Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-20-2009, 22:17
ketan ketan is offline
Friend
 
Join Date: Mar 2005
Posts: 157
Rept. Given: 0
Rept. Rcvd 19 Times in 10 Posts
Thanks Given: 8
Thanks Rcvd at 150 Times in 75 Posts
ketan Reputation: 19
IDA watermarking(s) and possibility of license file generation...

As of IDA latest public release (ie. v5.4.0.921),
following file+folders are watermarked...

/ida.key
/ida.wll
/loaders/*.*
/procs/*.*

Above info is gathered by looking at ida.key date.

Moreover no file is packed or obfuscated in any way,
this will allow to analyze IDA itself.

The registered user name is tagged in MS-DOS STUB portion of the watermarked executables.

So there are lot of possibilities to make a cracked version of IDA.

Key Pointers
=========
- Possibility to generate legitimate ida.key files,
// 'coz recently we seen awesome winrar solution

- Compare 2 identical version/edition of IDA to findout exect differences
Reply With Quote
  #2  
Old 03-21-2009, 03:52
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
My friend ...the problem is to get 2 identical version/edition of IDA...
how would like to share his one ?????!!!!!!!!
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
  #3  
Old 03-21-2009, 04:31
tofu-sensei tofu-sensei is offline
Friend
 
Join Date: Jul 2004
Posts: 113
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 4
Thanks Rcvd at 24 Times in 13 Posts
tofu-sensei Reputation: 15
Quote:
Originally Posted by ketan View Post
- Possibility to generate legitimate ida.key files,
// 'coz recently we seen awesome winrar solution
now that's a non sequitur
Reply With Quote
  #4  
Old 03-22-2009, 09:02
wtbw
 
Posts: n/a
There's no reason that comparing two would be enough... could be some things common to any two different copies but not any others.

Back when versions were being leaked and people tried to patch out their IDs Pierre would quote that 98% of the watermarks were left or so. Ilfak's not stupid, I'm sure he's come up with something quite crafty and not easily resolveable to an unidentifiable but still functional version.

Disclaimer: Haven't looked at it in any detail. I'm a big IDA fan and paid up user so I don't want to hurt them ;-)
Reply With Quote
  #5  
Old 03-22-2009, 21:47
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 971
Rept. Given: 70
Rept. Rcvd 431 Times in 101 Posts
Thanks Given: 83
Thanks Rcvd at 405 Times in 127 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
it's enough to hide the watermark in the instruction execution flow or in the data structure to create an almost impossible to un-watermark program, but there are hundred different ways to software watermark a program. Watermarking if properly done is one of the most efficient protection strategies (of course you must assume, like for IDA, that users can be threatened removing their licenses, if you catch their leaked copies on the net): it's easy to implement and doesn't complicate development, it's quite difficult to completely remove it.
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com
Reply With Quote
  #6  
Old 03-24-2009, 13:13
rcer rcer is offline
Friend
 
Join Date: Dec 2008
Posts: 171
Rept. Given: 5
Rept. Rcvd 9 Times in 8 Posts
Thanks Given: 6
Thanks Rcvd at 30 Times in 22 Posts
rcer Reputation: 9
WTWB

you mentioned that you are a paid user of IDA Pro.
Which version do you have, and is it the standard or Pro one?

Because I tried to buy a license for IDA and the only option they offer for private persons is the a "IDA Pro Standard Base Named license"

RCER
Reply With Quote
  #7  
Old 03-24-2009, 21:41
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,116
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 110
Thanks Rcvd at 220 Times in 126 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
I looked recently and it did not seem possible for a private person to buy any version of IDA, at least in the EU. VAT registration number is a mandatory part of the order form.

Git
Reply With Quote
  #8  
Old 03-24-2009, 22:20
sf42 sf42 is offline
Friend
 
Join Date: Feb 2003
Posts: 123
Rept. Given: 23
Rept. Rcvd 28 Times in 13 Posts
Thanks Given: 28
Thanks Rcvd at 103 Times in 37 Posts
sf42 Reputation: 28
Quote:
Originally Posted by Git View Post
I looked recently and it did not seem possible for a private person to buy any version of IDA, at least in the EU. VAT registration number is a mandatory part of the order form.

Git
Creating a company and receiving a VAT number costs 65€ where I live.
Reply With Quote
  #9  
Old 03-25-2009, 07:41
wtbw
 
Posts: n/a
rcer: I have an Advanced named license. I bought a Standard licence as a student, and upgraded to Advanced while it was still Datarescue.

Git: In the past, I've just left that blank.

Generally they're quite helpful if you e-mail them :-)

(Actually, I think I expired recently, I should probably upgrade...)
Reply With Quote
  #10  
Old 03-25-2009, 19:50
rcer rcer is offline
Friend
 
Join Date: Dec 2008
Posts: 171
Rept. Given: 5
Rept. Rcvd 9 Times in 8 Posts
Thanks Given: 6
Thanks Rcvd at 30 Times in 22 Posts
rcer Reputation: 9
Git,

VAT number is not mandatory, if you don't have one, they will still sell you IDA, but charge you an additional 18.5% VAT.

regards
Reply With Quote
  #11  
Old 03-26-2009, 01:33
sf42 sf42 is offline
Friend
 
Join Date: Feb 2003
Posts: 123
Rept. Given: 23
Rept. Rcvd 28 Times in 13 Posts
Thanks Given: 28
Thanks Rcvd at 103 Times in 37 Posts
sf42 Reputation: 28
Ok, so the only thing left is to pool money and buy IDA Advanced license from Datarescue If for example 50 members will join the cost per person will be miniscule...
Reply With Quote
  #12  
Old 03-27-2009, 06:39
Sergey Nameless
 
Posts: n/a
ru-board tried it before. Unfortunately people have money problems ;-)
Reply With Quote
  #13  
Old 03-27-2009, 13:37
rcer rcer is offline
Friend
 
Join Date: Dec 2008
Posts: 171
Rept. Given: 5
Rept. Rcvd 9 Times in 8 Posts
Thanks Given: 6
Thanks Rcvd at 30 Times in 22 Posts
rcer Reputation: 9
Talking

And also don't forget that the one who buys IDA and then uploads it to the forum will be blacklisted by Hexrays for the rest of his life
Reply With Quote
  #14  
Old 03-30-2009, 07:57
LaBBa LaBBa is offline
VIP
 
Join Date: Jul 2003
Posts: 150
Rept. Given: 0
Rept. Rcvd 16 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 11 Times in 11 Posts
LaBBa Reputation: 16
oh no! just don't blacklist me
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 06:51.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )