The cure for boredom is curiosity. There is no cure for curiosity - Dorothy Parker
MICROSOFT'S DIGITAL FORENSICS software has been spotted on a file-sharing site, available for all to download.
Computer Online Forensic Evidence Extractor (COFEE) is a forensics tool that fits on a USB drive for the police to use in PC forensics.
The software is free to police forces around the world and helps access details about crimes such as identity theft, online fraud, child pornography and illegal filesharing before criminals can wipe the information.
It's reportedly illegal for unauthorised people to download and use the software.
According to the Vole it takes the average bobbie "with even minimal computer experience" less than ten minutes to master the program.
"This enables the officer to take advantage of the same common digital forensics tools used by experts to gather important volatile evidence, while doing little more than simply inserting a USB device into the computer," said Microsoft.
The Vole and police are worried that cyber criminals could analyse COFEE and write code that would identify and intercept it, securely wiping incriminating data from their hard drives.
COFEE requires Windows XP but it does have some Windows Vista support. According to company insiders, Microsoft is developing a new version of COFEE that will be released next year for Windows Vista and Windows 7. µ
Developed in Japan, for law enforcement, except those trained in law enforcement where cued out in first US/Iraqi Invasion in 1990 & Now You'll notice NO government vechiles state"Law Enforcement, as Those People are DEAD. No Place where vechile originates ethier, so go figure. Lawlwess SCAM.
On Cofee, -=7=- cann't be tested by itheCOF command line, Inventors themselves are NO Longer With Us & Who Says that things Right About Anything.
If You Did Lose Your Machine, Whose Watching those "illegal" events NOW?
drashek
It's the "Hot Coffee" incident all over again... :-)
This is all just a very clever marketing ploy to get all the criminals to upgrade from XP. That way their data will be safe from the Cofee powered bobbie, at least for a while.
Before the e-media gets all up in arms about this, maybe they should look into the leak itself. Several hints show that it may possibly be a fake.
- All of the included "tools" are preinstalled on a Windows OS since Win2K.
- The few files not included in OS's are not digitally signed by Microsoft.
- Would MS really release something this major, even only in small circulations with a broken installer?
- Why would MS use opensource ajax javascript when they have already coded similar scripts for use in their live suite of products?
- Would MS really include a "Gang Bustaz" mode in their products, let alone something of this stature?
- None of the accompanying documentation, such as how to use the tools manual contain MS wordmarks, copyright or logos.
- The loader application does nothing more than run scripts that utilise OS's built in functions and logs them to a .xml, any user can copy files from sys32 to a usb drive and run a batch script to achieve the same effects.
Unsigned files:
http://i37.tinypic.com/2uglaj7.jpg
Inconsistent design (read: designed by a 7 year old with vbasic)
http://i37.tinypic.com/9amxld.jpg
Instead of downloading dodgy Windows programs to analyze dodgy Windows systems, Helix 3 free version CD (forensic Linux distro) is a reputable product that works fine for this, and is a free download from:
http://www.e-fense.com/products.php
Or there is always WFTC:
http://www.foolmoon.net/security/wft/
In analyzing the tool set that's included in COFEE, this might be much ado about nothing:
a href="http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/" http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/ /a
In analyzing the tool set that's included in COFEE, this might be much ado about nothing:
http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/
Seems the hype is really about how it was kept under wraps for so long, the technology is not new and many forensics tools out there do the same, but many do it better. This is meant for non-technical law enforcement.
http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/
Any evidence gathered with this utility wouldn't be permissible as evidence in court as the software ISN'T publicly available. It's simply worthless for any real law enforcement use. Encase is simply a better utility for law enforcement.
Suppling software like COFEE to an officer who isn't tech savvy has the potential for arguments that evidence was compromised or tampered with.
Intentional and advertent sponsorship of terrorism. Explicit providing of resources and exploits in support of organized crime and terrorism. Sponsorship of international crimes and espionage including sponsorship of terrorism. Direct and intentional provisioning of resources and support for organized crime and terrorist use.
THIS IS YOUR INTERPOL, YOUR DMCA. [sing] It's fun to sponsor terrorism with the D. M. C. A., Organized crime, terrorists can rhyme! D. M. C. A. Eh, terrorists?