Security News and Feeds News and events concerning the IT world.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 10th November 2009, 16:29
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,405
Blog Entries: 36
Rep Power: 10
Reputation: 198
MaXe has made his way up the systemMaXe has made his way up the system
Microsoft COFEE leaked on What.cd!

[Recently Microsofts "Computer Online Forensics Evidence Extractor" was leaked
on a private torrent site, the application is now widespread around the Internet]




What is COFEE?

In short words it is a set of Windows tools that runs in a batch from a USB-key.
In other words, it wont work against any hacker that suffers from general paranoia

What is COFEE in Microsofts own words?
Quote:
Microsoft has created Computer Online Forensic Evidence Extractor (COFEE),
designed exclusively for use by law enforcement agencies. COFEE brings together a number
of common digital forensics capabilities into a fast, easy-to-use, automated tool for first
responders. And COFEE is being provided—at no charge—to law enforcement around the world.

"COFEE (Computer Online Forensic Evidence Extractor) is a software that'll cut through whatever
flimsy security miscreants have slapped on windows computer in a flash, and then automatically
analyze the dirty bits the cops need to bust their ass, from internet activity to stored data, no
pwnage skillz or trips to the lab needed. Microsoft's giving the wonder tube to lawmen for free,
and 2,000 officers in 15 countries are already using it."
You can read more on websites mentioned in the references

What does COFEE require to work?
It requires physical access of course and first of all, a USB-key. However
in order to function as it should it also needs Autorun to set enabled on
USB-drives, and didn't Microsoft just disable that as default not long ago?

So, if autorun is disabled and the computer screen is locked, then the agent
wont have a chance besides taking the computer to the real Auditors.

Of course then they might run into another problem, such as the entire
harddisk except the boot-partition has been encrypted, just like I have :-D

So if you're paranoid about COFEE, don't be just disable Autorun on your
computer for USB-keys, lock your computer when you're away so people
can't run it manually and encrypt your harddisk so the encryption first has
to be broken in case your computer is stolen or taken by an agency or w/e.

The report generation is nice, but a little bit buggy in some results of course.


All of the best,
MaXe

Download Links:
http://rapidshare.com/files/304863094/COFEE_v1.1.2.rar

References:
http://torrentfreak.com/cofee-forens...-ban-it-091108
http://en.wikipedia.org/wiki/Compute...ence_Extractor
http://www.microsoft.com/industry/go...e/default.aspx
http://www.microsoft.com/industry/go...cofee_faq.mspx
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
  #2  
Old 10th November 2009, 20:40
hestas's Avatar
InterN0T Crew
 
Join Date: Jun 2008
Posts: 651
Blog Entries: 2
Rep Power: 13
Reputation: 159
hestas has made his way up the systemhestas has made his way up the system
Re: Microsoft COFEE leaked on What.cd!

lawl xD Very nice....
__________________
"Intern0t, fight crime with crime, preventing internet security risks since 2009!"
Reply With Quote
  #3  
Old 10th November 2009, 22:45
dsf's Avatar
dsf dsf is offline
 
Join Date: Oct 2009
Location: Portugal
Posts: 105
Rep Power: 4
Reputation: 33
dsf is on the way to become something
Re: Microsoft COFEE leaked on What.cd!

Thanks for sharing, didn't know what a COFEE was.
__________________

&lt;SCR\0IPT&gt;alert(1);/*<!--
Reply With Quote
  #4  
Old 11th November 2009, 04:40
Rorok's Avatar
Its the new style
 
Join Date: Jun 2008
Location: House
Posts: 695
Blog Entries: 10
Rep Power: 10
Reputation: 56
Rorok will become a Token soon
Re: Microsoft COFEE leaked on What.cd!

Quote:
Originally Posted by dsf View Post
Thanks for sharing, didn't know what a COFEE was.
Its what ya drink in the morning :)

ya know you can still **** your HDD up to where noone can recover it, not those clean labs. maxe taught me that trick :) its funny how lazy america is getting to have to use this.
__________________

Reply With Quote
  #5  
Old 11th November 2009, 06:38
System's Avatar
 
Join Date: Jun 2008
Posts: 309
Rep Power: 10
Reputation: 33
System is on the way to become something
Re: Microsoft COFEE leaked on What.cd!

O_O sexy!

<--- Been absent hacking my PS2 lol
And guitar of course
__________________
"BackTrack is the fastest way to go from boot to remote root." - H.D. Moore
Reply With Quote
  #6  
Old 20th November 2009, 02:13
K1llTh3C0rruption's Avatar
 
Join Date: Nov 2009
Location: US
Posts: 66
Rep Power: 4
Reputation: 41
K1llTh3C0rruption is on the way to become something
Re: Microsoft COFEE leaked on What.cd!

haha thats pretty awesome.

definitely grabbed me a copy.
Reply With Quote
  #7  
Old 21st November 2009, 10:20
Cyber Assassin
 
Join Date: Oct 2008
Posts: 401
Rep Power: 12
Reputation: 239
macd3v has made his way up the systemmacd3v has made his way up the systemmacd3v has made his way up the system
Re: Microsoft COFEE leaked on What.cd!

Quote:
Originally Posted by System View Post
O_O sexy!

<--- Been absent hacking my PS2 lol
And guitar of course
What were you using i used to hack my ps2 also :D exploited my memory card so i could run ftp and a bunch of other fun stuff on it hehe.


On topic this does sound pretty neat im definately going to check it out thanks for the post MaXe
__________________
http://i34.tinypic.com/24g5awx.gif
http://mack360.com
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
0-day in Microsoft DirectShow Erratum Exploits, Vulnerabilities & PoCs 3 25th February 2010 10:14
Thousands of Hotmail passwords leaked online MaXe Security News and Feeds 8 14th October 2009 22:21
how to use microsoft MS09-021 coolbrokenheart General Hacking Discussions 1 12th June 2009 21:36
DNS vulnerability leaked by Matasano MaXe Security News and Feeds 0 24th July 2008 16:36


All times are GMT +2. The time now is 13:59.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1