that someone else activated?

No, this is a mess, and the problem is the very malware activation and anti-consumer licensing that MS built into Vista. Then again, it is kind of hard to feel sorry for them the way they screw their paying customers. We'll give it three days before there is a slick GUI version with all the bells and whistles.

Edited by voidunknown

Perhaps when you buy a version of Vista now or install it/activate a key, you'll also have to include a PIN number or password. Then, if somebody tries to guess your key/use it, they'll also have to know and use your PIN. Perhaps this system is too simple, but I think just another level of security will be thrown on top of the key system.

Perhaps when you buy a version of Vista now or install it/activate a key, you'll also have to include a PIN number or password. Then, if somebody tries to guess your key/use it, they'll also have to know and use your PIN. Perhaps this system is too simple, but I think just another level of security will be thrown on top of the key system.

This is getting out of hand though. Wouldn't you agree?

If thats the case, next they will want my Social Security number, drivers license, birth certificate, proof of purchase, a digital copy of the cd, and for me to stand on my head and spin around 3 times.

I wonder how long it takes to find one that works.

To keep the trolls at bay, I edited the post.

Do you really think that is going to stop anyone? I don't...

I wonder how long it takes to find one that works.

Most have reported 2-5 hours...

depends on your computer speed. ill tell you tomorrow with a 64 3200+ ;)

Wait, you complained that I linked to the main page where the instructions where, then you openly admitted to using it? Oxymoron much?

I didn't try this. All 5 of my Vista installs are legit.

The biggest problem for MS? If this gets widespread, and I hope it will, people will start activating legit keys that are owned by other people.

It's good to know the article's author likes to have legitimate customers f**ked by pirates. Assclown.

There was a similar keygen for XP (which I won't mention by name, of course) although it only ever seemed to work right for one particular type of key. It could sometimes take hours for it to come up with a decent list of keys, but they all worked (at least until WGA came around with more stringent checks on product ids). What I don't get is why Microsoft never just made a database of all the keys that they issued, and checked all activations against that database.

There was a similar keygen for XP (which I won't mention by name, of course) although it only ever seemed to work right for one particular type of key. It could sometimes take hours for it to come up with a decent list of keys, but they all worked (at least until WGA came around with more stringent checks on product ids). What I don't get is why Microsoft never just made a database of all the keys that they issued, and checked all activations against that database.

that would be real smart, all it would take is a hacker and they have every key

This isn't such a big deal. They'll just limit activation tries to one per minute per IP, for example. Or they'll release an update to the activation mechanism in the software via a Critical update. Because of the nature of the importance Microsoft places upon this system, there is no way they'd release Vista without some sort of automatic updater of the activation procedures prior to the user activating.

Sure it's a hole but it'll be fixed, transparently to the user. The writer of the article has flawed logic.

but it doesnt try to brute force activate online, it brute forces the local activation and when you got a key you can try activating online if you want. they can try to release a patch that stops this but then you dont have to get it.

This isn't such a big deal. They'll just limit activation tries to one per minute per IP, for example. Or they'll release an update to the activation mechanism in the software via a Critical update. Because of the nature of the importance Microsoft places upon this system, there is no way they'd release Vista without some sort of automatic updater of the activation procedures prior to the user activating.

95% of the keys out there havent been activated yet, so the chances of you actually having to try to activate a working key more than once are pretty slim. Remember the OS checks to see if the key is valid, if it is THEN it tries to activate.

The keygen must be a bit more clever than simply trying a random key. After all, the number of possible keys is at least 22^25 = 2^111 (not all letters are possible).

well fist you can get rid of all the keys that youknow arent gunna be genuine. then with todays cpu's even a athlon64/pentuim d you could prolly get 30-60 thousand keys a sec. some dual core cpus could prolly hit 6 digits a sec. itll still take hours/days to get but not a ridiculous amount of time.

I always wondered why we were still at a mere 25 digits for cd keys. I wonder how many people will bother trying this, as opposed to the "other methods".
just as smart as having a 25 character key that only consists of upper case letters and numbers.

Yea like how many non-geeks are going to be able to type wR7v@-B#epr-*yaf!-Ze*aT-redet-acHep with ease and no error?

well fist you can get rid of all the keys that youknow arent gunna be genuine. then with todays cpu's even a athlon64/pentuim d you could prolly get 30-60 thousand keys a sec. some dual core cpus could prolly hit 6 digits a sec. itll still take hours/days to get but not a ridiculous amount of time.

I'll assume there's around 2^32 (about 4 billion) "valid" keys (in the sense that local activation accepts them). So assuming you can test even 2^30 (1 billion) keys per second, it would still take 2^(111-30-32) = 2^49 seconds = billions of years until you expect to find 1 locally valid key. So the author must be using some math to eliminate certain classes of keys.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Thanks free chatgpt. The issue is, with most browsers, is you shouldn't need tools to remove anything. It is the whole point of extensions. The only browser so far to man up and be honest that it needs money to function is Brave Origin. Don't like the monetisation and code bloat, have a clean browser for a one off $ charge. Firefox used to be that, but now it is a code bloat browser, hiding AI.
    • Source and more Giles in Buffy! Spooks (MI-5 for the US people)! The Prime Minister in Little Britain!
    • Pick up this lifetime subscription to Babbel Language Learning now at 47% off by Steven Parker Learn all 14 languages and access more than 10,000 hours of high-quality language education online. Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can pick up a lifetime subscription to Babbel Language Learning at 47% off. Note: Available to U.S. customers & NEW users only. Learn Spanish, French, Italian, German, and many more languages with Babbel, the #1 top-grossing language-learning app in the world. Developed by over 100 expert linguists, Babbel is helping millions of people speak a new language quickly and with confidence. After just one month, you will be able to speak confidently about practical topics, such as transportation, dining, shopping, directions, making friends and socializing and much more! Get lifetime access to learn all 14 languages Practice with 10-15 minute bite-sized lessons that fit conveniently into your schedule Cover a wide range of useful real-life topics, from travel to family, business, food & more Use speech recognition technology to keep your pronunciation on point Learn at a variety of skill levels, from beginner to advanced Get personalized review sessions to reinforce what you learn so it really sticks Study whenever & wherever you want and your progress will be synchronized across your devices Use offline mode to access courses, lessons & review items when not on Wi-Fi—just download them beforehand Languages Available: Spanish (Spain), German, Italian, French, Portuguese, Swedish, Turkish, Dutch, Polish, Indonesian, Norwegian, Danish, Russian, Spanish (Latin America) Good to know Length of access: lifetime Valid for New Users in the USA Only Redemption deadline: redeem your code within 30 days of purchase Please note redemption is required via Web Browser. Access to the mobile app will be available after redemption has been completed via web browser Max number of devices: Unlimited Access options: desktop & mobile Number of languages: 14 (all current languages) Updates included Babbel Language Learning: Lifetime Subscription (All Languages) normally costs $299, but you can pick it up for just $159 for a limited time - that represents a saving of $140. For a full description, specs, and license info, click the link below. Deal Price $159.00 with code LEARN NOTE: For NEW users in the US only. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
  • Recent Achievements

    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      468
    2. 2
      PsYcHoKiLLa
      256
    3. 3
      Skyfrog
      79
    4. 4
      ATLien_0
      61
    5. 5
      FloatingFatMan
      60
  • Tell a friend

    Love Neowin? Tell a friend!