View Full Version : BackupHDDVD, a tool to decrypt AACS protected movies
BUZZARD1
29th December 2006, 04:03
This has got me all excited again and it looks like im not the only one. A few more smart people and the problem is history.
Cheers to you all!
:stupid:
OverlordQ
29th December 2006, 04:18
so who is going to take this program to the next step?
Right now there is nothing illegal about the program because it doesn't provide any keys. It's just a nice proof of concept.
But for decryption to be useful I would think we need some automated way of extracting the key from the dvd. At that point we have a viable method of copying dvd's.
If we are forced to share keys through warez sites or download lists from offshore locations it makes the decryption unreliable and poorly supported (because we all know legitimate places like doom9 won't support the sharing of keys). +, there are so many variations of dvd's, probably each with it's own key.
I guess somebody is going to have to reverse engineer the playback and decryption of the key similar to the way commercial software players do it. Otherwise there will always be a cat and mouse game of updates to circumvent the protection.
Anyways, thank you so much for your program!
In addition, on sequential copies of the HD-DVD the content distributor can put a different key on the same title so the list can grow exponentially in having 30 odd keys for a single movie.
Craigular.B
29th December 2006, 05:07
I don't think it's a problem that he released this crack so early.
If the industry suddenly changed the encryption scheme, they'd have to have a way to be able to update all the players currently on the market with the new encryption (I think?). I'm pretty sure there wouldn't be a way to make the two encryption methods compatible without compromising the new one's security, right? Then again, maybe they'd keep up the age-old tradition of leaving the early adopters without a pot to p*** in, and revamp the discs/players for a new generation.
Please, correct me if I'm wrong. I really don't know much about DRM. But (to me, at least) it seems like two different encryption methods would be too different to make them work.
-Craig
Gradius
29th December 2006, 05:58
You can make titles where connection with the Internet is mandatory to be able to playback the s*** on your TV, so the player can send the firmware version to some EVIL Studio Server, if the version is old, the ESS will send a new firmware version using a new crypto engine, simple like that. :readfaq:
It can be done directly from some movie disc too, while you wait for the player to start the playback, it can just put a huge "please wait, you stupid noob", or something, message on your TV, while doing the firmware upgrade, just like that.
Now TCP is so EVIL that people around need to know this thing well to NOT buying a single piece of TCP implement or compliant. :sly:
BUZZARD1
29th December 2006, 09:56
You can make titles where connection with the Internet is mandatory to be able to playback the s*** on your TV, so the player can send the firmware version to some EVIL Studio Server, if the version is old, the ESS will send a new firmware version using a new crypto engine, simple like that. :readfaq:
It can be done directly from some movie disc too, while you wait for the player to start the playback, it can just put a huge "please wait, you stupid noob", or something, message on your TV, while doing the firmware upgrade, just like that.
Now TCP is so EVIL that people around need to know this thing well to NOT buying a single piece of TCP implement or compliant. :sly:
But is they did that then they would have to make sure every one who buys a HD-DVD player woudl have to have a internet connection, and it would have to say it on the box or walmart would get a trillion returns (this is when it is main stream of course). As far as them adding firmware updates on the disks, I would doubt it very much since there will be a crap load of models made in the next 5 - 10 years and it would be alot of space waested on the disk. Not to mention all the time and effort to make updates for all that firmware. But hey what do I know.
0xdeadbeef
29th December 2006, 10:41
I don't think it's a problem that he released this crack so early.
It's not a crack, not a hack, nor was a weakness of the encryption (AES 128) found. It's just a weakness of the player which delivers the keys esier than it should. This was somewhat expected by the industry and that's what the revocation list is for.
If the industry suddenly changed the encryption scheme, they'd have to have a way to be able to update all the players currently on the market with the new encryption (I think?). I'm pretty sure there wouldn't be a way to make the two encryption methods compatible without compromising the new one's security, right? Then again, maybe they'd keep up the age-old tradition of leaving the early adopters without a pot to p*** in, and revamp the discs/players for a new generation.
The encryption scheme doesn't need to be changed since it was not compromised. If we have really bad luck, PowerDVD will be blacklisted by entering a newly released HD-DVD in the drive in the next 1-3 months. If then nobody is able to read the keys from another player, we're were we started at.
Please, correct me if I'm wrong. I really don't know much about DRM. But (to me, at least) it seems like two different encryption methods would be too different to make them work.
-Craig
HD-DVD doesn't allow changing the encryption algorithm. BlueRay however does. But then again, it's unlikely that AES 128 gets hacked in the next years.
zeroprobe
29th December 2006, 11:43
and still no one has sucessfully done this.
cmon guys someone out there get a good memory dumper and post the results so we can have a look for yas.
Susana
29th December 2006, 11:56
and still no one has sucessfully done this.
cmon guys someone out there get a good memory dumper and post the results so we can have a look for yas.
Yeah, memoryman have had success:
http://www.memoryman.com/images/moviesm.jpg
;)
yodoso
29th December 2006, 12:43
LOL, this happens right after our guy leaves for vacation. Who cares if one change to the encryption can render this program useless, we have our first real progress in the world of HD. Now if these files are fully decrypted, and since the files are mpeg-2(are the first hddvd's still mpeg-2, or did they switch yet), we may only need to make a slight change if any to our favorite mpeg-2 decoder to actually make backup copies of our favorite movies. Thanks alot, Muslix64 you're not the only one with a monitor/vid card that doesn't support hdcp, your work is greatly appreciated.
This is gonna start a chain reaction of software development, just think of dess when it first came out. Actually forget that, before dess we'd started up a small program before launching our favorite dvd player(lol I think it was windvd back then too), and that program would actually frame grab from windvd. The software was buggy as hell, and the quality was terrible. LOL, I'd love to see an old doom9 guide using this method.
(btw, a couple of months ago, someone discovered that all you have to do is push the print screen in an old version of an hddvd program, and the frame was not encrypted. You could actually paste it into paint or any other program one wanted. Looks like the dvd, and the hddvd scene are progressing in the same way)
Next dess came out, and you guys know that program started the chain reaction of the dvd scene. I don't know the status of guy wrote the program, but hopefully the authorities gave him a break. But lets see someone rip a dvd of today with the software of yesterday. Thats right, it won't work. Like I said this program will start the domino effect
johner23
29th December 2006, 12:47
See above:
http://forum.videohelp.com/viewtopic.php?t=317738
http://forum.videohelp.com/viewtopic.php?t=317715
http://podcasts.engadget.com/2006/04/25/engadget-podcast-076-04-25-06/
http://www.engadget.com/2006/12/27/aacs-drm-cracked-by-backuphddvd-tool/
PS: now, people around the world can test and find / cause some weak point in that protection system. :)
Or, for those who has some proper knowledge, can create some similar tools that can be more succesful about that task.
And, of course, the industry will strike again very fast, I guess !! Be prepared !! LOL
Thanks.
xerces8
29th December 2006, 15:30
Hi Muslix64... could you please upload this to an alternative download source besides the infamous rapidshare?
I don't know how strict the moderators are , so I'll say just this: the MD4 hash of the file is 4860e9248663d52dc47bfc98d61ec6d7
(and I don't see any problems with this, since a few posts above a direct HTTP link to the file was posted; mods, please be consistent )
Regards,
xerces8
Wookie Groomer
29th December 2006, 15:40
This has to be a hoax since it appears not a single person in the entire world except the original poster is claiming this works or can confirm anything. Let's see some proof. A fancy edited You Tube Video is worthless without at least one key to test for ourselves.
ttringle
29th December 2006, 15:49
Next dess came out, and you guys know that program started the chain reaction of the dvd scene. I don't know the status of guy wrote the program, but hopefully the authorities gave him a break. But lets see someone rip a dvd of today with the software of yesterday. Thats right, it won't work. Like I said this program will start the domino effect
You don't know the status of the guy who wrote DeCSS?
He's probably one of the most well known hackers due to his cracking the dvd protection scheme and distributing the code around to the point it appeared on T-Shirts. Not sure how you could know about this website yet not know who DVD Jon is.
http://www.theregister.co.uk/2003/01/07/dvd_jon_is_free_official/
TimT
dchard
29th December 2006, 15:54
This has to be a hoax...
Should be, but noone can proved that yet.
Otherway: the guy should be right: the decrypted title-key where else could be, but in the RAM?
What all we need is a programmer with a HD-DVD drive and at least one encrpypted HD-DVD disk, to find out, that the Title-key is stored in the ram during playback.
Dchard
Atamido
29th December 2006, 16:23
This has to be a hoax since it appears not a single person in the entire world except the original poster is claiming this works or can confirm anything.
The reason people are excited is that his story is completely plausible. It has happened numerous other times that a program left the decryption key in open RAM to be used. And several people have looked at his program and determined that it is certainly a plausible set of code.
There are two reasons that people that have duplicated this wouldn't want to admit to it.
1. They don't want the legal trouble when their identities are discovered.
2. They hope to gain financially from this exploit (through the sale of pirate discs).
Honestly through, I suspect that there just aren't enough people out there with an HD-DVD drive to be able to work on this. Remember that some of the most able hackers don't have significant financial status.
Atamido
29th December 2006, 16:40
The program which the author is referring to as exposing the key in memory is probably PowerDVD 6.5. I'm trying to locate where in the memory the key is located, anyway if someone could post at least one key, I could be able to tell where PowerDVD will place the keys
Actually, you don't need to know where the key is, you can just test every byte sequence in PowerDVD's RAM. It would take a while, but not as long as you think. The secret is that you must know some byte sequence that occurs in the decrypted output to see if you have the correct key.
Lets say you know that somewhere in the first 1MB, this sequence is likely to occur: "0x2e513a5f2b9f3c5980". I assume you would pick some byte sequence from the HD-DVD specs or H.264/MPEG-2 specs.
1. Take 128bits at offset 0x0.
2. Take first 1MB of data from HD-DVD.
3. Feed both into decryption program.
4. Test output for test sequence.
5. If not found, start at step 1 and increment offset.
If a memory dump for PowerDVD is 50MB, and you want to test every 128-bit byte sequence, that means you will need to test a maximum of around 51 million offsets (the key is likely in the earlier section of RAM). This sounds like a lot, except for a few things:
1. The memory dump, 1MB of data, and output are all small enough to fit in RAM, so total speed will be limited by CPU+RAM.
2. Decryption of AES-128 is pretty fast (or else you couldn't decrypt the disc fast enough for real time playback).
3. The key is likely to be early in the RAM dump, before cached decrypted/unencoded output.
0xdeadbeef
29th December 2006, 18:13
Besides the fact that the key is unlikely to begin at unaligned addresses, I still would say that it's much more promising to set breakpoint on calls to DeviceIoControl. If the key challenge/response algorithm is similar to that of CSS, this functions should be called for the authentification process.
Indeed, I guess any call of DeviceIOControl which returns a 16 byte buffer is pretty likely to return a disc/title key.
So tracking the calls ot DeviceIOControl should also be a good start to retrieve the player key.
BTW: a quick look into the Win32 API shows that DeviceIOControl accepts 8 parameters.
BOOL DeviceIoControl(
HANDLE hDevice, // handle to device of interest
DWORD dwIoControlCode, // control code of operation to perform
LPVOID lpInBuffer, // pointer to buffer to supply input data
DWORD nInBufferSize, // size of input buffer
LPVOID lpOutBuffer, // pointer to buffer to receive output data
DWORD nOutBufferSize, // size of output buffer
LPDWORD lpBytesReturned, // pointer to variable to receive output byte count
LPOVERLAPPED lpOverlapped // pointer to overlapped structure for asynchronous operation
);
As the first parameter is the last to be pushed on the stack, the size of the output buffer is the 6th parameter or the 6th PUSH operation "above" the function call in the ASM listing.
Well, I have neither the ressources nor the time to do it myself - and admittedly I don't really want to get into trouble. But I would guess this appoach is pretty likely a good beginning.
Gradius
29th December 2006, 18:19
This has to be a hoax since it appears not a single person in the entire world except the original poster is claiming this works or can confirm anything. Let's see some proof. A fancy edited You Tube Video is worthless without at least one key to test for ourselves.
Keep in mind, really FEW people around have a HD-DVD on your PC or Mac, I would say not even 1%, including myself.
calinb
29th December 2006, 19:27
Now if these files are fully decrypted, and since the files are mpeg-2(are the first hddvd's still mpeg-2, or did they switch yet),Aren't most HD DVD titles shipping in VC-1? I don't know if they're good ol' WMV9/WMVA or if they're using the new WMV9 Advanced profile.
http://en.wikipedia.org/wiki/VC-1
dchard
29th December 2006, 19:36
Keep in mind, really FEW people around have a HD-DVD...
Thats the point: many people here are able to test the software, but they don't have the appropirate hardware to do it.
And ofcourse: the author also should give us some detailed information about how and where to find the Title-Key in RAm or whereever it is, or which debugger did he(?) use, etc.
Dchard
Zag
29th December 2006, 19:45
Thats the point: many people here are able to test the software, but they don't have the appropirate hardware to do it.
And ofcourse: the author also should give us some detailed information about how and where to find the Title-Key in RAm or whereever it is, or which debugger did he(?) use, etc.
Dchard
He is trying to stay on the legal side of things. If he gave instructions on how to obtain the title key he would be on the wrong side of the DMCA.
Atamido
29th December 2006, 20:03
Besides the fact that the key is unlikely to begin at unaligned addresses, I still would say that it's much more promising to set breakpoint on calls to DeviceIoControl.That is true. I was simply pointing out a method to do an exhaustive search of all allocated RAM, and that it could be done in a reasonable amount of time. He said he wanted to know the address, and I showed him how he could find it. Though, if one has reasonable experience with a debugger, and it isn't well hidden, that would be much faster to use that.
easy2Bcheesy
29th December 2006, 20:07
In summary, no matter what you do as a studio -- release on HD DVD or Blu-Ray -- some professional counterfeiter can hack open a TV, digitize the output, re-compress the movie, and release the title on HD DVD (or dvd, or super-dvd, or whatever.) Because the profit margin is so high, they could afford to trash their revoked player and buy a replacement for every movie if they had to. Every (smart) studio exec knows this; there's no reason for them to bail out just because of this. The "average joe" is probably screwed by either DRM even if this exploit turns out to work. The "advanced joe" will probably still find a way to copy movies. Overall, the best the execs can hope for is a small reduction in "average-joe" piracy which might or might not translate into a small boost in sales, which, over the next decade, might eventually amount to something more than a hill a beans after paying for the development of the DRM.
The more obvious solution would be to purchase an HDCP stripper, a Blackmagic Intensity and simply capture digitally into an enormous AVI file, then compress that. The only limitation would be the 4:2:2 colourspace, but at 1080p, believe me, you don't really notice.
0xdeadbeef
29th December 2006, 20:13
That is true. I was simply pointing out a method to do an exhaustive search of all allocated RAM, and that it could be done in a reasonable amount of time. He said he wanted to know the address, and I showed him how he could find it. Though, if one has reasonable experience with a debugger, and it isn't well hidden, that would be much faster to use that.
This would only be faster if you already had all the tools. Writing the tool to do this "brute force" approach would most probably cost much more time than debugging directly. Also unpredictable things like inverse byte order etc. could make the approach fail although the key is in there. Last but not least, it's not sure that the offset of the key inside the RAM dump will be the same for any disk. Tough this depends on the implementation, it could as well be that the key is at a different location each time depending on the HD-DVD structure or other things.
Last but not least, for the next step (extraction of the player key, recreation of the authentication algorithm) identifying the calls which return the disc/title keys is an important landmark.
calinb
29th December 2006, 20:17
He is trying to stay on the legal side of things. If he gave instructions on how to obtain the title key he would be on the wrong side of the DMCA.
I agree. This forum is certainly not a good place for getting anywhere near DMCA violations, so everyone must talk very generally.
Personally, I'm boycotting these anti-consumer technologies so I have no interest or means to test any of the methods, suggestions, or theories described in this forum that might be used to view or obtain decrypted keys from an HD DVD. That said, it seems to me that an HD DVD key changes each time a new DVD is inserted in the drive and it's pretty easy to focus on what's changed in a memory dump.
0xdeadbeef
29th December 2006, 20:47
That said, it seems to me that an HD DVD key changes each time a new DVD is inserted in the drive and it's pretty easy to focus on what's changed in a memory dump.
It has to be expected that a lot of things in the memory change when you exchange the disc. E.g. it would be sensible of a player to cache information about the disc structure etc.
Furthermore, though I don't know too much about the AACS decryptin process, it might be that the title key is only extracted when a new title is played. It's obvious that lots of things are cached in the memory for that and this will be completely different for another disc.
neviens
29th December 2006, 22:58
Some hints for reversers with HD-DVD players (I haven't).
Easiest way to find the key is look for for code and not data.
AES code is easy to find in executable or memory because
code is standartized.
Then attach the debugger, and put the breakpoint on key
expansion routine input. When decryption of title begins,
routine will be called, and program breaks in debugger.
Pointer to key will be on the stack or in register. Then Ctrl-C,
Ctrl-V or write down it.
Well I oversimplified the process, in real life there may be problems
with antidebugging, code obfuscation, etc, but it's possible to
overcome these too.
Next step is write patch for keys collecting code, or inject such
a code in working process.
Atamido
29th December 2006, 23:17
This would only be faster if you already had all the tools. Writing the tool to do this "brute force" approach would most probably cost much more time than debugging directly.
It all depends where your experience lays. The method I mentioned is pretty trivial, even for a programmer with limited experience. As I said, if you already are experienced debugger that would be much faster. If you've never used debugging software in your life, but you know how to program...
0xdeadbeef
29th December 2006, 23:47
It all depends where your experience lays. The method I mentioned is pretty trivial, even for a programmer with limited experience. As I said, if you already are experienced debugger that would be much faster. If you've never used debugging software in your life, but you know how to program...
My experience of programming versus ASM debugging is about 10000:1 in favor of programming. Still I would use the debugger approach for the named reasons. Also the suggestions posted by neviens is interesting. If one of the common AES tables could be located, this would be a good start as well. Still I think looking closely at the calls of DeviceIOControl would be the approach with the least effort.
The basic conditions for your suggestions assume to many things that first need to be worked out. The time alone to get the crypted and decrypted data and the memory dump would probably suffice to find the key with the debugger. Then you have to code the tool (which indeed should not be too much work). However if this approach fails (and it sure will) the first time you run it, there are too many factors which could be the reason for this: the input data or the expected output could be wrong, the tool could be buggy or it could be something you didn't consider like the byte order or storing the key as a string or whatever. It not even sure when exactly a title key will be visible in RAM and for how long.
hajj_3
30th December 2006, 00:19
the creator of this hasn't replied in about 3days, wonder if he's been arrested lol.
hope he replies soon and answers all these questions and hopefully creates a nice new shiny version that finds the key's automatically, even if the program takes 2hrs to find it that would be cool.
if cracking hd-dvd is this easy (well i say easy) why on earth was hd-dvd and blue-ray delayed for so long, why didnt they just hire stephen hawking and dvd-jon to create an unbreakable algorithm.
if a new version can auto find the key for the hd-dvd drive and the disc itself instantly or pretty quickly i will prob have to purchase a 360 hd-dvd drive. Ģ130 aint too bad. Ģ117 with 10% discount codes.
blutach
30th December 2006, 00:24
I don't know how strict the moderators are , so I'll say just this: the MD4 hash of the file is 4860e9248663d52dc47bfc98d61ec6d7
(and I don't see any problems with this, since a few posts above a direct HTTP link to the file was posted; mods, please be consistent )
Regards,
xerces8Posting an MD5 hash of a program is OK. Posting keys is not OK.
Nor is there need to somehow challenge the mod team to be consistent.
why didnt they just hire stephen hawking and dvd-jon to create an unbreakable algorithm.Does such a thing exist?
Regards
0xdeadbeef
30th December 2006, 00:39
And again (though it becomes boring): the crypting algorithm (AES128) is in no way broken and thus HD-DVD is not "cracked".
I would be happy if these statements were true, but at the moment, they aren't and there's no hint they will be soon.
hajj_3
30th December 2006, 00:39
Does such a thing exist?
Regards
Yes it does, the SSL256bit encryption hasnt been cracked, its approx 402 numbers long, its 2 prime numbers multiplied together. there is a $1m prize for anyone who can crack it.
zeroprobe
30th December 2006, 02:00
ahh well new years nearly here so we shall see sooner or later.
xerces8
30th December 2006, 02:34
Posting an MD5 hash of a program is OK. Posting keys is not OK.
Eh, the hash is not MD5 but MD4. A hash code used in a popular P2P network. Knowing it is as knowing an URL, only better, since it can not break due to a closing of a single server.
PS: For easy use, the size of the file must also be known, it is 17964 bytes
Alxemi
30th December 2006, 04:23
Well, i also hope this is not a hoax, but like other guy said, 12-28 is santos inocentes day, (fools day in spain) letīs hope itīs just a coincidence....
Anyway, if this is a hoax, the crack will come. We all now it, and the industry should know it.
plonk420
30th December 2006, 05:42
it would be badass if the key used was a standalone player's key ;)
dukey
30th December 2006, 05:51
Just some thoughts ..
I'm pretty sure brute forcing the memory is a viable solution. Probably could brute force 4gig of ram in under an hour on a fast machine. 1gig of ram in 15 mins .. etc
You could probably even speed up the process and see when the program allocates x amount of memory. Where x is the number of bytes a key will take up in memory. That might be a give away :p
zacox
30th December 2006, 07:04
It's easy for them to get YouTube or some other site to cough up an IP addy on this guy.
You honestly believe a person who has the skill necessary to write this software doesn't know how to cover his tracks?
After seeing what charges DVDJon faced (though he was eventually found not guilty), I'm fairly certain he used several layers of proxy servers and anonymizers to post here, on YouTube, and anywhere else. Hell, he probably routed his IP traffic around the world twice before hitting a destination. Good luck with that, MPAA.
It sort of underscores the beauty of collaboration and desire to be free of limitations and boundaries only made available through a worldwide network of minds. It's a game. Any 1000 software engineers can build an encryption scheme for DRM, and any million hackers can find a way to break it quicker than those 1000 engineers ever imagined. Sort of like a prison in that the guards work 8 hour shifts trying to keep drugs, gangs and weapons out, while the inmates have 24/7/365 to figure out how to get them in. Who do you think wins the war?
The only way this guy will ever be found out is if he gets drunk and starts bragging to his college buddies that he is the new DVDJon.
Unless of course, he is looking for the DMCA fight, in which case, more power to him.
JarrettH
30th December 2006, 08:27
you're on reuters...
http://today.reuters.com/news/articlenews.aspx?type=technologyNews&storyID=2006-12-29T104641Z_01_N28191949_RTRUKOC_0_US-DVDS-HACKER.xml
a "hacker" lol :p
daft009
30th December 2006, 08:45
wow! impressive stuff!
OverlordQ
30th December 2006, 10:22
Yes it does, the SSL256bit encryption hasnt been cracked, its approx 402 numbers long, its 2 prime numbers multiplied together. there is a $1m prize for anyone who can crack it.
No, that doesn't mean that it's unbreakable as you claim. The only unbreakable encryption is a properly setup one time pad.
XStylus
30th December 2006, 11:33
He is trying to stay on the legal side of things. If he gave instructions on how to obtain the title key he would be on the wrong side of the DMCA.
He's still not quite on the legal side of things simply because of his YouTube video. It's proof that he used his tool to violate the DMCA. I don't know if that's a civil infraction or a criminal infraction, but it's a risk to him nonetheless, thus why I suggested earlier that he take steps to protect his identity unless he's willing to do what 2600 lost the will to do back when they published DeCSS--that being taking it all the way to the Supremes. Although with the current corrupted political climate, I don't hold much hope there, to be honest.
Perhaps it's all just paranoia, but considering the extreme public importance of what muslix64 is doing against the unconscionable viciousness of the **AAs, it's justified.
cc979
30th December 2006, 11:50
He's still not quite on the legal side of things simply because of his YouTube video. It's proof that he used his tool to violate the DMCA. I don't know if that's a civil infraction or a criminal infraction, but it's a risk to him nonetheless, thus why I suggested earlier that he take steps to protect his identity unless he's willing to do what 2600 lost the will to do back when they published DeCSS--that being taking it all the way to the Supremes. Although with the current corrupted political climate, I don't hold much hope there, to be honest.
Perhaps it's all just paranoia, but considering the extreme public importance of what muslix64 is doing against the unconscionable viciousness of the **AAs, it's justified.
spooky stuff, law is not my field but posting the title-keys in the youtube film is asking for trouble
KillaByte
30th December 2006, 12:05
spooky stuff, law is not my field but posting the title-keys in the youtube film is asking for troubleHe didn't. What is seen in the film are only hashes - the title keys are well hidden behind a black bar ;)
neviens
30th December 2006, 13:38
My experience of programming versus ASM debugging is about 10000:1 in favor of programming.
...
It's easy to guess from your nickname too (;
Those with 1:10000 ratio usually select something like
0DEADBEEFh for nick (:
...
Still I think looking closely at the calls of DeviceIOControl would be the approach with the least effort.
...
You are complicating things. DeviceIoControl is for communication
with kernel mode drivers, and it's a bad practice to put computation
intensive code (ie. crypto functions) into driver.
Better pay attention to CLDShowX.dll library, it's the only file
with all necessary crypto functions (Rijndael aka AES, SHA1,
ECC) into.
Cyberace
30th December 2006, 13:43
since the files are mpeg-2 (are the first hddvd's still mpeg-2, or did they switch yet), we may only need to make a slight change if any to our favorite mpeg-2 decoder to actually make backup copies of our favorite moviesI read that all HD DVD movies released so far uses the 'newer' MPEG-4 AVC (H.264) codec, (it is Blu-Ray that still uses MPEG-2 for it's retail movies, but I guess they going to switch to H.264 soon enough as well). My favorite H.264 encoder is x264, and my favorite H.264 decoder is FFmpeg (FFmpeg's libavcodec/libavformat also contains a H.264 encoder based on x264), they are my favorites because the are open source (GPL/LGPL). Nero Digital by Nero/Ateme probebely has the best commercial H.264 encoder for home-usage, and CoreAVC by CoreCodec is probebly the best commercial H.264 decoder for home-usage, however those are closed source and cost money.
http://en.wikipedia.org/wiki/HD_DVD
http://en.wikipedia.org/wiki/Blu-Ray
http://en.wikipedia.org/wiki/H.264/MPEG-4_AVC
0xdeadbeef
30th December 2006, 14:02
It's easy to guess from your nickname too (;
Those with 1:10000 ratio usually select something like
0DEADBEEFh for nick (:
A good observation on this ;)
Then again, the C notation adds the "0x" pun, so this was a reason as well. On a second thought, I spent hundreds if not thousands of hours debugging on several processors, so the 1:10000 ratio was maybe a little exaggerated :)
You are complicating things. DeviceIoControl is for communication
with kernel mode drivers, and it's a bad practice to put computation
intensive code (ie. crypto functions) into driver.
When looking at the source code of DVD authentication functions, they use DeviceIOControl to send/retrieve keys from the DVD drive, which is not surprising as this is the only way to do it. Should be the same for HD-DVD and if you determine the handle by watching calls to CreateFile, you can break only on calls which are sent to the HD drive.
Then again this has nothing to do with the encryption and thus is neither compitation intensive nor bad practice.
Better pay attention to CLDShowX.dll library, it's the only file
with all necessary crypto functions (Rijndael aka AES, SHA1,
ECC) into.
That's a very interesting observation of course. If one could identify the function entries of the AES128 decryption in there and set a breakpoint to it, this would deliver the title key immediately. Then again, I neither have the hardware nor the software nor the wish to be the aim of some lawyers, so let's just see what other people make of this.
v_spec
30th December 2006, 14:21
The guy is famous! He's all over the news.
hartiberlin
30th December 2006, 14:48
The encryption scheme doesn't need to be changed since it was not compromised. If we have really bad luck, PowerDVD will be blacklisted by entering a newly released HD-DVD in the drive in the next 1-3 months. If then nobody is able to read the keys from another player, we're were we started at.
.
What a crap,
just keep the PowerDVD Version you have now
and uninstall a newer Version.
Or install Windows XP again and then install
the old PowerDVD Version again...
This way you always have access to the old
Version.
Also, if a movie is decrypted it can be recoded
into WMVHD or MPEG-4 H.264 or XVID-HD or DIVX-HD
or Nero-HD and stored onto a normal
DVD-R as a backup.
I guess this hack will boost HDDVD very much now in
the future !
I might myself buy now a XBOX HD-DVD rom drive
and rent some HD-DVD movies, if I can make backups.
Also if HD-movies would come out at the same
day as they are released in the movie theater and are
not sold much higher than a movie ticket, I also would
just buy them !
All this DRM crap is stupid.
It just doesnīt make sense...
I will not go to a movie theater to see a movie
and be annoyed by the big guy in front of me,
who has an Afro look hair and makes noise
with his popcorn bag...
I just want to have the movie at home myself...
I just collect movies and I donīt sell them...
If the movie studies would be smarter, they would just drop
the DRM and make the media available at prices, everone
can afford to buy and release it at the same day,
they are also released at the movie theaters
or make them available to download the same day for
the same fee what a movie ticket costs...
Then they would make much more money...
Now we have to rent the movies, copy them
and recode them to DVD-R, which is very time
and work consuming...
I would love to pay 5 to 10 Euros for a HD movie
to download online, if it would be much easier and
would be availabe on the first day, the new
movie is released into the movie theaters..
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.