Hackers Brew Self-Destruct Code to Counter Police Foren

reghakr

New member
Local time
5:16 AM
Messages
1,614
Location
Pennsylvania
Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed Decaf is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.
The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.

Someone submitted the COFEE suite to the whistleblower site Cryptomelast month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.

This week two unnamed hackersreleased decaf, an application that monitors a computer for any signs that COFEE is operating on the machine

More..............Hackers Brew Self-Destruct Code to Counter Police Forensics | Threat Level | Wired.com
 

My Computer My Computer

At a glance

Windows 7 Pro & Vista Home PremiumAthlon 64 3800+ (Orleans) 2.40GHz2GB DDR2 RAM DIMMNVIDIA GeForce 8500 GT 512 MB memory HDMI out
Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed Decaf is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.
The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.

Someone submitted the COFEE suite to the whistleblower site Cryptomelast month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.

This week two unnamed hackersreleased decaf, an application that monitors a computer for any signs that COFEE is operating on the machine

More..............Hackers Brew Self-Destruct Code to Counter Police Forensics | Threat Level | Wired.com
Smartasses...Decaf against Cofee...

This is really going to cause an issue with law enforcement
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64Intel Core 2 Duo T9300 2.5 GHz4GB Kingston DDR2-800NVIDIA Geforce 8600M GT (512MB Model)
Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
I work in some capacity (customs) where PC's are often seized and examined, albeit that aspect of matters isn't down to me personally.

The software which is used definitely isn't authored by Microsoft, however there are support measures in place to get assistance from Microsoft if needs be.

I've seen Microsofts Computer Online Forensic Evidence Extractor, and in major part it's true (if questionable) value is to tell what a computer which was seized in a powered on state was being used for in the immediate past.

I'm not at liberty to say which software is used by my employers for recovering data by forensic means, because it is part and parcel of the employment package I agreed to - however it's not been written specifically for crime investigation agencies and is available in commercial guise if you can stump up a hefty license fee.

Criminals of any worth are using remote servers in overseas locations which have laws that protect their data, with access solely through securely encrypted VPN access of another provider in another secure global location, minimizing all traces of what their local computer might reveal about their activities and records.
 

My Computer My Computer

At a glance

W7 x64Intel Q9300 2.5Ghz Quad LGA775 (Would like Q9...4Gb OCZ Gold 1,333MhzPalit HD4850 O/C Sonic 512Mb DDR3, Dual DViD's
Computer Manufacturer/Model Number
Custom built machine
OS
W7 x64
CPU
Intel Q9300 2.5Ghz Quad LGA775 (Would like Q9650)
Motherboard
Gigabyte GA-EP45T-UD3R (F6 Bios)
Memory
4Gb OCZ Gold 1,333Mhz
Graphics Card(s)
Palit HD4850 O/C Sonic 512Mb DDR3, Dual DViD's
Sound Card
Azalia to twin Samson 50w Studio Monitors
Monitor(s) Displays
Twin Dell (E-IPS) U2311H 23.6" Screens
Screen Resolution
1920 x 1080 @ 60Hz
Hard Drives
Crucial M4 SSD, archives on twin Western Digital Caviar Black WD2002FAEX, 2TB, 7200rpm HDD's, Samsung Ritemaster CD/DVD Burner...
PSU
OCZ 600w
Case
Lian-Li PC8 acoustifoamed' aluminium tower
Cooling
Scythe 140mm Zipang
Keyboard
Cherry PS/2 custom model
Mouse
Lenovo USB laser "Thinkpad" Mouse
Internet Speed
ADSL2+ @14Mbps downstream & Cat6 Gigabit Ethernet
Antivirus
NOD32
Browser
Opera
Other Info
Silicon Dust HD Homerun Dual FTA (Ethernet) TV Tuners, Dray Tek Vigor 2850Vn router and 8x HP Gigabit Switch. Lian-Li CR26 Card Reader, Canon MF4430 iSensys laser printer/scanner.
]I'm not at liberty to say which software is used by my employers for recovering data by forensic means, because it is part and parcel of the employment package I agreed to - however it's not been written specifically for crime investigation agencies and is available in commercial guise if you can stump up a hefty license fee.

I can telly ou mine ran about $600.00 for one single program.

bUT THERE ARE SOME FOR FREE OUT THERE AND IF CONCLUSIONS SUPPORT THE CSE, THEY CAN BE EBNTERED IN THE EXNIBATUIN AND TESTIMONT AT A TRU[IAL,

Sorry about the jey board, another butes the dust,
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Pro & Vista Home PremiumAthlon 64 3800+ (Orleans) 2.40GHz2GB DDR2 RAM DIMMNVIDIA GeForce 8500 GT 512 MB memory HDMI out
Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
Back
Top