How Was Windows 7 Hacked??
Posted by Ali Reda | Posted in | Posted on 12/13/2010
Windows 7 - as you know - can be permanently activated with OEM style instant offline activation which will pass Windows Genuine Advantage (WGA) validation but how did this happen?
All you need to activate Windows 7 as OEM is just these things.
1) SLIC 2.1 (Software Licensing Table) in your BIOS.
2) OEM Certificate Matching Bios.
3) OEM-SLP Key matching your Edition of Windows.
At first Windows 7 Ultimate OEM DVD ISO from Lenovo was leaked and posted on Chinese forum. The ISO was quickly grabbed to retrieve boot.wim, which was then used to retrieve the OEM-SLP product key and OEM certificate for Windows 7 Ultimate. After extracting the OEM certificate and OEM product key, it’s confirmed that Windows 7 uses the same digitally signed OEM certificate (in .xrm-ms extension) that is been used in Windows Vista. Windows Vista OEM cert can be used in Windows 7.
Steps
- OEMID part of SLIC table in BIOS specified by the OEM munfacturer.
- OEMTableID part of SLIC table in BIOS specified by the OEM munfacturer.
- The OEM sends the public key + its own OEMID to Microsoft, in order to be signed using Microsoft private key and This becomes the OEM certificate.
- The Windows Marker is also a digital certificate that is generated by taking into account the OEMID + OEMTableID. It is signed by the OEM by using the private key that matches the public key.
BIOS Modding
The SLIC 2.1 can be modded into BIOS physically (hardmod or biosmod - flashing the bios) which is a permenant way or been emulated during Windows boots up (softmod) using loaders like Daz loader which the loader code in the boot code in the MBR (Master Boot Record) it even emulates SLIC 2.1 although the actual BIOS has SLIC 2.0 so no need at all to risk flashing the BIOS . Various SLIC 2.1 BIN has been retrieved from various notebook computer that shipped with new SLIC 2.1 in BIOS to support the free Windows 7 Upgrade Option from Windows Vista.
.
Comments (0)
Post a Comment