It is currently Thu Sep 09, 2010 2:12 pm

All times are UTC




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: Self-Destruct Code against Micro$oft Forensic Software
PostPosted: Tue Dec 15, 2009 2:55 am 
Offline
OAH Owner
User avatar

Joined: Wed Dec 07, 2005 10:53 pm
Posts: 1235
Location: San Antonio, TX / Boston, MA / Tokyo Japan
Quote:
Hackers Brew Self-Destruct Code to Counter Police Forensics

* By Kim Zetter

Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed DECAF, is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.

The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.

Someone submitted the COFEE suite to the whistleblower site Cryptome last month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.

This week two unnamed hackers released DECAF, an application that monitors a computer for any signs that COFEE is operating on the machine.

According to the Register, the program deletes temporary files or processes associated with COFEE, erases all COFEE logs, disables USB drives, and contaminates or spoofs a variety of MAC addresses to muddy forensic tracks.

The hackers say that later releases of the program will allow computer owners to remotely lock down their machine once they detect that it has fallen into law enforcement hands. The hackers, however, have not released source code for the program, which would make it easy for anyone to see if the program contains malware that might also harm a computer or allow the attackers to take control of it.

Update: The developers of DECAF have taken issue with Threat Level referring to them as hackers. “We’re just two developers who support the free flow of information and privacy,” one of them wrote Threat Level in an anonymous e-mail. “You could say we’re just average joes.”


Source : wired.com

_________________
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Image
Image
Image

"May God have mercy upon my enemies, because I won't." Gen. George S. Patton

アノニマス


Top
 Profile  
 
 Post subject: Re: Self-Destruct Code against Micro$oft Forensic Software
PostPosted: Wed Jan 27, 2010 8:46 pm 
Offline
OAH Member
User avatar

Joined: Sat Aug 05, 2006 11:15 am
Posts: 259
Location: Fuck Knows
Quote:
Update: 01/21/2010

As many of our loyal followers and supporters are aware, Microsoft has accused us of violating copyright laws. After further investigation we found that Microsoft's claim was based on our identification of a product in which, we are currently disputing. Microsoft's claim to this copyright violation has resulted in a DMCA take-down notice and suspension from our service provider. While we understand the motives behind Microsoft's course of action, we do not agree that they have a legal or ethical right to do this.

Article 1, Section 8, Clause 8 of the United States Constitution

"To promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries."

We are currently speaking with a well recognized and established organization; seeking out legal council to help support DECAF in our continued product releases. We sincerely appreciate the support we have received during this challenging time. If you would like to participate in our endeavor, please contact me at mike@DECAFme.org.

Sincerely,
Mike
close




source: http://www.decafme.org/

heh microsofts gunning for them now.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB. OAH Security, & Thousands of Cans of Redbull 2004-2010