Full Disclosure mailing list archives
RE: Product activation is exploitable
From: "Rick Kingslan" <rkingsla () cox net>
Date: Sun, 7 Sep 2003 11:40:54 -0500
Well, maybe on your systems. That's the product ID that MS might want to SUPPORT your system, but has nothing to do with Product Activation or the ability to shut it off, if MS so desires. Now, the DigitalProductID is a bit different - it DOES contain some information, but is only part of the piece that one would need. The key that is on the back of your CD case or the 25 AlphNum that is input for activation is NOT the ProductID. So, I'm still a bit puzzled over what the threat to security and the potential for someone to remotely (or locally for that matter, unless - of course, you've left the CD case next to the computer) retrieve any codes that could be used to shut down a group of systems. -rtk -----Original Message----- From: Geoincidents [mailto:geoincidents () getinfo org] Sent: Sunday, September 07, 2003 5:41 AM To: Rick Kingslan; full-disclosure () lists netsys com Subject: Re: [Full-disclosure] Product activation is exploitable
Interesting. But, I'm not sure how effective this would be, as everything that I've looked at (XP, 2003) doesn't have the actual WPA keys in the registry
In windows XP it's at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductID Geo. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: Anybody know what Sobig.F has downloaded?, (continued)
- RE: Anybody know what Sobig.F has downloaded? Ferris, Robin (Sep 02)
- RE: Anybody know what Sobig.F has downloaded? Nick FitzGerald (Sep 06)
- Product activation is exploitable Geoincidents (Sep 06)
- Re: Product activation is exploitable w g (Sep 06)
- RE: Product activation is exploitable Rick Kingslan (Sep 06)
- Re: Product activation is exploitable Kristian Hermansen (Sep 06)
- Re: Product activation is exploitable Lan Guy (Sep 07)
- RE: Product activation is exploitable Rick Kingslan (Sep 07)
- RE: Product activation is exploitable Justin Shin (Sep 07)
- RE: Anybody know what Sobig.F has downloaded? Nick FitzGerald (Sep 06)
- Re: Product activation is exploitable Geoincidents (Sep 07)
- RE: Product activation is exploitable Rick Kingslan (Sep 07)
- RE: Anybody know what Sobig.F has downloaded? Ferris, Robin (Sep 02)
