* Astronomy

Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Resistance is futile


L

Posts: 131433
Date:
Pirated Windows
Permalink  
 


Microsoft has just dropped the hammer on 26 US resellers that the company suspects of selling pirated software outright or pre-loading it onto PC hard drives. The company filed lawsuits against firms in Colorado, Georgia, Illinois, New Jersey, New York, Ohio, and South Carolina after "secret shopper" tests turned up illicit software.

Read more

__________________


L

Posts: 131433
Date:
Resistance is futile
Permalink  
 


Resistance is futile you will be assimilated
A tool provided by Microsoft could let people get around a check meant to prevent those with pirated copies of Windows from downloading additional software from the company, according to a security researcher.
Researcher Debasis Mohanty outlined what he said was a technique to trick Microsoft's Windows Genuine Advantage validation check in a posting to the Full Disclosure security mailing list on Monday. WGA is a software tool that verifies whether a particular copy of the operating system is properly licensed.
Using a secondary Microsoft validation tool called "GenuineCheck.exe," it may be possible for people to trick the checking mechanism, Mohanty said in the posting. They could then download and run supposedly restricted software from Microsoft's Download Centre on a PC running a pirated version of Windows.
(It creates a hidden dummy file called GenuineCheck.exe in the same directory that Microsoft uses, setting its attributes to read-only)
Microsoft confirmed that the technique could circumvent the piracy check, but that the company is not worried.
"This represents very little threat to Microsoft. We expected counterfeiters to try a number of different methods to circumvent the safeguards provided by Windows Genuine Advantage."
The company has been testing the WGA piracy lock on its Download Centre and Windows Update Web sites for several months. It has said that by an unspecified date in the middle of this year, all Windows XP and Windows 2000 users will have to validate their copy of Windows before they can download from the Web sites.
Since last year the company has been testing a tool that can check whether a particular version of Windows is legitimate, but until now the checks have been voluntary. Starting Feb. 7, the verification will be mandatory for many downloads for people in three countries: China, Norway and the Czech Republic.

The GenuineCheck.exe tool used to bypass the check is meant to provide an alternative way for users to prove that their copy of Windows is genuine. The primary Windows Genuine Advantage checking mechanism uses ActiveX, which is not supported in all Web browsers.
GenuineCheck generates a code that can subsequently be used to validate a pirated copy of Windows. However, a PC running a legitimate version of Windows is required to run the GenuineCheck tool.

The threat is mitigated because the keys generated by the GenuineCheck tool expire "rapidly," - Microsoft representative.
Consequently, it would not do anyone much good to put up a Web page with a list of keys. Still, somebody would be able to generate a key and use it immediately on a PC with a pirated copy, or pass it on to a friend.
"This is more of an individual method of pirating. We don't see this as too different from people who take legitimate software, burn it to a CD and distribute it to their friends that way," - Microsoft representative.

Microsoft's Download Centre and Windows Update Web sites offer applications such as Windows Media Player and the Windows AntiSpyware product, as well as security updates for Microsoft products. The trick with the GenuineCheck tool works only on Download Centre, according to Microsoft.
When the Windows Genuine Advantage pilot program began last year, it was purely optional, with no benefit for verifying one's operating system and no penalty if the OS was found not to be genuine. Microsoft has gradually expanded the piracy check and is now withholding downloads for users of some international versions of Windows XP.

Er, but it must be stressed that Microsoft is not blocking access to any updates, in particular to Windows XP Service Pack 2, which the company is encouraging all customers to upgrade to. The company is not requiring customers to have a genuine copy of Windows to get SP2, though it has blocked a few registration codes that have been known for several years as pirated.

Micro$oft.com

__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.



Create your own FREE Forum
Report Abuse
Powered by ActiveBoard