Language Selection

English French German Italian Portuguese Spanish

Another way past Windows antipiracy found

Filed under
Microsoft

The check is meant to prevent people with pirated copies of the operating system from downloading additional software from Microsoft. By changing a setting in a Microsoft validation tool called "GenuineCheck.exe," it's possible to generate a code that will validate the Windows software on a machine as genuine even if it is pirated, according to a Web site publicized on Thursday in a posting to the popular Full Disclosure security mailing list.

Microsoft would not confirm that the method works, but the software maker is investigating the issue, a company representative said. "It is not a surprise for us that those who never intended to pay for software would try to find some way to circumvent Windows Genuine Advantage," the representative said.

Microsoft last week made the Windows piracy check mandatory for all customers who want to download add-ons for Windows XP and 2000. The effort, dubbed Windows Genuine Advantage, requires users to verify that they have a legitimate copy of the operating system before they can get files from Microsoft's download Web sites.

Tricking the check

For the software maker, the news could be another episode of people finding a way to get around WGA. Last week, several Web sites said it was possible to bypass the piracy lock by several means, including pasting a JavaScript string into the Web browser. Earlier this year, during WGA's pilot phase, a security researcher outlined another way to trick the check.

The GenuineCheck.exe tool is meant to provide an alternative way for people to prove that their copy of Windows is an official Microsoft version. The primary WGA checking mechanism uses ActiveX, which is not supported in all Web browsers. The popular open-source Firefox Web browser, for example, does not support ActiveX.

"To make the validation experience as user-friendly as possible, Microsoft engineered a process that enables customers to validate their systems easily, and unfortunately, unscrupulous users are able to exploit that," the Microsoft representative said.

According to the Thursday posting, all a PC user apparently has to do to have GenuineCheck.exe generate a valid code on a machine with pirated Windows XP is to run it in Windows 2000 compatibility mode. This is done by downloading the tool, right-clicking on the file and selecting "properties." Then select the "compatibility" tab in the menu and change the compatibility mode.

If the method actually works, it may be short-lived. "Microsoft will be updating the validation system from time to time and plans to address these issues," the Microsoft representative said.

WGA is a stepped-up effort by Microsoft to increase the number of Windows users that are actually paying Microsoft for its software. At the moment, the company estimates that roughly a third of Windows copies worldwide are not legitimate.

By Joris Evers
CNET News.com

More in Tux Machines

Raspberry Pi analog input board has weather station option

RasPi.TV has Kickstartered a $12 “RasPiO Analog Zero” Raspberry Pi add-on board the size of an Raspberry Pi Zero. It offers eight 10-bit analog inputs. The RasPiO Analog Zero has surpassed its Kickstarter goals, and is available through May 31 starting at 8 Pounds ($12). Designed for reading up to eight analog sensors simultaneously on a Raspberry Pi, the add-on board is matched to the size of the 65 x 30mm Raspberry Pi Zero. However, it plugs into any Pi with a 40-pin expansion connector, and can work with older 26-pin Pi models with the help of an adapter. Read more

GhostBSD 10.3 Development Continues, Now with UEFI Support for 64-bit Platforms

Today, May 25, 2016, GhostBSD maintainer Eric Turgeon announced the general availability of the second Alpha release of the upcoming GhostBSD 10.3 operating system. Read more

Samsung still undecided on their Android Wear future

Yesterday the Internet lit up like a Christmas tree with the news that Samsung was no longer going to use Android Wear for any of its Smartwatches, but it seems that might not be quite the case. The report from Fast Company cited some Samsung executives confirming that Samsung was not looking into developing any further Android Wear products. Now, In a statement provided to the Engadget website Samsung states: “We disagree with Fast Company’s interpretation. Samsung has not made any announcement concerning Android Wear and we have not changed our commitment to any of our platforms.” Read more

Meizu Pro 5 Ubuntu Edition review

The Meizu Pro 5 is the latest flagship smartphone to run on Canonical’s Ubuntu operating system. Ubuntu is designed to work across all device types – including mobile, tablets, convertibles and desktops – using a common core code. This is similar to Microsoft Windows 10 Mobile. However, unlike Microsoft’s code, Ubuntu is totally open source and has largely been developed and improved by the desktop OS’s millions-strong user base. This means the OS is capable of evolving and changing at a great pace and has update cycles that would make most sysadmins weep. Read more