Vista Activation Cracked By Brute Force


Recommended Posts

I wonder what this means for me. I have multiple legitimate keys and if someone magically got one of my keys from a keygen mine would fail WGA :/

I guess if that happens in high enough numbers Microsoft will have to end WGA altogether?

Yes, I will definitely be ****ed if my key ever starts giving me trouble because someone generated it through brute force. I will give this a try just for fun. I wouldn't mind generating a list of keys and just keeping them on hand in case this becomes cold war between Microsoft and the citizens of the world.

Yay got mine only in 40 minutes!
Here's what to do next!
  1. Yell upstairs to your mom
  2. Tell the dumb broad to fix you some Pop Tarts
  3. Sit in front of your activated copy of Vista all day and develop some blood clots in your legs
  4. Have 1 (or more) of those clots pass up into your lungs
  5. Instruct your family to sue Microsoft for wrongful death after you've passed

What I want to know is how someone "comes across this accidentally" while learning vbscript. That statement right there is BS. If my key gets stolen, I expect Microsoft to replace it with a new one. In the end, it really doesn't matter. They let you activate your copy over the phone no matter what.

Not even MS said it was unhackable, so why do things like this keep being spread. Also, brute force generation is not really a crack; a crack involves bypassing a protection, while brute forcing is really just trying a whole lot of keys. Any protection using keys or passwords is "vulnerable" to that really, the difference is just how long it takes. But that's mostly semantics. What's important to both MS and priates alike is if this method is efficient enough. :)

What I'm surprised about is how bruteforcing can be possible even now...

25 characters with 26 (letters) + 10 (digits) combinations each => 25^36 combinations. That number is 50 digits long!

211758236813575084767080625169910490512847900390625 combinations.

I don't really get how they can do this in a viable way still... They have to have figured out a way to reduce the number of permutations far below 26^36 somehow, perhaps by figuring out the key algorithm and not trying *all* combinations. That would just be ridiculous! Perhaps they're able to just try out for a specific Vista Edition, but it still feels like a whole lot! 100 million "valid" keys among all those combinations would still just be a drop in the ocean?

add on top of that, on the forum the guy says it can only go 10,000 keys every 30min. and no there's no algorithm used its just striaght brute force. i think alot of people lie about getting a key maybe a small handful will get lucky cause of randomness.

Here's what to do next!
  1. Yell upstairs to your mom
  2. Tell the dumb broad to fix you some Pop Tarts
  3. Sit in front of your activated copy of Vista all day and develop some blood clots in your legs
  4. Have 1 (or more) of those clots pass up into your lungs
  5. Instruct your family to sue Microsoft for wrongful death after you've passed

Thats freakin ironic.

I was thinking about getting M$ to cough up a few billion that way for me, except, I was going to say it was

too much exposure to porno and drugs on the net that made me an addict, so M$ cough up. My lawyers will be the EU!

add on top of that, on the forum the guy says it can only go 10,000 keys every 30min. and no there's no algorithm used its just striaght brute force. i think alot of people lie about getting a key maybe a small handful will get lucky cause of randomness.

He should know at least that certain characters are not used in Microsoft's product keys... EVER!

When was the last time you've seen an A??? Or any vocal?!?!

Actually, theres a couple of them actually:

The 5 Vocals - A, E, I, O, U

4 consonants - N, L, S, Z

The numbers 0 and 1

So that drops the number of possible combinations down considerably. If his script is coded without these considerations then it would take a lot longer to get an usable key.

If you have Vista, you can try it yourself. Go over to Windows Properties and click on the change product key "link" and try punching in any of those characters! You will get a message that says that an unusable character was used.

If any of you guys have the script, please send it over to hotmail_staff_warning-AT-hotmail.com to review it.

care to elaborate ?
wow it was cracked, didnt see that coming..... haaaaaa

There was a BIOS hack that made the OS think the machine is an OEM machine and activated the OS without a problem. And then a week later this hack came out and the news break headlines. I just don't see how this method get more attention than it should. To my knowledge, I think if Microsoft was to fear of such hack it shouldn't be this one but the BIOS one. That is at the root of activation.

:::Update:::

icon_newest_reply.gif Brute force keygen a phoney

fact is the brute force keygen is a joke, i never intended for it to work. I have never gotten it to work, everyone should stop using it!

everyone who said they got a key a probably lying or mistaken!

i suggest everyone uses the 120 day 3x rearm method.

what a guy..

:::Update:::

icon_newest_reply.gif Brute force keygen a phoney

what a guy..

It's almost sounds like he got a call from MS lawyers or something...

A lot of people claim that it worked for them, are they all lieing?

Did you guys read his apology letter to MS ?

http://keznews.com/forum/viewtopic.php?t=2696

lmao :)

Is there anyone here who seriosly was able to get a legit key that activate through this method?

Edited by Ron21
You would think it would be surprisingly easy to stop brute force attacks. Just limit activation attempts by IP.

ive said this already in the thread. it doesnt try to activate, it checks your vista locally to see if it accepts the key then if you want to you can try to activate.

In worst case .. it will take 4613477611100251487689152970642 years to find a valid key.

Exactly:

(25^36)/10,000/60/24/365 = The amount of years it would take to figure out all the keys if it did 10,000 per minute

And that's about:

4.02888578 ? 10^40 years.

So that's about 40,000,000,000,000,000,000,000,000,000,000,000,000,000 years

Good luck with that:pp

So yeh, I find it no surprise the guy called it in as phoney. I mean, cmon - do the maths:pp

Exactly:

(25^36)/10,000/60/24/365 = The amount of years it would take to figure out all the keys if it did 10,000 per minute

And that's about:

4.02888578 ? 10^40 years.

So that's about 40,000,000,000,000,000,000,000,000,000,000,000,000,000 years

Good luck with that:pp

So yeh, I find it no surprise the guy called it in as phoney. I mean, cmon - do the maths:pp

I agree with you that it's unlikely that a key can be found at random, but your math is off. First off, the total number of combinations is 25^25 (25 possible digits in a serial of length 25). That's still a lot. But what you're forgetting is that we have no idea how MS has limited the keyspace that Windows Vista will accept as a valid key. Further, nobody needs to find ALL the keys, they only need to find one. These 2 facts could make it considerably easier to happen upon a valid key. Impossible to say how likely unless we know the valid key space.

However, the brute-force script that is running around itself is flawed. The code is poorly written and includes the letter "L," which Vista will not accept; and the number "5," which Vista will also not accept. This means that, on average, every other key that the script tests will have no chance of being valid because it includes invalid characters. Further, I tested the script for a about an hour and found that on a dual-core machine it was only testing, on average, about 600 keys PER HOUR.

Bottom line: it's theoretically possible that people are happening on keys using this method, but I doubt it. However, the quadrizillion years claim (like the cryptographers like to use) is just silly. Once people figure out how to narrow down the key space by finding clues about how the key algorithm works, then a brute-force mechanism might become feasible.

The only way a brute force could work is if someone did some good coding and removes the obvious invalid keys such as AAAAA-AAAAA-AAAAA-AAAAA 11111-11111-11111-11111 etc something like that, it will still leave a few billion combination but it will be more specific as you only need to find 1 working key not all the possible keys.

Also arent some letters not allowed in cd keys?

I suppose if you did that you will probably be down to a few hundred million or a billion keys.

Then by pure chance you could find a cdkey or 2 in a couple of day or something.

It's almost sounds like he got a call from MS lawyers or something...

A lot of people claim that it worked for them, are they all lieing?

Did you guys read his apology letter to MS ?

http://keznews.com/forum/viewtopic.php?t=2696

lmao :)

Is there anyone here who seriosly was able to get a legit key that activate through this method?

It must have worked properly at least for some, otherwise they wouldn't have bothered to go after him (they have better things to do), and he wouldn't have needed to write that apology letter. He was probably also forced by MS to claim that it is fake to keep people from using it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • OpenAI is now rolling out Lockdown Mode to more ChatGPT users by Pradeep Viswanathan Back in February, OpenAI first announced Lockdown Mode for users who want the most comprehensive protection from potential attacks. At the time of the announcement, the company mentioned that this feature was available to a small set of highly security-conscious users, including executives or security teams at leading organizations. Today, OpenAI announced that Lockdown Mode is now rolling out to all personal ChatGPT accounts, including Free, Go, Plus, and Pro, and also self-serve ChatGPT Business accounts. Users can enable the feature from ChatGPT Settings > Security when it is available for their account. When Lockdown Mode is enabled, ChatGPT limits or disables several features that connect to the web or external services. These include live web browsing, Deep Research, Agent Mode, and more. Here is the complete list of services that will be disabled in Lockdown Mode: Live web browsing: Web browsing is limited to accessing only cached content. Search results may be limited, unavailable, or stale. Image support: ChatGPT may not display images in regular responses or retrieve images from the web. Users can still upload image files, and image generation remains available where it is otherwise available. Deep research: Deep research is disabled. Agent mode: Agent mode is disabled. Canvas networking: Users cannot approve Canvas-generated code to access the network. File downloads: ChatGPT cannot download files for data analysis. ChatGPT can still operate on your manually uploaded files. It is important to note that Lockdown Mode does not completely block prompt injections from appearing in content that ChatGPT processes. For example, a malicious instruction could still be present in an uploaded file or cached web content. However, the mode is designed to reduce the ways such an attack could send sensitive information outside the conversation. Along with Lockdown Mode, OpenAI today also announced that the Active sessions feature is now available across ChatGPT accounts and workspace types. This feature allows users to review where their account is signed in across devices and end sessions if required. A session will have the following information displayed: Device or browser information. First-party app context, such as ChatGPT, Codex, or API Platform. Approximate location. Sign-in date and time. Whether the device is a trusted device. Whether it is your current session. OpenAI highlighted that the Active sessions feature will not be available for accounts linked to an organization’s single sign-on setup, including SAML or OIDC.
    • with LSTC and ESU, moving to w11 or linux because w10 suddenly will not work when in reality it works and its a better choice, of course there are also developers that only test in 11 or force you to have TPM and Secure boot for the sake of "better security" in games. or most likely people is buying new PC that only ship with 11
    • with LTSC and ESU there are still viable as a stable platform not that they care and let people deal with w11 crashing and burning every month support mean shet if the platform is trash
    • Most boring game ever. Repetitive, empty, predictable, and full of cliches. Total waste of time and money, IMO.
    • Mafia: The Old Country expansion Man of Honor announced, brings back Salieri from original by Pulasthi Ariyasinghe During Summer Game Fest, 2K and Hanger 13 brought out a new Mafia: The Old Country trailer, revealing the game's first expansion. Named Man of Honor, this is slated to add two new chapters to the Enzo storyline that the game follows. There is an iconic character returning to the series with this expansion, with players set to run into Ennio Salieri, the future Don of the Salieri crime family. Fans of the original Mafia, or its Definitive Edition remake, may remember that name as one of the biggest characters in the storyline. This expansion is set prior to his rise to being the kingpin in the City of Lost Heaven. "Set in Sicily during the winter of 1905, Enzo Favara has proven himself a reliable soldier of the Torrisi crime family in the months since his initiation," says the studio about the new chapters. "Now, the Don entrusts him and Cesare with a delicate assignment of assisting Ennio Salieri, a man of honor recently released from prison and intent on reclaiming what is his." Working at Salieri's side, players will be heading into fresh environments as they return to the role of Enzo as a high-ranking soldato. The studio also promises brand-new weapons, fresh vehicles, and charms to collect in this expansion. Moreover, the expansion will add new content to the updated Free Ride mode. Alongside new collectibles and locations, this will add more challenges to beat alongside Salieri, which are described as runs that will "test the skills of even the most elite mafiosi." The Mafia: The Old Country Man of Honor story expansion will release on August 14, 2026, across PC, Xbox Series X|S, and PlayStation 5. It will cost $10 for owners of the base game to jump into.
  • Recent Achievements

    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      488
    2. 2
      PsYcHoKiLLa
      270
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      63
  • Tell a friend

    Love Neowin? Tell a friend!