Vista Activation Cracked By Brute Force


Recommended Posts

I'll assume there's around 2^32 (about 4 billion) "valid" keys (in the sense that local activation accepts them). So assuming you can test even 2^30 (1 billion) keys per second, it would still take 2^(111-30-32) = 2^49 seconds = billions of years until you expect to find 1 locally valid key. So the author must be using some math to eliminate certain classes of keys.

well yes isnt that the point of hacking? to find vulnerbilities in the algorithm used?

I'll assume there's around 2^32 (about 4 billion) "valid" keys (in the sense that local activation accepts them). So assuming you can test even 2^30 (1 billion) keys per second, it would still take 2^(111-30-32) = 2^49 seconds = billions of years until you expect to find 1 locally valid key. So the author must be using some math to eliminate certain classes of keys.

They are really going to have problems once someone harnesses the power of using an Nvidia 8800 as a so called "super computer". That could probably generate keys in seconds/minutes.

They go to all this trouble with one time activation schemes... I personally just wouldn't mind buying Windows on a subscription model at say $10/month for a Home Edition, $15 for a Professional Edition even if it required a constant internet connection and regular subscription verification (much like Steam) and then I wouldn't feel so jipped when I wanted to upgrade to the next operating system version or have the flexibility to upgrade/downgrade distributions.

They go to all this trouble with one time activation schemes... I personally just wouldn't mind buying Windows on a subscription model at say $10/month for a Home Edition, $15 for a Professional Edition even if it required a constant internet connection and regular subscription verification (much like Steam) and then I wouldn't feel so jipped when I wanted to upgrade to the next operating system version or have the flexibility to upgrade/downgrade distributions.

hmm 5 years * 12 months = 60 months * 15$ per month = 900$

hmm 5 years * 12 months = 60 months * 15$ per month = 900$

Ok... poor example... assuming that new versions of Windows were available on a three - four year window and not the XP - Vista gap. You could also include all support such as service packs and updates as revisions of current versions that you are getting for free now. Point being I hate to purchase an additional XP licence say in July 2006 with Vista release only 6 months away $250 vs 15*6 = $90 so depends on the case of purchase and use. Appropriate pricing to be determined later, and I'm sure the traditional purchase method would still be available.

So, basically what this program does is find a genuine cd-key that's being sold in stores? If this is the case, Microsoft has a problem of catastrophic dimension in their hands right now. :o

well according to the forum the script can only do 10000 keys in 30 minutes so youd be lucky to find a legit key in your lifetime.

honestly my vista cant stay up long enough without bsod'ing for me to really test it out.

I think this article is being overreacted on.

In my country vista business costs about 160 bux ;) Is it worth it?

i got my ultimate x64 for 159? (SB Version).

that sux, really! hope MS get it fixed for themselfes and for US!!! i think, that not only me was exited about vista and bought it for his hard earned money. i don?t care when they get "new" keys and MS can blacklist them and they have to do it again, but to generate keys that already are on the booklets and the new ones comming to stores, thats bad.

that freak is a sucker*, hope they get him, i dont care, because i payed for my vista:crazy:zy:

i got my ultimate x64 for 159? (SB Version).

that sux, really! hope MS get it fixed for themselfes and for US!!! i think, that not only me was exited about vista and bought it for his hard earned money. i don?t care when they get "new" keys and MS can blacklist them and they have to do it again, but to generate keys that already are on the booklets and the new ones comming to stores, thats bad.

that freak is a sucker*, hope they get him, i dont care, because i payed for my vista:crazy:zy:

I can't stop laughin:laugh:gh:

I have a legal license myself but that must be the dumbest thing I've ever heard.

If Vista wasn't overpriced, why would you care about people getting it for free?

Doom that version of vista is OEM and i think your only allowed to install it on the computer ya using and not allowed any hardware modifications, i think.

But ill be getting the OEM version to and ill change what i want and if microsoft say ya cant ill say well why the **** do ya need 2 OS's on 1 disk, your only gonna use one of em. Then they want to make ya pay ?328 and they call that a good deal, yeah whatever more like forcing both OS's on ya to increase there money cus they know theyve done a **** job with vista.

If they new they couldnt include all the good stuff like the new filesystem they should of ditched that stuff years ago and kept to a decent release date. Instead its us suckers that gotta pay for there mistake

Doom that version of vista is OEM and i think your only allowed to install it on the computer ya using and not allowed any hardware modifications, i think.

But ill be getting the OEM version to and ill change what i want and if microsoft say ya cant ill say well why the **** do ya need 2 OS's on 1 disk, your only gonna use one of em. Then they want to make ya pay ?328 and they call that a good deal, yeah whatever more like forcing both OS's on ya to increase there money cus they know theyve done a **** job with vista.

If they new they couldnt include all the good stuff like the new filesystem they should of ditched that stuff years ago and kept to a decent release date. Instead its us suckers that gotta pay for there mistake

SB is system builder edition, you have to choose bevor you buy in 32bit or 64bit. its one user license, yes, and about that hardware change, they can?t do it here because of the laws (germany), you can change hardware and activate again.

@SBeaver: i dont get you, why you have to laugh and why its dumb what i said? this why i payed 159? and not 499?.

i dont understand you

IT LOOKS LIKE Microsoft's unhackable OS activation malware has been hacked.
Not even MS said it was unhackable, so why do things like this keep being spread. Also, brute force generation is not really a crack; a crack involves bypassing a protection, while brute forcing is really just trying a whole lot of keys. Any protection using keys or passwords is "vulnerable" to that really, the difference is just how long it takes. But that's mostly semantics. What's important to both MS and priates alike is if this method is efficient enough. :)
I always wondered why we were still at a mere 25 digits for cd keys. I wonder how many people will bother trying this, as opposed to the "other methods".

What I'm surprised about is how bruteforcing can be possible even now...

25 characters with 26 (letters) + 10 (digits) combinations each => 25^36 combinations. That number is 50 digits long!

211758236813575084767080625169910490512847900390625 combinations.

I don't really get how they can do this in a viable way still... They have to have figured out a way to reduce the number of permutations far below 26^36 somehow, perhaps by figuring out the key algorithm and not trying *all* combinations. That would just be ridiculous! Perhaps they're able to just try out for a specific Vista Edition, but it still feels like a whole lot! 100 million "valid" keys among all those combinations would still just be a drop in the ocean?

Edited by Jugalator
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • OpenAI is now rolling out Lockdown Mode to more ChatGPT users by Pradeep Viswanathan Back in February, OpenAI first announced Lockdown Mode for users who want the most comprehensive protection from potential attacks. At the time of the announcement, the company mentioned that this feature was available to a small set of highly security-conscious users, including executives or security teams at leading organizations. Today, OpenAI announced that Lockdown Mode is now rolling out to all personal ChatGPT accounts, including Free, Go, Plus, and Pro, and also self-serve ChatGPT Business accounts. Users can enable the feature from ChatGPT Settings > Security when it is available for their account. When Lockdown Mode is enabled, ChatGPT limits or disables several features that connect to the web or external services. These include live web browsing, Deep Research, Agent Mode, and more. Here is the complete list of services that will be disabled in Lockdown Mode: Live web browsing: Web browsing is limited to accessing only cached content. Search results may be limited, unavailable, or stale. Image support: ChatGPT may not display images in regular responses or retrieve images from the web. Users can still upload image files, and image generation remains available where it is otherwise available. Deep research: Deep research is disabled. Agent mode: Agent mode is disabled. Canvas networking: Users cannot approve Canvas-generated code to access the network. File downloads: ChatGPT cannot download files for data analysis. ChatGPT can still operate on your manually uploaded files. It is important to note that Lockdown Mode does not completely block prompt injections from appearing in content that ChatGPT processes. For example, a malicious instruction could still be present in an uploaded file or cached web content. However, the mode is designed to reduce the ways such an attack could send sensitive information outside the conversation. Along with Lockdown Mode, OpenAI today also announced that the Active sessions feature is now available across ChatGPT accounts and workspace types. This feature allows users to review where their account is signed in across devices and end sessions if required. A session will have the following information displayed: Device or browser information. First-party app context, such as ChatGPT, Codex, or API Platform. Approximate location. Sign-in date and time. Whether the device is a trusted device. Whether it is your current session. OpenAI highlighted that the Active sessions feature will not be available for accounts linked to an organization’s single sign-on setup, including SAML or OIDC.
    • with LSTC and ESU, moving to w11 or linux because w10 suddenly will not work when in reality it works and its a better choice, of course there are also developers that only test in 11 or force you to have TPM and Secure boot for the sake of "better security" in games. or most likely people is buying new PC that only ship with 11
    • with LTSC and ESU there are still viable as a stable platform not that they care and let people deal with w11 crashing and burning every month support mean shet if the platform is trash
    • Most boring game ever. Repetitive, empty, predictable, and full of cliches. Total waste of time and money, IMO.
  • Recent Achievements

    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      487
    2. 2
      PsYcHoKiLLa
      270
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      63
  • Tell a friend

    Love Neowin? Tell a friend!