[117457] in Cypherpunks

home help back first fref pref prev next nref lref last post

No subject found in mail header

daemon@ATHENA.MIT.EDU (Anonymous)
Fri Sep 3 13:18:29 1999

Date: Fri, 3 Sep 1999 18:16:17 +0200 (CEST)
Message-Id: <199909031616.SAA24600@mail.replay.com>
From: Anonymous <nobody@replay.com>
To: cypherpunks@algebra.com
Reply-To: Anonymous <nobody@replay.com>

Very interesting: and so is the fact that the signature check boils down
to one "JNZ" instruction in ADVAPI32.DLL.  NOP that and you have
no verification.

For details on how to patch that ADVAPI32 and run
any old CSP you want, any time, with no signature
check at all, just %43oitio0-f3#FW$tt5435764


"Background: MSFT CAPI comes pre-installed with two keys used to check the
validity of a Cryptographic Service Provider (CSP). The holder of either key
can install operating system security services without user authorization.
The first key is used by MSFT to sign their own security services modules.
The identity of the second key holder until now been unknown. That is to say
until MSFT forgot to strip the binary of NT4 SP5 off debugging symbols.


Perhaps not surprisingly, the debugging symbol for the second key is...
_NSAKEY,


For more information and a program to remove the NSA's key from your copy of
Windows 95, 98, NT, 2000, see
http://www.cryptonym.com/hottopics/msft-nsa.html"
        


home help back first fref pref prev next nref lref last post