PlayReady DRM Leak Triggers Microsoft Takedown and Amazon Account Suspensions * TorrentFreak

To protect PlayReady DRM, GitHub was asked to remove leaked SL3000 certificates, while Amazon nuked accounts for using leaked credentials.

The leaked files from the disclosure https://seclists.org/fulldisclosure/2024/Jun/7 have since been removed from https://developercommunity.visualstudio.com/t/Incorrect-code-generation-on-warbirded-b/10680249. Someone on Reddit (https://www.reddit.com/user/TapAppropriate1458/) posted a direct link to a download from azurewebsites.net that's been taken down now too. The #InternetArchive has the files still at:
https://web.archive.org/web/20240624211440/https://sendvsfeedback2-download.azurewebsites.net/api/fileBlob/file?name=B0cde770200a945109437927ba3fe4d67638537352993712632_ICE_REPRO.zip&tid=0cde770200a945109437927ba3fe4d67638537352993712632

Unfortunately I cannot verify whether those files/the link was the original file or a re-upload. But at least all files within `ICE REPRO.zip/Linker/linkrepro.zip' match the size (in bytes) of the originals as given in the listing on seclists.

The file download from there has the sha256 hash:

d4c1a74f81e5259596466027ebac9f7eb026931c7cef02e5c37d884bbbb7f96f ICE_REPRO.zip

---

In addition, the disclosure notes that the MS symbol server does (STILL ONLINE!) leak the PDB of warbird.dll if requested. A backup has been re-upped here: https://files.catbox.moe/8iz2qk.pdb

Again, the sha256 hash. This has been matched against the original served by the MS symbol server:

2e8b5e0c17b4a4693ed494444f347f22a2eed15bcade18a5ac25d370011f8aa5 warbird.dll.pdb

---

I provide those hashes just for people to be on the safe side while analyzing the files. Keep in mind that accessing those files may be illegal.

#MSRP #leak #SecLists #Microsoft #WarBird #PlayReady #DRM #PDB #Widevine #PlayFair #Piracy

Full Disclosure: Microsoft leak of PlayReady developer / Warbird libs

#Microsoft bekommt seine Sicherheit noch immer nicht in den Griff. Jetzt ist auch noch versehentlich der Code des Kopierschutz-Systems #PlayReady geleakt. https://winfuture.de/news,143600.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
Wieder ein Microsoft-Leak: Quellcode des Kopierschutz-Systems ist frei

Bei der Durchsetzung von Sicherheits-Richtlinien hapert es bei Microsoft weiterhin. Das zeigt ein neuer Vorfall, bei dem durchaus beachtliche Mengen internen Codes an die Öffentlichkeit gelangten. Diesmal stammt dieser vom DRM-System der Redmonder.

WinFuture.de
Microsoft PlayReady-Datenleck: Quellcode versehentlich veröffentlicht

Das Microsoft PlayReady-Datenleck: Wie ein scheinbar harmloser Forumsbeitrag zur Preisgabe von 4 Gigabyte internem Code führte.

Tarnkappe.info