[Full-disclosure] Defeating Microsoft WGA Validation Check

From: Debasis Mohanty (mail_at_hackingspirits.com)
Date: 05/23/05

  • Next message: Martin Pitt: "[Full-disclosure] [USN-132-1] ImageMagick vulnerabilities"
    To: <full-disclosure@lists.grok.org.uk>
    Date: Mon, 23 May 2005 15:16:22 +0530
    
    
    

    There is lot of hype about WGA (Windows Genuine Advantage) when Microsoft
    builds functionality in its few of the public beta products to conduct a
    genuine product check before the product gets installed. MS products or
    tools with WGA check enabled can only be installed on a valid / genuine copy
    of MS Windows XP. Incase it is a pirated copy then the product denies to
    install.

     

    If you are aware of Microsoft WGA validation then you can directly jump in
    to the PoC section otherwise it is advisable to read on WGA and what it does
    before reading the PoC.

     

    To know more about WGA, refer to the following Microsoft link:

    http://www.microsoft.com/genuine/downloads/FAQ.aspx?displaylang=en

     

    Defeating Microsoft WGA Validation Check - Proof of Concept (PoC)

    This PoC explains how Microsoft WGA validation check can be defeated and any
    Microsoft product with the WGA validation feature can be run and installed
    on machines running pirated copy of Windows XP. To bypass WGA validation
    check, one can run "GenuineCheck.exe" file on a machine running a copy of an
    authentic Windows XP for generating a key code. This key code generated on
    the machine running genuine copy of Win XP can be used to circumvent the WGA
    check on the machine running a pirated copy of Win XP.

     

    A detailed approach can be downloaded from the following link -

    http://www.hackingspirits.com/vuln-rnd/defeating-wga-check.zip

     

    Microsoft in its reply to my mail specified that "The generated code is
    partly made up of a timestamp, which would prevent use after a short
    period". However, I checked this on a pirated copy of Windows XP Pro and
    installed couple of public beta products and tools for testing purpose. They
    are still up and running since past 1.5 months.

     

    Incase, anyone is going to try this out on their pirated versions of Win XP
    then do let me know if the installed product make noise after certain time
    period.

     

     

    * Debasis Mohanty

    * www.hackingspirits.com <http://www.hackingspirits.com/>

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Martin Pitt: "[Full-disclosure] [USN-132-1] ImageMagick vulnerabilities"

    Relevant Pages

    • WARNING LONG - Brian Livingstons take on Windows Genuine Advantage
      ... Genuine Advantage is Microsoft spyware ... Some tech writers have said categorizing WGA as spyware is arguable. ... It causes serious problems for some legitimate Windows users and was sprung on customers with no notice other than a press release the day before. ... If an instance of Windows doesn't seem to have a valid license, display notices to the user and prevent any updates being downloaded from Microsoft.com except security upgrades that are rated "Critical." ...
      (alt.sys.pc-clone.dell)
    • Re: Windows Genuine Advantage - Big Brother is watching you
      ... Microsoft Provides Additional Clarity About Windows Genuine Advantage Notifications ... Some tech writers have said categorizing WGA as spyware is arguable. ...
      (microsoft.public.windowsupdate)
    • Re: WGAtray.exe (Windows Genuine Authentication) spyware. Can this be disabled?
      ... To disable WGA Notify, with minimal risk, download Sysinternals ... Microsoft discontinuance of supporting pirated versions of Windows ... I disable or remove their startup entries from the registry, ...
      (microsoft.public.windowsxp.general)
    • WGA - the most recent phase
      ... Microsoft has bowed to public pressure, releasing a version of WGA that no longer validates Windows using a server-side configuration ... Responding to pressure from irked Windows users, Microsoft released an updated version of its antipiracy program on Tuesday that changes the frequency with which the program checks for pirated or counterfeit copies of its client operating system. ... "Our customers have told us that they were disappointed with their WGA Notifications experience, and we have made an effort to improve that with this update," a company representative said in a statement. ...
      (alt.sys.pc-clone.dell)
    • Re: Is WGA used to violate your privacy or not?
      ... If WGA is touted to protect and respect the privacy of thos who use ... Windows, how could it do this without violating privacy?!? ... How does Microsoft use this information? ... the WGA to validate their copy - can they report it and possibly get a free ...
      (microsoft.public.windowsupdate)