226
General Software Discussion / Re: What the hell is OpenCandy?
« Last post by scancode on September 13, 2009, 06:45 PM »-- All this testing was done on a VMWare VM
Testing started on a Clean, WinXP SP3 install. I took a registry and filesystem snapshot, proceeded to install MediaCoder (Audio Edition), typical next-next-next install. It left an OpenCandy folder in the temp dir, with a DLL and a small explanation (OpenCandy_Why_Is_This_Here.txt). After a reboot, for good measure, a third filesystem snapshot showed no changes, and the DLL was still there. However, I had no problems deleting the file. I poked fun at the DLL using OllyDbg (With MediaCoder as my victim) and found that indeed, all information sent is non-personally idenfying. However, it saved stuff (session keys, product keys) in HKLM\Software\MediaCoder with criptic names, even if I didn't install anything.
This are the HTTP requests it made.
It's really opt-in as far as the additional installations are concerned, but I'm not sure about the purpose of those reg entries. I could do some more poking at it with Olly, but i'd rather hear the official version.
I tried Miro too, but they now bundle the Ask toolbar (opt-out)
I like the end-user experience, but I'm not sure why the reg keys are saved, (and why aren't they clearly identified as belonging to OpenCandy)
Testing started on a Clean, WinXP SP3 install. I took a registry and filesystem snapshot, proceeded to install MediaCoder (Audio Edition), typical next-next-next install. It left an OpenCandy folder in the temp dir, with a DLL and a small explanation (OpenCandy_Why_Is_This_Here.txt). After a reboot, for good measure, a third filesystem snapshot showed no changes, and the DLL was still there. However, I had no problems deleting the file. I poked fun at the DLL using OllyDbg (With MediaCoder as my victim) and found that indeed, all information sent is non-personally idenfying. However, it saved stuff (session keys, product keys) in HKLM\Software\MediaCoder with criptic names, even if I didn't install anything.
This are the HTTP requests it made.
Spoiler
api.opencandy.com?clientv=12&language=es,en&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=get_offers&os=WIN5.1SP2&product_key=4bc3108774fe0784644fed43647b5d3e&v=1.0&signature=dfb6e2937da9a2557da73950ff5fc381
api.opencandy.com?clientv=12&language=es&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=get_translations&product_key=4bc3108774fe0784644fed43647b5d3e&v=1.0&version=0&signature=a7707a70e4adfe281a43fe57e3c8226b
api.opencandy.com?accepted_ind=0&clientv=12&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=track_offer_result&offer_id=390&product_key=4bc3108774fe0784644fed43647b5d3e&session_key=356b199c89601bd9be384d6fde734ec3&v=1.0&signature=de090feecbad0d2cc50c61119265e919
api.opencandy.com?clientv=12&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=track_product_installed&product_key=4bc3108774fe0784644fed43647b5d3e&session_key=356b199c89601bd9be384d6fde734ec3&v=1.0&signature=6246b02806ebb3eafebdfc4af5c1433c
api.opencandy.com?clientv=12&language=es&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=get_translations&product_key=4bc3108774fe0784644fed43647b5d3e&v=1.0&version=0&signature=a7707a70e4adfe281a43fe57e3c8226b
api.opencandy.com?accepted_ind=0&clientv=12&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=track_offer_result&offer_id=390&product_key=4bc3108774fe0784644fed43647b5d3e&session_key=356b199c89601bd9be384d6fde734ec3&v=1.0&signature=de090feecbad0d2cc50c61119265e919
api.opencandy.com?clientv=12&machine_code=B876377DDB5C44C4B788798B8D54C56E&method=track_product_installed&product_key=4bc3108774fe0784644fed43647b5d3e&session_key=356b199c89601bd9be384d6fde734ec3&v=1.0&signature=6246b02806ebb3eafebdfc4af5c1433c
It's really opt-in as far as the additional installations are concerned, but I'm not sure about the purpose of those reg entries. I could do some more poking at it with Olly, but i'd rather hear the official version.
I tried Miro too, but they now bundle the Ask toolbar (opt-out)
I like the end-user experience, but I'm not sure why the reg keys are saved, (and why aren't they clearly identified as belonging to OpenCandy)

Recent Posts
)




