Register
FAQ
Today's Posts
THE DAEMON TOOLS FORUM
Quick Links
OFF-TOPIC General Chat, everything that doesn't fit in the other Forums

Tip: System Errors? Click here to Fix your PC

Closed Thread
 
LinkBack Thread Tools Display Modes

  #1
Old 09.11.2008, 14:06
User

 
Sblade's Avatar
 
Join Date: 09.11.2008
Posts: 31
Beitrag Securom FAQ Updated, Big BS

Hi there LocutusofBorg. Iґm Inspector Switchblade, better known as Sblade. Iґve helped thousand of gamers run Securom protected gamers for some years with my TECH FAQ

I donґt mind DRMґs like TAGES, but Securom is built in a way that is invasive, risky and annoying to say the least....

Iґm joining the lawsuit against EA for their use in Spore. Now short after the lawsuit, assh**es updated their FAQ:

SecuROM


2.2 Is SecuROM actually loaded onto my computer?
SecuROM is a DRM system used by software publishers to protect their intellectual property. In the course of applying the solution, certain files are placed onto the computer for the system to work properly


Cool, no prob with that.


2.3 Does SecuROM install a driver or any other software at the kernel level ("Ring 0") of my PC?
No, SecuROM does not install any components or perform any processes at the kernel or ring 0 level. All SecuROM components and processes occur at ring 3, the normal application level.



Well hereґs my question LocutusofBorg. How they can find your DT application then?

SecuROM

Your software is legal, if I were you Iґll sue their butts ASAP, but that is entirely up to you....

What I want to know is if thereґs any chance they can detect RING0 virtual drives by running at RING3? I highly doubt it....


Looking forward to your answers
Regards
Sblade
Sblade is offline  
Sponsored Links
Sponsored Links
  #2
Old 09.11.2008, 14:09
GERMAN TRANSLATOR

 
Blazkowicz's Avatar
 
Join Date: 09.11.2005
Posts: 5,094
Default Re: Securom FAQ Updated, Big BS

They can detect several registry keys and also, of course, file names.
__________________
Make something idiot proof, but then they just make a better idiot
Peace Through Power
Blazkowicz is offline  
  #3
Old 09.11.2008, 14:16
User

 
Sblade's Avatar
 
Join Date: 09.11.2008
Posts: 31
Default Re: Securom FAQ Updated, Big BS

I understand in my book that Securom doesnґt detect IDE drives emulation in DT PRO.... canґt they detect those keys you are talking about?
Sblade is offline  
  #4
Old 09.11.2008, 15:38
GERMAN TRANSLATOR

 
Blazkowicz's Avatar
 
Join Date: 09.11.2005
Posts: 5,094
Default Re: Securom FAQ Updated, Big BS

They do in latest SecuROM version.
__________________
Make something idiot proof, but then they just make a better idiot
Peace Through Power
Blazkowicz is offline  
  #5
Old 09.11.2008, 15:52
User

 
Sblade's Avatar
 
Join Date: 09.11.2008
Posts: 31
Default Re: Securom FAQ Updated, Big BS

How they Distinguish between legit and emulated IDE drives? I mean thereґs no way to tell... since emulating hardware is required to be at RING0 they canґt tell the difference...

and blacklisting would be a baaaad idea...
Sblade is offline  
  #6
Old 09.11.2008, 19:23
experienced user

 
Join Date: 27.09.2005
Posts: 774
Default Re: Securom FAQ Updated, Big BS

sure, theres ways to tell, however your limited (even then you dont admit it) knowledge and experience makes you guess (incorrectly)...

to 'take on' an enemy, its usually a good idea to understand them first, not make guesses....
evlncrn8 is offline  
  #7
Old 09.11.2008, 20:19
User

 
Sblade's Avatar
 
Join Date: 09.11.2008
Posts: 31
Default Re: Securom FAQ Updated, Big BS

OK, I found the post you donґt like evlcrn8...

http://www.daemon-tools.cc/dtcc/f23/...html#post51276

Foolish Chris. He is paranoid about DT, not paranoid about a Sony DRM similar to XCP...ignorant completely of the risks that implies running Securom games...

So DT works now in Ring3? if DT virtual drives runs still in RING0, canґt you write a rutine that will always fool Securom RING3 access?
Sblade is offline  
  #8
Old 10.11.2008, 00:01
experienced user

 
Join Date: 27.09.2005
Posts: 774
Default Re: Securom FAQ Updated, Big BS

dt agent and other program run in ring r3 (userland), the daemon tools device is handled by the ring 0 drivers (the daemon tools one.. and the sptd one)... there's no 100% way to hide ring 0 from ring 3 because registry keys, interfaces for ioctl and so on have to exist for communication purposes... if a ring 3 program crashes, it doesn't (usually) take out the system with it... if ring 0 crashes its game over.. typically a bugcheck -> bsod...

as for writing a routine that blocks securom ring 3 access, look again.. what do you think yasu does, curerom does/did , seculauncher and various other utilities out there do/did?...

not sure what you mean about the post i don't like.. the one you posted makes no sense or not, if i didn't like daemon tools i wouldn't have the customer tag now would i?

nor (if i thought it was a rootkit) would i have bought it... sure, it uses some rootkit-like things (api hooking in ring 0 for example) which may make people feel paranoid but that all depends on your trust of the developers..
evlncrn8 is offline  
  #9
Old 10.11.2008, 00:18
User

 
Sblade's Avatar
 
Join Date: 09.11.2008
Posts: 31
Default Re: Securom FAQ Updated, Big BS

I trust DT. I donґt trust Securom using RING 0 countermeasures to flag/stop DT.

Sony has a history of invading systems. DT not.
Sblade is offline  
  #10
Old 10.11.2008, 00:40
User

 
Sblade's Avatar
 
Join Date: 09.11.2008
Posts: 31
Default Re: Securom FAQ Updated, Big BS

Quote:
Originally Posted by evlncrn8 View Post
dt agent and other program run in ring r3 (userland), the daemon tools device is handled by the ring 0 drivers (the daemon tools one.. and the sptd one)... there's no 100% way to hide ring 0 from ring 3 because registry keys, interfaces for ioctl and so on have to exist for communication purposes... if a ring 3 program crashes, it doesn't (usually) take out the system with it... if ring 0 crashes its game over.. typically a bugcheck -> bsod...

as for writing a routine that blocks securom ring 3 access, look again.. what do you think yasu does, curerom does/did , seculauncher and various other utilities out there do/did?...

We know that the utilities that you have mentioned don´t work with latest Securom version if they aren´t updated....

Ring 3 detection routines still have to go into Ring 0 if the program is in stealth mode. It already hides itself in the registry in that mode otherwise it would have been easy for DRM's to circumvent the circumvention.

Securom starts in RING3 and monitors the RING0... otherwise nothing will prevent DT stealth to false registry data and fool Securom.... when I say registry data.... what data CAN´T be falsified from RING0 to the naive RING3?

Ring0 overrule Ring3, that´s a simple fact no one can deny...

Last edited by Sblade : 10.11.2008 at 00:45. Reason: quoting
Sblade is offline  
Closed Thread

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 13:27.
Powered by vBulletin Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2   Forum Copyright © 2000-2010 THE DAEMON TOOLS FORUM
Contact Us DAEMON-Search.com Web Store: Disc-Soft.com