{"id":87614650,"date":"2009-11-17T23:31:59","date_gmt":"2009-11-18T07:31:59","guid":{"rendered":"http:\/\/www.geckotemple.com\/blog\/?p=87614650"},"modified":"2009-11-17T23:35:41","modified_gmt":"2009-11-18T07:35:41","slug":"cofee-really-thats-it","status":"publish","type":"post","link":"http:\/\/www.geckotemple.com\/blog\/?p=87614650","title":{"rendered":"COFEE &#8211; Really? That&#8217;s it?"},"content":{"rendered":"<p>Latest <a href=\"http:\/\/www.geckotemple.com\/blog\/?page_id=87614600\">Movember<\/a> photos are on the Mo&#8217;09 photos (there&#8217;s a link to the page at the top of this page.)<\/p>\n<p>So, a while ago (really? April of last year?) I <a href=\"http:\/\/www.geckotemple.com\/blog\/?p=87614223\">wrote about Microsoft&#8217;s new toolkit<\/a> for police to quickly gather everything they&#8217;d need from a Windows-based workstation, called COFEE.\u00a0 I had a bunch of questions about COFEE at the time, and now that I know a little more about it, I&#8217;m going to go back and answer my own questions and see if there&#8217;s any clarification on some of the\u00a0 (I hope).<\/p>\n<p>(15 minutes go by while I read the documentation).<\/p>\n<p>Are you <em>serious<\/em>?\u00a0 Is this the right thing?<\/p>\n<p>There&#8217;s like, it&#8217;s practically, I mean, c&#8217;mon.<\/p>\n<p>It&#8217;s a nice big batch file that collects a bunch of information, fair enough, but it doesn&#8217;t actually DO very much.\u00a0 No passwords are grabbed.\u00a0 No filelist generated (at least, not that they documented), and it looks like all you&#8217;d need to do to make it pretty-much useless is<a href=\"http:\/\/www.google.com\/search?hl=en&amp;q=disable+usb+ports+windows+xp&amp;sourceid=navclient-ff&amp;rlz=1B3GGGL_enCA319CA319&amp;ie=UTF-8&amp;aq=t&amp;oq=disable+usb+port\"> disable your USB ports&#8217; and\/or mass storage device drivers<\/a>.\u00a0 The documentation for end-users tells us how to do such things as run the scanner with OR without the autorun enabled on the system.<\/p>\n<p>(Heh, wait. What?)<\/p>\n<p>I thought this was going to be a bootable thing &#8211; was I wrong?\u00a0 I thought there was going to be this killer tool that meant you could walk up to a machine that&#8217;s OFF, boot from the stick instead of the onboard drive, collect the data from the operating system, and walk away, and as far as Windows knows, the machine wasn&#8217;t even powered on.<\/p>\n<p>I&#8217;m, I guess, in a way, sorta saddened.\u00a0 Don&#8217;t get me wrong &#8211; I don&#8217;t expect the average cop out there to be able to do a thorough job of collecting all the necessary data by hand, but I was sorta hoping that maybe they&#8217;d have something that would at least be on-par with <a href=\"http:\/\/www.remote-exploit.org\/backtrack.html\">Backtrack<\/a>, which any person with a highspeed connection and a thumb drive (or a blank CD) could create, and it&#8217;ll let you do all SORTS of alarming things to a machine without actually &#8220;touching&#8221; the operating system (unless you want to, in which case you can pretty much set the thing on &#8220;Liquefy&#8221; and watch all of Microsoft&#8217;s security go away).<\/p>\n<p>(<em>That <\/em>was a long sentence, woof).<\/p>\n<p>I guess what makes me sad is that COFEE isn&#8217;t going to collect any data that isn&#8217;t obviously available on the system in the first place.\u00a0 Seriously: is it common for prosecutors to bring forth evidence based on which local groups on the machine someone is a member of?<\/p>\n<p>&#8220;He must have done it &#8211; he&#8217;s in the SuperElite Hacker Pwnz0rz group, see?&#8221;<\/p>\n<p>I know the &#8220;no touchies&#8221; forensic methods for data gathering (like <a href=\"http:\/\/www.forensicswiki.org\/wiki\/Encase_image_file_format\">ENCASE<\/a>, which I&#8217;ve used in a previous job) are a different class than what COFEE is meant to do, but it looks like it&#8217;s only meant to be useful for kicking the door in, pushing the alleged bad guy outta the chair in front of the computer, and then running the launcher to collect your data.<\/p>\n<p>I can literally hear the hardware hackers out there trying to figure out how to set up something that&#8217;ll either automatically cram the drive with data that&#8217;s bogus, or simply melt it into a little plastic Hershey&#8217;s Kiss, or hey, maybe a virus that&#8217;ll wreak havoc back at the station.<\/p>\n<p>Not that I want that to happen.\u00a0 As much as my brain enjoys trying to figure out how to defeat whatever security system I come across, I want the cops to be able to figure out what&#8217;s real and what&#8217;s not about a given machine.\u00a0 I want them to be able to nail the bad guys when the chips are down.\u00a0 I want them to have the tools, I really do.<\/p>\n<p>COFEE isn&#8217;t the tool they need (yet).\u00a0 It&#8217;s better than taking the machine to the guys at the nearest Best Buy and asking &#8220;has this machine been used illegally?&#8221; but not much better.<\/p>\n<p>And if any of you have ever had your USB stick&#8217;s data go &#8220;poof&#8221; when being moved from computer A to computer B, you&#8217;ll know why I don&#8217;t trust that the data will even <em>make <\/em>it back to the office (or even the cruiser&#8217;s laptop).<\/p>\n<p>I just hope what I have is a red herring, and not the real deal.<\/p>\n<p>Oh, and this time last year*? I was yammering about <a href=\"http:\/\/www.geckotemple.com\/blog\/?p=87614328\">other stuff<\/a>, but still lovin&#8217; a good run-on sentence&#8230;<\/p>\n<p>And now, because most people won&#8217;t bother going to my Movember page, here&#8217;s a picture of me rubber-facing because my normal face never looks good to me.<\/p>\n<p>Neither does this, but it makes me giggle.<\/p>\n<div id=\"attachment_87614653\" style=\"width: 235px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/www.geckotemple.com\/blog\/wp-content\/uploads\/2009\/11\/DSCN0134.JPG\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-87614653\" class=\"size-medium wp-image-87614653\" title=\"Rubber-Facing\" src=\"http:\/\/www.geckotemple.com\/blog\/wp-content\/uploads\/2009\/11\/DSCN0134-225x300.jpg\" alt=\"Helps if you imagine me going &quot;Borkely-orkely-yobbley-bawk!&quot;\" width=\"225\" height=\"300\" srcset=\"http:\/\/www.geckotemple.com\/blog\/wp-content\/uploads\/2009\/11\/DSCN0134-225x300.jpg 225w, http:\/\/www.geckotemple.com\/blog\/wp-content\/uploads\/2009\/11\/DSCN0134-768x1024.jpg 768w, http:\/\/www.geckotemple.com\/blog\/wp-content\/uploads\/2009\/11\/DSCN0134.JPG 1200w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/a><p id=\"caption-attachment-87614653\" class=\"wp-caption-text\">Helps if you imagine me going &quot;Borkely-orkely-yobbley-bawk!&quot;<\/p><\/div>\n<h6>* I&#8217;m tellin&#8217; you? With the uptalking?<\/h6>\n<div id=\"_mcePaste\" style=\"overflow: hidden; position: absolute; left: -10000px; top: 382px; width: 1px; height: 1px;\">http:\/\/www.forensicswiki.org\/wiki\/Encase_image_file_format<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Latest Movember photos are on the Mo&#8217;09 photos (there&#8217;s a link to the page at the top of this page.) So, a while ago (really? April of last year?) I wrote about Microsoft&#8217;s new toolkit for police to quickly gather everything they&#8217;d need from a Windows-based workstation, called COFEE.\u00a0 I had a bunch of questions [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,24,7],"tags":[],"class_list":["post-87614650","post","type-post","status-publish","format-standard","hentry","category-general","category-grumpy-old-man","category-software"],"_links":{"self":[{"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/87614650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=87614650"}],"version-history":[{"count":3,"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/87614650\/revisions"}],"predecessor-version":[{"id":87614652,"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/87614650\/revisions\/87614652"}],"wp:attachment":[{"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=87614650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=87614650"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.geckotemple.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=87614650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}