Full Disclosure mailing list archives
Product activation is exploitable
From: "Geoincidents" <geoincidents () getinfo org>
Date: Sat, 6 Sep 2003 19:04:29 -0400
So I'm reading this story http://www.nccomp.com/sysadmin/dell.html about a company who laid off their admin and he took all their product keys and posted them on the internet. Well to make a long story short, somehow applying a hotfix caused the software to deactivate (it has to have a deactivation feature or what good is it?) and require activation again which of course was impossible since MS shut those numbers down. It got to thinking, what if the dcom worm had grabbed the product key from [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion] "ProductKey"="XXXXX-XXXXX-XXXXX-XXXXX-XXXXX" or ProductID="XXXXX-OEM-XXXXXXX-XXXXX" and posted it to a dozen random newsgroups? According to the EULA Microsoft has the right to shut down every one who becomes infected and compromised in this manner. Sure looks like a security issue to me, product activation makes this registry entry which allows all users full read access a dangerous thing to have laying around unprotected. Geo. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Anybody know what Sobig.F has downloaded? Brent J. Nordquist (Sep 01)
- <Possible follow-ups>
- RE: Anybody know what Sobig.F has downloaded? Ferris, Robin (Sep 02)
- RE: Anybody know what Sobig.F has downloaded? Nick FitzGerald (Sep 06)
- Product activation is exploitable Geoincidents (Sep 06)
- Re: Product activation is exploitable w g (Sep 06)
- RE: Product activation is exploitable Rick Kingslan (Sep 06)
- Re: Product activation is exploitable Kristian Hermansen (Sep 06)
- Re: Product activation is exploitable Lan Guy (Sep 07)
- RE: Product activation is exploitable Rick Kingslan (Sep 07)
- RE: Product activation is exploitable Justin Shin (Sep 07)
- RE: Anybody know what Sobig.F has downloaded? Nick FitzGerald (Sep 06)
- Re: Product activation is exploitable Geoincidents (Sep 07)
- RE: Product activation is exploitable Rick Kingslan (Sep 07)