Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 09-11-2009, 06:11
o_o o_o is offline
Friend
 
Join Date: Oct 2005
Posts: 15
Rept. Given: 6
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 0 Times in 0 Posts
o_o Reputation: 0
Really impressive feat.
Anyone already tried to reverse the keygen?
Reply With Quote
  #17  
Old 09-13-2009, 18:00
kubik kubik is offline
Friend
 
Join Date: Oct 2004
Posts: 9
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
kubik Reputation: 0
Quote:
Originally Posted by o_o View Post
Really impressive feat.
Anyone already tried to reverse the keygen?
Main problem is search of private key ECDSA. Coding keygen isn't too hard. Reversing of keygen will not help.
Reply With Quote
  #18  
Old 09-19-2009, 07:23
berry berry is offline
Friend
 
Join Date: Nov 2005
Posts: 36
Rept. Given: 6
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 10
Thanks Rcvd at 2 Times in 1 Post
berry Reputation: 1
It's great. But if can crack the password of rar file would be greater.
Reply With Quote
  #19  
Old 09-19-2009, 08:47
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
seems EDCSA isn't secure anymore... anyone know about (public) holes? didn't read any news about it.
Reply With Quote
  #20  
Old 09-19-2009, 09:09
tofu-sensei tofu-sensei is offline
Friend
 
Join Date: Jul 2004
Posts: 113
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 4
Thanks Rcvd at 24 Times in 13 Posts
tofu-sensei Reputation: 15
aren't fff famous for stealing private keys off webservers?
Reply With Quote
  #21  
Old 09-20-2009, 03:09
nanobit nanobit is offline
Curious reverseR
 
Join Date: Nov 2008
Location: Cyberspace
Posts: 226
Rept. Given: 7
Rept. Rcvd 111 Times in 55 Posts
Thanks Given: 3
Thanks Rcvd at 30 Times in 14 Posts
nanobit Reputation: 100-199 nanobit Reputation: 100-199
well, D-Jester did a little research. see them here:
ECDSA Books
The Insecurity of the Elliptic Curve Digital Signature Algorithm with Partially Known Nonces

Last edited by nanobit; 09-20-2009 at 03:21.
Reply With Quote
  #22  
Old 09-20-2009, 03:35
tofu-sensei tofu-sensei is offline
Friend
 
Join Date: Jul 2004
Posts: 113
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 4
Thanks Rcvd at 24 Times in 13 Posts
tofu-sensei Reputation: 15
Quote:
Originally Posted by nanobit View Post
these are hardly relevant, though.
Reply With Quote
The Following User Gave Reputation+1 to tofu-sensei For This Useful Post:
  #23  
Old 09-27-2009, 23:03
NoFlexlm NoFlexlm is offline
Friend
 
Join Date: Jan 2009
Posts: 23
Rept. Given: 2
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
NoFlexlm Reputation: 0
Quote:
Originally Posted by Syoma View Post
I don't think that ECDSA is vulnerable. IMHO, it was attack on implementation.
p.s. Forget about hasp, man
That is true, so we still can do something to find the right way.
Reply With Quote
  #24  
Old 11-10-2009, 06:35
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
I also agree with the a few other guys that the attack was started over a vulnerable implementation of the algorithm.
propably somebody who found a weakness in the algorithm would rather say nothing at all or he/she would wrote a very detailed document on it, because of the importance of that fact.

just my 2 cents.

regards,
PAPiLLiON
Reply With Quote
  #25  
Old 11-19-2009, 05:26
arlequim's Avatar
arlequim arlequim is offline
IBMSecuritySystemsXForce
 
Join Date: Feb 2009
Location: Punta Entinas-Sabinar, ALMERIMAR
Posts: 295
Rept. Given: 52
Rept. Rcvd 317 Times in 104 Posts
Thanks Given: 46
Thanks Rcvd at 193 Times in 63 Posts
arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399
I'm thinking ... SeVen will be able to keygen CRO 239 bits (120 chars ECC) Flexlm target licenses??? Atm LND and ZWT cant do that, or not?

see more here
Code:
http://www-curri.u-strasbg.fr/documentation/calcul/doc/ProPack/3SP1/docs/doc/lmsgi-9.2.3/flexprog/chap15.htm
Reply With Quote
  #26  
Old 11-19-2009, 23:37
Asus Asus is offline
VIP
 
Join Date: Feb 2005
Posts: 594
Rept. Given: 122
Rept. Rcvd 27 Times in 13 Posts
Thanks Given: 147
Thanks Rcvd at 94 Times in 35 Posts
Asus Reputation: 28
LND can do almost FlexLM with some experience reversers Legends Never Die
Reply With Quote
  #27  
Old 11-20-2009, 01:35
arlequim's Avatar
arlequim arlequim is offline
IBMSecuritySystemsXForce
 
Join Date: Feb 2009
Location: Punta Entinas-Sabinar, ALMERIMAR
Posts: 295
Rept. Given: 52
Rept. Rcvd 317 Times in 104 Posts
Thanks Given: 46
Thanks Rcvd at 193 Times in 63 Posts
arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399
Quote:
Originally Posted by Asus View Post
LND can do almost FlexLM with some experience reversers Legends Never Die
thanks for reply but i think that is not right, because LND cracks Pro/Engineer with license.dat + patch, and this is not really *pure* keygening
Reply With Quote
  #28  
Old 11-20-2009, 04:47
merfy merfy is offline
Friend
 
Join Date: Feb 2009
Posts: 8
Rept. Given: 9
Rept. Rcvd 2 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
merfy Reputation: 2
keygen by FFF works 100% with version 4.2.12.4
_http://narod.ru/disk/12146877000/The.Bat!.v4.2.9.1_KEYGEN-FFF.zip.html
_http://rapidshare.com/files/309364279/The.Bat_.v4.2.12.4_KEYGEN-FFF.zip
Reply With Quote
  #29  
Old 11-24-2009, 22:05
dirkmill dirkmill is offline
Friend
 
Join Date: Jul 2004
Posts: 23
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
dirkmill Reputation: 0
Quote:
Originally Posted by arlequim View Post
I'm thinking ... SeVen will be able to keygen CRO 239 bits (120 chars ECC) Flexlm target licenses??? Atm LND and ZWT cant do that, or not?
If FFF/SeVen did indeed break ECDSA on sect163k1 they should (in theory) be able to generate licenses with LM_STRENGTH_163BIT considering the following from the flexlm headers
Code:
#define LM_PUBKEY_CURVE113BIT 	sect113r1
#define LM_PUBKEY_CURVE163BIT 	ec163a02  // (a.k.a  sect163k1)
#define LM_PUBKEY_CURVE239BIT 	ec239a03  // (a.k.a. sect239k1)
IMHO it is much more likely that Rarlabs made a poor choice of privkey/pubkey or have other implementation problems whereas
Macrovision/Acresso/Flexera bought their ECC/ECDSA-implementation from Certicom, a respected(?) company dealing exclusively in high security software products...

So to answer your question: I personally don't think we are going to see keygenned flexlm CRO/TRL SIGN2 licenses anytime soon ...

cheers,
dirkmill
Reply With Quote
  #30  
Old 11-25-2009, 02:13
arlequim's Avatar
arlequim arlequim is offline
IBMSecuritySystemsXForce
 
Join Date: Feb 2009
Location: Punta Entinas-Sabinar, ALMERIMAR
Posts: 295
Rept. Given: 52
Rept. Rcvd 317 Times in 104 Posts
Thanks Given: 46
Thanks Rcvd at 193 Times in 63 Posts
arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399
Hello Dirkmill, thanks for reply.
After this result we can compare SeVen with other great keygeners on the past like Dimedrol. But i think you right, probably the choice of WinRAR keys is really poor. Cracking of FlexLM CRO protected applications will be harder of course, maybe it is impossible today. But who knows, freaks of nature (like Se7en) are ready to attack. We will see, alto this is another history.
Bye!
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 01:10.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )