Windows 8/2012 sideloading crack

Discussion in 'Windows 8' started by kost, Oct 30, 2012.

Tags:
  1. KNARZ

    KNARZ MDL Addicted

    Oct 9, 2012
    895
    482
    30
  2. VBTheory

    VBTheory MDL Novice

    Oct 31, 2012
    6
    0
    0
    Did anybody manage to crack reckless racing ultimate or rocket riot 3d or hydro thunder hurricane?
    Please let me know how you did so, thanx ;) :worthy:
     
  3. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    #23 kost, Nov 1, 2012
    Last edited: Nov 1, 2012
    (OP)
    I managed to disable Windows store signature checks and spoof license responses from microsoft

    I change license type from Trial to Full, delete expiry date and force WSService to save it into tokens.dat
    But I don't know how to test if applications actually expire.

    Even if I do no modifications to license - changing system date does not expire them.
    I need any application where I can reproduce trial effects, may be some feature locks.

    Anyone know such app ?

    Yes, hydro thunder is one of such apps. Unfortunately, simply changing type to Full cause error.
    I suppose some additional information should be present in the license when app is bought.
    I need to gather larger statistics.
     
  4. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    For curious guys I post protocol capture of licensing requests.
    You can see yourself WHAT KIND OF INFORMATION IS SENT TO MICROSOFT.
    Some personal data - computer name, system manufacturer.

    https :// lic.apps.microsoft.com

    *** Purchase

    GET /Commerce/Purchase/6.2.9200-1/615/p/b340039d-9924-49ce-88c8-80d4d69a266f/t/2/channel/10005001/locale/en-US/market/RU/al/en-US HTTP/1.1

    *** Response

    <?xml version="1.0" encoding="utf-8"?>
    <PurchaseResponse xmlns:xsd="http :// w w w.w3.org/2001/XMLSchema" xmlns:xsi="http :// w w w.w3.org/2001/XMLSchema-instance">
    <Success>true</Success>
    <ErrorCode>0</ErrorCode>
    <Redirect xsi:nil="true" />
    <PCSIsNotArmSupported xsi:nil="true" />
    <Result>
    <OfferPrice>45.00</OfferPrice>
    <TotalSalesTax>0</TotalSalesTax>
    <TotalTaxRate>0</TotalTaxRate>
    <TotalPrice>0</TotalPrice>
    <Currency>RUB</Currency>
    <CurrencySymbol>р.</CurrencySymbol>
    <TransactionId>66d3d721-d89d-4337-a089-f2177d9bcd54</TransactionId>
    <ServiceTicket>EwBgApVABAAUqPq18hpYHZBQFiQjg6Ywv8m8HEQAAU4RAlJnHh//MLDPcZzP/NvdF/aezjcZCHvRJy5FPzIFX0qeBDxM16ZtIMUa7BWidGzOtEeEbvD2P0BhWPgVmB1cgSoZ813OnhniHfN5jTy3iAa2BBxTmksAeBWfoF3UsPBNMl05rvV4R1VLfFqt5LgI6kfg8vidLMl7Dn2BDhFeHKGeUHj50C+WCjv2cdL5y2szGJ1qBtUhOioEpyJ9HWPyyLu258QJShY9t418RCUpGxYrt/RXSymsFNbb/ZJO0mXvPQWa1xAMk7JOXakKRswQyDUR6E5xhbEztUt+qt4sMmp1QDLZaHlwTCMqhiAzOzdYHDGMRUmvAIUwWOXsgyQDZgAACOY5p7h9BPu3MAGvrWenColNglOKJFOpqTffUVkXZleHLe+vIEi3vGCWR5lAJfpP+wqfuDXZ0FVzOVyXlkmr4WbiQzGuXRAcB2s33qsQQR7tgkLan8rR/y1UAmK/aNu/444qvsYuT8oumsf9/raNDNyBNlR93x//tyJnsmdX3WKaU5ZtJr+qkMbPo4Ev7TLOFn3fT3g0P9DF27Pr/yJcSpuDHrBij1TCMP8gy4FoWABOuTek91jQxTWqZlP378dLRl0XCfP5Y0WF7WN8BWrcJs2Q2fbNVvTeUGluqeffyb79AwNqR9IIPdI2Vwp3iUvR0pvksJIKdY0lwaQEJ+ndVeD40HFuCvqb+9bESWzzHVQs5ga7tKPkAKCWR3NK4iDHdQgqbCleAuz+Rpw+6cqYB8LuoWSmKfhpv59RXAE=&amp;p=</ServiceTicket>
    <ReleaseGuid>8adec589-005b-4834-b222-e714458ee730</ReleaseGuid>
    <ProductTileData>
    <Pt>
    <I>b340039d-9924-49ce-88c8-80d4d69a266f</I>
    <R>8adec589-005b-4834-b222-e714458ee730</R>
    <B>8adec589-005b-4834-b222-e714458ee730</B>
    <Pfn>2859fincooper.MagnificentCheckers_26jw83kfsfqtc</Pfn>
    <T>Magnificent Checkers</T>
    <Wr>3</Wr>
    <Ico>8adec589-005b-4834-b222-e714458ee730/Icon.21215.png</Ico>
    <Bg>#000000</Bg>
    <Fg>light</Fg>
    <R0 />
    <C>
    <I>3</I>
    <N>Games</N>
    </C>
    <Sc>
    <I>44</I>
    <N>Strategy</N>
    </Sc>
    <Typ>1</Typ>
    <Acc>false</Acc>
    <Dca>false</Dca>
    <Try>true</Try>
    <Tryd>1</Tryd>
    <Lud>2012-10-31T07:12:36.42-07:00Z</Lud>
    <Ats>
    <At>
    <N>Tammi</N>
    <Bg>#000000</Bg>
    <Fg>light</Fg>
    <Mai>App</Mai>
    <Logo>8adec589-005b-4834-b222-e714458ee730/AppTile.2.21215.24614.png</Logo>
    <Img>
    <T>1</T>
    <U>8adec589-005b-4834-b222-e714458ee730/AppTile.1.21215.24614.png</U>
    </Img>
    <Imgs>
    <Img>
    <T>1</T>
    <U>8adec589-005b-4834-b222-e714458ee730/AppTile.1.21215.24614.png</U>
    </Img>
    </Imgs>
    </At>
    </Ats>
    </Pt>
    </ProductTileData>
    <AlreadyOwned>false</AlreadyOwned>
    </Result>
    <TransactionId>66d3d721-d89d-4337-a089-f2177d9bcd54</TransactionId>
    </PurchaseResponse>


    -----------------------------------------------------------------------------------------------------


    *** Getting license

    POST /Commerce/Purchase/6.2.9200-1/615/p/b340039d-9924-49ce-88c8-80d4d69a266f/t/2/channel/10005001/locale/en-US/market/RU/al/en-US HTTP/1.1

    <?xml version="1.0" encoding="utf-8"?>
    <ConfirmBody>
    <TransactionId>66d3d721-d89d-4337-a089-f2177d9bcd54</TransactionId>
    <Price>45.00</Price>
    <DigitalMarker>
    <GenuineTicketError>0x80070422</GenuineTicketError>
    </DigitalMarker>
    <MachineId></MachineId>
    <challenge>
    <ClientInformation>
    <Version>1.0</Version>
    <ClientVersion>1.0.0.0</ClientVersion>
    <HardwareID>LgAAAAEAAgABAAEAAQABAAAAAQABAAEAliv+laQRDFzmt2IF/BTnIWOpITAAHA==</HardwareID>
    <SystemName>WIN-10RC2KGP7FU</SystemName>
    <SystemManufacturer>VMware, Inc.</SystemManufacturer>
    <SystemProductName>VMware Virtual Platform</SystemProductName>
    <MachineID>{A1492CCD-639F-42B5-A3B9-0A2F54E4ABDA}</MachineID>
    <N>4124325663</N>
    <SKU>7</SKU>
    </ClientInformation>
    <ProductID>{B340039D-9924-49CE-88C8-80D4D69A266F}</ProductID>
    </challenge>
    <SCM>
    <![CDATA[]]>
    </SCM>
    <SendReceipt>false</SendReceipt>
    </ConfirmBody>


    *** Response :

    <?xml version="1.0" encoding="utf-8"?>
    <PurchaseResponse xmlns:xsd="http :// w w w.w3.org/2001/XMLSchema" xmlns:xsi="http :// w w w.w3.org/2001/XMLSchema-instance">
    <Success>true</Success>
    <ErrorCode>0</ErrorCode>
    <Redirect xsi:nil="true" />
    <PCSIsNotArmSupported xsi:nil="true" />
    <Result>
    <OfferPrice>45.00</OfferPrice>
    <TotalSalesTax>0</TotalSalesTax>
    <TotalTaxRate>0</TotalTaxRate>
    <TotalPrice>0</TotalPrice>
    <Currency>RUB</Currency>
    <CurrencySymbol>р.</CurrencySymbol>
    <TransactionId>66d3d721-d89d-4337-a089-f2177d9bcd54</TransactionId>
    <ReleaseGuid>8adec589-005b-4834-b222-e714458ee730</ReleaseGuid>
    <ProductTileData>
    <Pt>
    <I>b340039d-9924-49ce-88c8-80d4d69a266f</I>
    <R>8adec589-005b-4834-b222-e714458ee730</R>
    <B>8adec589-005b-4834-b222-e714458ee730</B>
    <Pfn>2859fincooper.MagnificentCheckers_26jw83kfsfqtc</Pfn>
    <T>Magnificent Checkers</T>
    <Wr>3</Wr>
    <Ico>8adec589-005b-4834-b222-e714458ee730/Icon.21215.png</Ico>
    <Bg>#000000</Bg>
    <Fg>light</Fg>
    <R0 />
    <C>
    <I>3</I>
    <N>Games</N>
    </C>
    <Sc>
    <I>44</I>
    <N>Strategy</N>
    </Sc>
    <Typ>1</Typ>
    <Acc>false</Acc>
    <Dca>false</Dca>
    <Try>true</Try>
    <Tryd>1</Tryd>
    <Lud>2012-10-31T07:12:36.42-07:00Z</Lud>
    <Ats>
    <At>
    <N>Tammi</N>
    <Bg>#000000</Bg>
    <Fg>light</Fg>
    <Mai>App</Mai>
    <Logo>8adec589-005b-4834-b222-e714458ee730/AppTile.2.21215.24614.png</Logo>
    <Img>
    <T>1</T>
    <U>8adec589-005b-4834-b222-e714458ee730/AppTile.1.21215.24614.png</U>
    </Img>
    <Imgs>
    <Img>
    <T>1</T>
    <U>8adec589-005b-4834-b222-e714458ee730/AppTile.1.21215.24614.png</U>
    </Img>
    </Imgs>
    </At>
    </Ats>
    </Pt>
    </ProductTileData>
    <AlreadyOwned>false</AlreadyOwned>
    <LicensingResponse>
    <LicenseResponse Version="1" ErrorCode="0x0" LicensePage="0" InAppPage="0">
    <ServerInfoResponse>77u/PFNlcnZlcj48SW5mbyBOPSI0MTI0MzI1NjYzIj48TWFjaGluZUlEPmExNDkyY2NkLTYzOWYtNDJiNS1hM2I5LTBhMmY1NGU0YWJkYTwvTWFjaGluZUlEPjxDdXJyZW50VGltZT4yMDEyLTEwLTMxVDE3OjIzOjUyWjwvQ3VycmVudFRpbWU+PC9JbmZvPjxTaWduYXR1cmUgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvMDkveG1sZHNpZyMiPjxTaWduZWRJbmZvPjxDYW5vbmljYWxpemF0aW9uTWV0aG9kIEFsZ29yaXRobT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS8xMC94bWwtZXhjLWMxNG4jIiAvPjxTaWduYXR1cmVNZXRob2QgQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAxLzA0L3htbGRzaWctbW9yZSNyc2Etc2hhMjU2IiAvPjxSZWZlcmVuY2UgVVJJPSIiPjxUcmFuc2Zvcm1zPjxUcmFuc2Zvcm0gQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwLzA5L3htbGRzaWcjZW52ZWxvcGVkLXNpZ25hdHVyZSIgLz48L1RyYW5zZm9ybXM+PERpZ2VzdE1ldGhvZCBBbGdvcml0aG09Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvMDQveG1sZW5jI3NoYTI1NiIgLz48RGlnZXN0VmFsdWU+TTlUb3NVNVZqWXV3K29KMmVad1hsMEpVcHRrZGhjNUUyd2lQN0d5RzN1dz08L0RpZ2VzdFZhbHVlPjwvUmVmZXJlbmNlPjwvU2lnbmVkSW5mbz48U2lnbmF0dXJlVmFsdWU+V2tFS29NQTZaUTFqMm9OQXlyVUhBcm1MRFkzQzZhL05vSzl3bWsyK0k5cG1hejlzRHRLQTNnd2xrZ0UwdFlneDd1ejhMUWI5UnBrTkhEWUZQb1dCU29TckdhdUNjNHloTzMzNTNiUkIreFd1VzR5QUxDbkQ2VExsdEl1aklhY1Q2VHlyNjdWY1l4eHpVYmFjTDM2dDB4OGpodWdlRHEreFN4eWx6c05iQWZSSzNIOHFaZTdlVEVqOHhGa2ZwbEZvS0MyWHlUbGREVnB2RlNvQ2ZwREozandadDRqeHhzSHV2T254dm5WbGZxNUd3T29kZGlRNzFxdW5zZTdCVW1DOHJ2MmJ0QVVvemljSExsTmZNeTNRSHRSNmJDZzV6Ti9NMkIrN1NYUDZCeU9aazhrY2tLelNnbUN2ZW9wbGYvdHZ2MXNHd2VadENwelBnSEF5ZXM5djhnPT08L1NpZ25hdHVyZVZhbHVlPjwvU2lnbmF0dXJlPjwvU2VydmVyPg==</ServerInfoResponse>
    <UpdatedLicense LicensesAllDone="1" InAppLicenseAllDone="1">
    <License>77u/PExpY2Vuc2UgVmVyc2lvbj0iMSIgeG1sbnM9InVybjpzY2hlbWFzLW1pY3Jvc29mdC1jb206d2luZG93czpzdG9yZTpsaWNlbnNpbmc6bHMiPjxCaW5kaW5nIEJpbmRpbmdfVHlwZT0iTWFjaGluZSI+PFByb2R1Y3RJRD5iMzQwMDM5ZC05OTI0LTQ5Y2UtODhjOC04MGQ0ZDY5YTI2NmY8L1Byb2R1Y3RJRD48UEZNPjI4NTlmaW5jb29wZXIuTWFnbmlmaWNlbnRDaGVja2Vyc18yNmp3ODNrZnNmcXRjPC9QRk0+PEhhcmR3YXJlSUQ+WEFBQUFCTUFMZ0FBQUFFQUFnQUJBQUVBQVFBQkFBQUFBUUFCQUFFQWxpditsYVFSREZ6bXQySUYvQlRuSVdPcElUQUFIQTBBQWdBQkFRQUNCUUFEQVFBRUFnQUZBQUFHQVFBSEFBQUlCd0FKQXdBS0FRQUxBQUFNQndBPTwvSGFyZHdhcmVJRD48TWFjaGluZUlEPmExNDkyY2NkLTYzOWYtNDJiNS1hM2I5LTBhMmY1NGU0YWJkYTwvTWFjaGluZUlEPjxVc2VySUQ+N2ZmNDMxODFjODJmMjZlYTwvVXNlcklEPjwvQmluZGluZz48TGljZW5zZUluZm8gVHlwZT0iVHJpYWwiPjxJc3N1ZWREYXRlPjIwMTItMTAtMzFUMTc6MjM6NTJaPC9Jc3N1ZWREYXRlPjxMYXN0VXBkYXRlRGF0ZT4yMDEyLTEwLTMxVDE3OjIzOjUyWjwvTGFzdFVwZGF0ZURhdGU+PEV4cGlyYXRpb25EYXRlPjIwMTItMTEtMDFUMTc6MjM6NTJaPC9FeHBpcmF0aW9uRGF0ZT48L0xpY2Vuc2VJbmZvPjxTaWduYXR1cmUgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvMDkveG1sZHNpZyMiPjxTaWduZWRJbmZvPjxDYW5vbmljYWxpemF0aW9uTWV0aG9kIEFsZ29yaXRobT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS8xMC94bWwtZXhjLWMxNG4jIiAvPjxTaWduYXR1cmVNZXRob2QgQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAxLzA0L3htbGRzaWctbW9yZSNyc2Etc2hhMjU2IiAvPjxSZWZlcmVuY2UgVVJJPSIiPjxUcmFuc2Zvcm1zPjxUcmFuc2Zvcm0gQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwLzA5L3htbGRzaWcjZW52ZWxvcGVkLXNpZ25hdHVyZSIgLz48L1RyYW5zZm9ybXM+PERpZ2VzdE1ldGhvZCBBbGdvcml0aG09Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvMDQveG1sZW5jI3NoYTI1NiIgLz48RGlnZXN0VmFsdWU+ZEVxN01sUjU5K2ZtL3VaV3JVMml5K1oxVUg3elJONk1zMVNZa1ZvZFA2MD08L0RpZ2VzdFZhbHVlPjwvUmVmZXJlbmNlPjwvU2lnbmVkSW5mbz48U2lnbmF0dXJlVmFsdWU+TVYzeTNudmFXS09hKzZES283N2FxallMTFVBM0ZJbldzcnlXZDRBWG00VW9ocUJtY3M0YVJkZldNczJlM2J0NkN3Z01ZVUZqT2JzQy8wTHpGbmtOS0NtUnM1blh4aDJ4bjZSclgzaVkxRmZFT1VxQ1kra1hucWlweWxjT3lRVHJrd0c1R2lzUHh6aTlXVE5VbDZPUWhHU2VQMDBpeUFLUWFiOWM0OXZIMTBBMjFLSnhvWXFKRGlvOUV2bmJtdGgrOEo0SGJqblhKR0gwM1J0WlJzYWVROTlkaEIxZEpaNDcyRklyUThSUldTNC95Tk9BdGUyUHp0NFZoV2ptYnZhZzkvQThseFVKaXZZRjdkeUFtYm1aOXRveEZweTNSeXFvQ2hFOXNISFFOQjZlcG82ait1a0JkN29KeVYwcGhwQVBaZDRCMndOa0RhVG1SREZKMGgyUGl3PT08L1NpZ25hdHVyZVZhbHVlPjwvU2lnbmF0dXJlPjwvTGljZW5zZT4=</License>
    </UpdatedLicense>
    </LicenseResponse>
    </LicensingResponse>
    </Result>
    <TransactionId>66d3d721-d89d-4337-a089-f2177d9bcd54</TransactionId>
    </PurchaseResponse>




    *** ServerInfoResponse (base64) :


    <Server>
    <Info N="4124325663">
    <MachineID>a1492ccd-639f-42b5-a3b9-0a2f54e4abda</MachineID>
    <CurrentTime>2012-10-31T17:23:52Z</CurrentTime>
    </Info>
    <Signature xmlns="http :// w w w.w3.org/2000/09/xmldsig#">
    <SignedInfo>
    <CanonicalizationMethod Algorithm="http :// w w w.w3.org/2001/10/xml-exc-c14n#" />
    <SignatureMethod Algorithm="http :// w w w.w3.org/2001/04/xmldsig-more#rsa-sha256" />
    <Reference URI="">
    <Transforms>
    <Transform Algorithm="http :// w w w.w3.org/2000/09/xmldsig#enveloped-signature" />
    </Transforms>
    <DigestMethod Algorithm="http :// w w w.w3.org/2001/04/xmlenc#sha256" />
    <DigestValue>M9TosU5VjYuw+oJ2eZwXl0JUptkdhc5E2wiP7GyG3uw=</DigestValue>
    </Reference>
    </SignedInfo>
    <SignatureValue>WkEKoMA6ZQ1j2oNAyrUHArmLDY3C6a/NoK9wmk2+I9pmaz9sDtKA3gwlkgE0tYgx7uz8LQb9RpkNHDYFPoWBSoSrGauCc4yhO3353bRB+xWuW4yALCnD6TLltIujIacT6Tyr67VcYxxzUbacL36t0x8jhugeDq+xSxylzsNbAfRK3H8qZe7eTEj8xFkfplFoKC2XyTldDVpvFSoCfpDJ3jwZt4jxxsHuvOnxvnVlfq5GwOoddiQ71qunse7BUmC8rv2btAUozicHLlNfMy3QHtR6bCg5zN/M2B+7SXP6ByOZk8kckKzSgmCveoplf/tvv1sGweZtCpzPgHAyes9v8g==</SignatureValue>
    </Signature>
    </Server>


    *** License (base64) :


    <License Version="1" xmlns="urn:schemas-microsoft-com:windows:store:licensing:ls">
    <Binding Binding_Type="Machine">
    <ProductID>b340039d-9924-49ce-88c8-80d4d69a266f</ProductID>
    <PFM>2859fincooper.MagnificentCheckers_26jw83kfsfqtc</PFM>
    <HardwareID>XAAAABMALgAAAAEAAgABAAEAAQABAAAAAQABAAEAliv+laQRDFzmt2IF/BTnIWOpITAAHA0AAgABAQACBQADAQAEAgAFAAAGAQAHAAAIBwAJAwAKAQALAAAMBwA=</HardwareID>
    <MachineID>a1492ccd-639f-42b5-a3b9-0a2f54e4abda</MachineID>
    <UserID>7ff43181c82f26ea</UserID>
    </Binding>
    <LicenseInfo Type="Trial">
    <IssuedDate>2012-10-31T17:23:52Z</IssuedDate>
    <LastUpdateDate>2012-10-31T17:23:52Z</LastUpdateDate>
    <ExpirationDate>2012-11-01T17:23:52Z</ExpirationDate>
    </LicenseInfo>
    <Signature xmlns="http :// w w w.w3.org/2000/09/xmldsig#">
    <SignedInfo>
    <CanonicalizationMethod Algorithm="http :// w w w.w3.org/2001/10/xml-exc-c14n#" />
    <SignatureMethod Algorithm="http :// w w w.w3.org/2001/04/xmldsig-more#rsa-sha256" />
    <Reference URI="">
    <Transforms>
    <Transform Algorithm="http :// w w w.w3.org/2000/09/xmldsig#enveloped-signature" />
    </Transforms>
    <DigestMethod Algorithm="http :// w w w.w3.org/2001/04/xmlenc#sha256" />
    <DigestValue>dEq7MlR59+fm/uZWrU2iy+Z1UH7zRN6Ms1SYkVodP60=</DigestValue>
    </Reference>
    </SignedInfo>
    <SignatureValue>MV3y3nvaWKOa+6DKo77aqjYLLUA3FInWsryWd4AXm4UohqBmcs4aRdfWMs2e3bt6CwgMYUFjObsC/0LzFnkNKCmRs5nXxh2xn6RrX3iY1FfEOUqCY+kXnqipylcOyQTrkwG5GisPxzi9WTNUl6OQhGSeP00iyAKQab9c49vH10A21KJxoYqJDio9Evnbmth+8J4HbjnXJGH03RtZRsaeQ99dhB1dJZ472FIrQ8RRWS4/yNOAte2Pzt4VhWjmbvag9/A8lxUJivYF7dyAmbmZ9toxFpy3RyqoChE9sHHQNB6epo6j+ukBd7oJyV0phpAPZd4B2wNkDaTmRDFJ0h2Piw==</SignatureValue>
    </Signature>
    </License>
     
  5. anthonykash

    anthonykash MDL Novice

    Aug 29, 2012
    12
    0
    0
    I hope something like this comes out for the Pro version. You guys really kick ass over here, I love this forum.
     
  6. KNARZ

    KNARZ MDL Addicted

    Oct 9, 2012
    895
    482
    30
    Very good.

    And I managed to completly unlock all features from Windows such as LOB, Sideloading or other Limitations.
    It's like a Ultimate+ Version without ANY limitation. Also Server reserved functions are unlocked!

    With some collegue, we may will programm a small application to easy unlock the features.
    Thanks to kost he pointed me to the right direction.

    Now I turn on the VM and only see black till the already logged in Deskop!
    BLACK-BOOM-DESKTOP!
     
  7. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    This is very good.
    I confirmed my idea - by hijaqing cryptography API it is possible to void almost anything that rely on RSA signatures and uses standard cryptoapi.
    My technique with application license spoofing works. At least on some apps - I found some apps been able to successfully unlock from trial.
    Now i'm gonna write some useful functionality - file logging and docs - and then post it here for testing
    It will work on anything - even on core edition

    Then, it will be very intereseting to me to tamper with sppsvc.
    Who knows, may be it will do the magic. You will need to disable sppsvc no more. It will eat anything from ppdlic
     
  8. KNARZ

    KNARZ MDL Addicted

    Oct 9, 2012
    895
    482
    30
    #28 KNARZ, Nov 1, 2012
    Last edited: Nov 6, 2012
    "You will need to disable sppsvc no more. It will eat anything from ppdlic"

    This would be just wonderfull ^^ ;)
     
  9. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    Updated version 1.1 is here (see the first post for downloading URL)
     
  10. athene

    athene MDL Novice

    Feb 6, 2012
    16
    6
    0
    Installous, Windows version :p
     
  11. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    #31 kost, Nov 5, 2012
    Last edited: Nov 5, 2012
    (OP)
    After numerous experiments I have discovered how microsoft track win8
    devices in their store.
    This information can be used to reset all trials and make microsoft
    see your device as new - never seen before - without reinstalling windows.

    To install something from windows store you need to enter your liveID.
    Microsoft under your liveid keep track about everything you have ever installed,
    license status - full,trial,expiration date.
    If you move to another device and enter the same liveid - license sync occurs.
    If you install a trial app , uninstall it, enter another liveid and
    try to install it again - windows store says "you have installed this
    app on this computer before" and prohibit installation. Installation
    is possible if trial is not expired and you use the same liveid
    you first used to acquire trial license on this device.
    Furthermore, If you even reinstall windows and try to use your previous liveid
    store will prohibit installation.

    Reasonable question arises. How microsoft track your device.
    I know exactly how. It tracks MachineID GUID.
    On clean windows there's no MachineID.
    First time you install any appliation from windows store MachineID is created.
    If you use you previous liveid microsoft query their database for hardwareid
    presented by your windows store application.
    If it finds something similar it return previous MachineID with all logical
    consequences. Store will not allow you try and try the app endlessly using different LiveIDs
    on the same machine.
    MachineID associacion is supposed to be one time and forever.
    It is never supposed to change.
    Idea here NOT TO USE YOUR PREVIOUS LIVEID.
    If no MachineID is associated to the device and you use clean livid
    microsoft has no way to associate your device with something from their
    database. MS does not verify your IP. It also assumes there may be
    many computers with the same hardwareid. The only piece of information
    that help to track you is your LiveID.

    Second question is. Is it possible to remove MachineID without reinstalling ?
    The answer is YES.
    MachineID is stored under registry key
    HKEY_LOCAL_MACHINE\SYSTEM\WPA\39EEE4D3-6EBB-4C0A-8CBC-421AB72D114E-1

    Once created this key cannot be deleted. It is protected by windows kernel.
    But it is still posible to delete it.
    You must boot from windows installation disk. Press shift+F10 and you will
    get command prompt. Run regedit. Place cursor on HKEY_LOCAL_MACHINE node.
    Map SYSTEM hive from your windows installation.
    Common location is D:\windows\system32\config\system.
    Remove
    HKEY_LOCAL_MACHINE\<mapping node>\WPA\39EEE4D3-6EBB-4C0A-8CBC-421AB72D114E-1.
    Then boot to your windows installation.
    Go to windows store settings and sign out from your current liveid.
    Enter there clean liveid. (I suppose you dont use LiveID for windows logon - its very bad idea !)
    First time you install an app you'll get new MachineID.
    And you will also be able to try all trial apps again.
    Microsoft will give you trial licenses because it thinks you are new customer.

    Format of stored machine ID :

    <Machine>
    <Registration>
    <MachineID>12345678-cbd7-414b-c217-edb5660512ae</MachineID>
    <HardwareID>XAAAABMALgAAAAEAAwABAAEAAAABAAAAAQABAAEA+l6kPOeDJGbmt/7biAR26Hb5GDEAHA0AAgABAQACBQADAQAEAgAFAAAGAQAHAAAIBwAJAwAKAQALAAAMBwA=</HardwareID>
    </Registration>
    <Signature xmlns="http :// www .w3.org/2000/09/xmldsig#">
    <SignedInfo>
    <CanonicalizationMethod Algorithm="http :// www .w3.org/2001/10/xml-exc-c14n#" />
    <SignatureMethod Algorithm="http :// www .w3.org/2001/04/xmldsig-more#rsa-sha256" />
    <Reference URI="">
    <Transforms>
    <Transform Algorithm="http :// www .w3.org/2000/09/xmldsig#enveloped-signature" />
    </Transforms>
    <DigestMethod Algorithm="http :// www .w3.org/2001/04/xmlenc#sha256" />
    <DigestValue>92pU0KnXWLTC3Xnj+ka0hnLT2eYNcRD3auqW7jQ1u5o=</DigestValue>
    </Reference>
    </SignedInfo>
    </Machine>

    It is signed by microsoft and verified by WSService on its startup.
    WSServiceCrk also removes signature checks from MachineID - it removes ALL signature checks from WSService.
    You can tamper with MachineID. But if you change it manually and remove
    WSServiceCrk - WSService will not be able to verify signature and may fail.
    Better to delete it and request new ID. MS will sign it for you.


    Also it is desired to delete
    "C:\Users\user\AppData\Local\Packages\WinStore_cw5n1h2txyewy\AC\Microsoft\Windows Store\*"
    while Windows Store client is not running.
    It keeps there some local cache about trial expiration.
     
  12. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    Guyz !! Victory !!

    I discovered how to feed licenses to wsservice without store client.
    WSClient.dll!WSLicenseInstallLicense
    It works !

    Some apps are preinstalled with windows 8. They have OEM licenses such as:

    <License Version="1" Source="OEM" xmlns="urn:schemas-microsoft-com:windows:store:licensing:ls">
    <Binding Binding_Type="Machine">
    <ProductID>16db93bf-8748-449a-96ba-e9ed3a5f872d</ProductID>
    <PFM>Microsoft.ZuneMusic_8wekyb3d8bbwe</PFM>
    </Binding>
    <LicenseInfo Type="Full">
    <IssuedDate>2012-07-14T01:24:20Z</IssuedDate>
    <LastUpdateDate>2012-07-14T01:24:20Z</LastUpdateDate>
    </LicenseInfo>
    </License>


    It is possible to change ProductID and PFM and import license for any product.
    Appxes can be easily downloaded from winstore. Use fiddler to find URL.

    Having

    1) Appx
    2) WSServiceCrk
    3) Bogus OEM license
    4) my WSService license loader

    it is possible to install any metro app even withoug internet connection.

    Redistribution via torrents is possible !

    I need some time to prepare release. And it starts. Torrentz for metro appz
     
  13. Tito

    Tito Super Mod / Adviser
    Staff Member

    Nov 30, 2009
    18,681
    18,587
    340
    @kost

    Awesome news!! Keep it up!!
    :worthy:
     
  14. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    Here we go. I'm rewriting first post.
     
  15. kost

    kost MDL Member

    Jan 22, 2011
    116
    225
    10
    I prepared some packages with games.
    I'll post them on a torrent tracker. Tomorrow. Now is too late where I am.
     
  16. paul44

    paul44 MDL Member

    Feb 11, 2010
    176
    80
    10
    Very nice news everybody :D
     
  17. jaydoza

    jaydoza MDL Member

    May 28, 2012
    166
    21
    10
    #37 jaydoza, Nov 6, 2012
    Last edited: Nov 6, 2012
    very exciting :) when will you upload the latest version of your tool?

    EDIT: nevermind i just read your post above .
     
  18. s1ave77

    s1ave77 Has left at his own request

    Aug 15, 2012
    16,104
    24,378
    340
    Very nicely done mate :cool2:! Chapeaux! Awaiting your trorrent.
    Regards
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  19. wolf69

    wolf69 MDL Senior Member

    Jul 29, 2009
    276
    19
    10
    looking forward to this how hard is it too do everything that needs done?
     
  20. coggy9

    coggy9 MDL Novice

    Mar 16, 2011
    35
    8
    0
    #40 coggy9, Nov 6, 2012
    Last edited: Nov 6, 2012
    Has anyone tried Hydro Thunder Hurricane? It seems to have additional protection. :negative: Will your torrent address this?
    EDIT: Looked in my tokens.dat, there is a trial token for HTH, and I can't seem to overwrite it. Does anyone know how to remove tokens yet?