WAT (antipiracy update) released unofficaly....official launch at 17/02

Discussion in 'Windows 7' started by SoLoR, Feb 1, 2010.

  1. Yen

    Yen Admin
    Staff Member

    May 6, 2007
    13,081
    13,979
    340
    That would 'fit' to my guess.....(I hadn't a look at WAT yet)...the manufacturer string of the mobo is usually located at low address range 'shadowed from Bios' <= 1Mbyte...(0xC0000 to 0xDFFFF and 0xE0000 to 0xFFFFF)...screen messages at P.O.S.T. also (SLP1.0 ranges are valid there as well, at second range)....this address range is read only after P.O.S.T....a loader would have trouble to write in there, because it's Northbridge dependent to set a special bit to write.
    Not sure how they want to identify mobos that are not officially SLP licensed....blacklist?

    .........anyway to read out the chipset and hardwareIds would be more effective...SLI licenses (Nvidia) are working that way....solution (besides a DSDT mod) is to patch the HAL.dll to retrieve chipsetIds of your choice..
    anyway....nothing more than speculations
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. Elle233

    Elle233 MDL Member

    Aug 26, 2009
    200
    17
    10
  3. MasterDisaster

    MasterDisaster MDL Expert

    Aug 29, 2009
    1,256
    674
    60
    GetSystemFirmwareTable is a function in kernel32.dll that retrieves ACPI tables such as FACP, APIC, SSDT, SLIC and so on. It can also retrieve the Raw SMBIOS data and dumps physical memory address data from 0xC0000 to 0xDFFFF and 0xE0000 to 0xFFFFF (this part has SLP strings).
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. Elle233

    Elle233 MDL Member

    Aug 26, 2009
    200
    17
    10
    What's the implication of this for BIOS mods?
     
  5. Daz

    Daz MDL Developer / Admin
    Staff Member

    Jul 31, 2009
    9,534
    67,254
    300
    #105 Daz, Feb 5, 2010
    Last edited: Feb 5, 2010
    MD is right, the API function could just be a harmless check to simply read the SLIC and compare it.

    If you look at Everest that can mark some things as emulated and sometimes it can't tell the difference, it's all based off the SLIC address which if anything is a very poor thing to base validation off and I would be surprised if MS were to flag the "maybe modified" users without an accurate finding.

    It will be funny when Hazar's RemoveWAT actually does remove the standalone WAT update, because thats all it is. A few files that are not even required for Windows 7 to run and can easily be deleted and/or patched :p
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. MasterDisaster

    MasterDisaster MDL Expert

    Aug 29, 2009
    1,256
    674
    60
    Probably nothing. ;)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. alexus

    alexus MDL Novice

    Oct 2, 2009
    25
    0
    0
    what is this???
     
  8. Stannieman

    Stannieman MDL Guru

    Sep 4, 2009
    2,232
    1,818
    90
    This my friend, is what will try to stop us from running windows without paying for it.
    But don't worry, there's always a workaround for everything.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. Yen

    Yen Admin
    Staff Member

    May 6, 2007
    13,081
    13,979
    340
    I'm not sure if that API function is able to retrieve the ACPITable's memory addresses. Since some bios mod methods are using 'unusual' addresses it could be possible to detect a biosmod. Also to retrieve the raw SMBIOS data and to verify them could be a way to detect modded bioses..anyway M$ has to be very careful not to mark official licenses being 'modded'...all this can be circumvented by a new biosmod and a dynamically allocated SLIC....and a new string placed at mainbiosmodule to fool the verification again....

    What makes me believing that additional checks are not easy to perform for M$ is the fact that the licensing is specified. It's clearly described what has to match to get it valid. It are the OEMIds and TABLEIds of the RSDT table or if present the IDs of XSDT that have to match the one of the SLIC.... NO OTHER table....any additional check would mean to extend the specification of the license...
    So possible would be the address verification of the tables without to extend the licensing specification...although there are no ranges excluded by the specification....

    Interesting....and means probably nothing..yes..
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. Brainsuck

    Brainsuck MDL Addicted

    Oct 9, 2009
    676
    157
    30
    same thing that paymyrent said what dont you understand about service pack 1?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. OEM-USER

    OEM-USER Guest

    Brainsuck please look at my signature. :spacecraft:
     
  12. Daz

    Daz MDL Developer / Admin
    Staff Member

    Jul 31, 2009
    9,534
    67,254
    300
    #112 Daz, Feb 6, 2010
    Last edited: Feb 7, 2010
    @ Brainsuck
    SP1 is just a service pack, it installs most of the updates in just a "pack" form to save download time... that and it can sometimes contain a few improvements. At the end of the day though it's just as easy to remove the files from the service pack or patch them to always return valid. I mean why release WAT as a standalone if you think SP1 will integrate it into the system more? It won't because MS will constantly have to be updating WAT and like XP's WGA it can be stripped from the system or modified. So simply put service pack 1 means nothing and if you think otherwise then you will only end up being proven wrong :rolleyes:

    MS can't fix all bugs, MS left Windows 7 as vulnerable to the same exploits Vista had and they were perfectly aware of that so I personally think whatever MS does there will always be a way around activation until they drastically change the whole activation system.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  13. armada

    armada MDL Addicted

    Dec 8, 2007
    857
    209
    30
    so we still think bios mods will be fine with the new wat then?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. ennio

    ennio Guest

    Yes.............
     
  15. armada

    armada MDL Addicted

    Dec 8, 2007
    857
    209
    30
    ok great with everyone talking about the acpi tables etc i was unsure if there was anything new on it.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. ennio

    ennio Guest

    Relax, MS is always full of s***, I mean big stories how they will correct something, and then you will see that even loaders will survives after some modification. I once told Hazar that I thought Microsoft HAL was smarter, but it is not.
     
  17. Yen

    Yen Admin
    Staff Member

    May 6, 2007
    13,081
    13,979
    340
    To read out data only and to decide about are different matters. M$ is probably planning to read out more info about the bios / ACPITables. If they can use it to differentiate / detect a biosmod is the other question.

    Yes...
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. secr9tos

    secr9tos MDL Addicted

    Jul 28, 2009
    999
    133
    30
    And in case WAT makes our mods useless, which I don't believe actually, we would need to patch WAT so that the info it reports to m$ is always "correct"
     
  19. urie

    urie Moderator
    Staff Member

    May 21, 2007
    9,039
    3,388
    300
    Do you realy believe that MS can't detect file removal WAT bad enought the panic about bios mods, even DMI which have never been knocked out yet. Scare mongering people again no Prophets here we have to wait and see but all bets are on bios mods. at the end of the day it is MS OS system not ours we just rent it so Big Bill can get his money :)
     
  20. RanCorX2

    RanCorX2 MDL Addicted

    Jul 19, 2009
    999
    554
    30
    still activated here with hazar's loader.