Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Hackers Brew Self-Destruct Code to Counter Police Forensics

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
The Straight Story Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 03:56 PM
Original message
Hackers Brew Self-Destruct Code to Counter Police Forensics
Hackers Brew Self-Destruct Code to Counter Police Forensics


Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed Decaf, is designed to counteract the Computer Online Forensic Evidence Extractor, aka Cofee. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.

The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.

Someone submitted the Cofee suite to the whistleblower site Cryptome last month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.

http://www.wired.com/threatlevel/2009/12/decaf-cofee
Printer Friendly | Permalink |  | Top
formercia Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 03:58 PM
Response to Original message
1. Now we can find out about the back doors in MS Software.
Edited on Mon Dec-14-09 04:03 PM by formercia
I bet they still have a few more, just in case.

Wouldn't it be funny if there was a Trojan in the Decaf code?

..and be sure to set your BIOS to not boot from USB.

... and be sure your BIOS is password encrypted.
Printer Friendly | Permalink |  | Top
 
OneTenthofOnePercent Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 04:31 PM
Response to Reply #1
4. Password protected or password encrypted?
I was unaware one could "encrypt" the bios.
Password protection on the other hand seems to be a pretty common feature.

Also, what's to stop the police from simply unplugging the Hard drives and scanning or imaging them?
Printer Friendly | Permalink |  | Top
 
Taverner Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 03:59 PM
Response to Original message
2. Good
Printer Friendly | Permalink |  | Top
 
Greyhound Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 04:13 PM
Response to Original message
3. The computer is the democratization of communication, and therefore, power.
The base of the power structure as we know it is gone, it's just going to take a generation or two for most to catch on.


Printer Friendly | Permalink |  | Top
 
L0oniX Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 04:48 PM
Response to Original message
5. Heh ...thanks ...I just dl'd both and more.
Printer Friendly | Permalink |  | Top
 
paulsby Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-14-09 05:39 PM
Response to Original message
6. it never ceases to amaze me how frigging cavalier
child porn people etc. are when it comes to encryption, etc.

i can't remember the last time i searched a computer disk that had encrypted files.

and apparently, 99% of these people don't know that "erasing" a file does nothing of the sort.

with all the shareware encryption tools, anonymous surfing tools, etc. it's simply amazing how few people use them.

especially considering in many cases we are talking about convicted felons/and/or on parole people who are looking at serious prison time for an offense.

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 26th 2024, 10:46 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC