Jump to content
The Inquirer-Home

Microsoft Cofee leaks onto the web

No use crying over it
Monday, 9 November 2009, 14:18

MICROSOFT'S DIGITAL FORENSICS software has been spotted on a file-sharing site, available for all to download.

Computer Online Forensic Evidence Extractor (COFEE) is a forensics tool that fits on a USB drive for the police to use in PC forensics.

The software is free to police forces around the world and helps access details about crimes such as identity theft, online fraud, child pornography and illegal filesharing before criminals can wipe the information.

It's reportedly illegal for unauthorised people to download and use the software.

According to the Vole it takes the average bobbie "with even minimal computer experience" less than ten minutes to master the program.

"This enables the officer to take advantage of the same common digital forensics tools used by experts to gather important volatile evidence, while doing little more than simply inserting a USB device into the computer," said Microsoft.

The Vole and police are worried that cyber criminals could analyse COFEE and write code that would identify and intercept it, securely wiping incriminating data from their hard drives.

COFEE requires Windows XP but it does have some Windows Vista support. According to company insiders, Microsoft is developing a new version of COFEE that will be released next year for Windows Vista and Windows 7. µ

 

Share this:

Comments
DEFENSE:RUN-=7=-.

Developed in Japan, for law enforcement, except those trained in law enforcement where cued out in first US/Iraqi Invasion in 1990 & Now You'll notice NO government vechiles state"Law Enforcement, as Those People are DEAD. No Place where vechile originates ethier, so go figure. Lawlwess SCAM.

On Cofee, -=7=- cann't be tested by itheCOF command line, Inventors themselves are NO Longer With Us & Who Says that things Right About Anything.
If You Did Lose Your Machine, Whose Watching those "illegal" events NOW?
drashek

posted by : cream?, 09 November 2009 Complain about this comment
Hot Coffee

It's the "Hot Coffee" incident all over again... :-)

posted by : Black Adder, 09 November 2009 Complain about this comment
Marketing ploy

This is all just a very clever marketing ploy to get all the criminals to upgrade from XP. That way their data will be safe from the Cofee powered bobbie, at least for a while.

posted by : TomM, 09 November 2009 Complain about this comment
A little research goes a long way

Before the e-media gets all up in arms about this, maybe they should look into the leak itself. Several hints show that it may possibly be a fake.

- All of the included "tools" are preinstalled on a Windows OS since Win2K.

- The few files not included in OS's are not digitally signed by Microsoft.

- Would MS really release something this major, even only in small circulations with a broken installer?

- Why would MS use opensource ajax javascript when they have already coded similar scripts for use in their live suite of products?

- Would MS really include a "Gang Bustaz" mode in their products, let alone something of this stature?

- None of the accompanying documentation, such as how to use the tools manual contain MS wordmarks, copyright or logos.

- The loader application does nothing more than run scripts that utilise OS's built in functions and logs them to a .xml, any user can copy files from sys32 to a usb drive and run a batch script to achieve the same effects.

Unsigned files:
http://i37.tinypic.com/2uglaj7.jpg

Inconsistent design (read: designed by a 7 year old with vbasic)
http://i37.tinypic.com/9amxld.jpg

posted by : Dr Prawn, 09 November 2009 Complain about this comment
Helix works fine

Instead of downloading dodgy Windows programs to analyze dodgy Windows systems, Helix 3 free version CD (forensic Linux distro) is a reputable product that works fine for this, and is a free download from:

http://www.e-fense.com/products.php

Or there is always WFTC:
http://www.foolmoon.net/security/wft/

posted by : N. S. Sherlock, 09 November 2009 Complain about this comment
Doesn't seem to be much to COFEE

In analyzing the tool set that's included in COFEE, this might be much ado about nothing:

a href="http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/" http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/ /a

posted by : Prefect, 10 November 2009 Complain about this comment
Sorry, here's the link to the full analysis of COFEE

In analyzing the tool set that's included in COFEE, this might be much ado about nothing:

http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/

posted by : Prefect, 10 November 2009 Complain about this comment
most agree not a big deal

Seems the hype is really about how it was kept under wraps for so long, the technology is not new and many forensics tools out there do the same, but many do it better. This is meant for non-technical law enforcement.

http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/

posted by : mjpinvestor, 10 November 2009 Complain about this comment
Not permissible in US courts

Any evidence gathered with this utility wouldn't be permissible as evidence in court as the software ISN'T publicly available. It's simply worthless for any real law enforcement use. Encase is simply a better utility for law enforcement.

Suppling software like COFEE to an officer who isn't tech savvy has the potential for arguments that evidence was compromised or tampered with.

posted by : 5iN, 10 November 2009 Complain about this comment
Treason and Sponsorship of Terrorisms

Intentional and advertent sponsorship of terrorism. Explicit providing of resources and exploits in support of organized crime and terrorism. Sponsorship of international crimes and espionage including sponsorship of terrorism. Direct and intentional provisioning of resources and support for organized crime and terrorist use.

THIS IS YOUR INTERPOL, YOUR DMCA. [sing] It's fun to sponsor terrorism with the D. M. C. A., Organized crime, terrorists can rhyme! D. M. C. A. Eh, terrorists?

posted by : lee, 12 November 2009 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Nvidia Fermi

Will graphics cards built with Nvidia's Fermi GPUs be a hit?