All the latest UK technology news, reviews and analysis

Red faces as Cofee spills onto the net

by Dave Neal

09 Nov 2009

Comment: 1

  • Tweet this
crime scene
Cofee is designed to help the police track down computer criminals

In an ironic twist of fate, Microsoft's Computer Online Forensic Evidence Extractor (Cofee) crime scene reporting tool has leaked onto the net.

According to the security firm Sophos and other reports, copies of the tool have surfaced on a file sharing site, and users are already downloading it. Cofee is designed to be used by crime scene investigators, letting them download the contents of a suspicious computer without the need to insert a USB key.

Microsoft describes the system thus: "Computer Online Forensic Evidence Extractor (Cofee) is designed exclusively for use by law enforcement agencies. Cofee brings together a number of common digital forensics capabilities into a fast, easy-to-use, automated tool for first responders. And Cofee is being provided — at no charge — to law enforcement around the world."

Should it fall into the wrong hands it could prove a useful tool for data harvesters and thieves, security experts warn.

"The ability to grab a perfect copy of data from a PC without interfering with a computer is attractive to the computer crime authorities - and it's especially handy when more and more drives are using encryption and strong passwords to prevent unauthorised access," wrote Sophos senior technology consultant Graham Cluley, in his blog.

"But at the same time, you can probably understand why Microsoft might wish to control who can get their paws on the software."

Cluley warned that as well as using Cofee to assist them in their own malicious activities, criminals could and write their own code that " neutralises" Cofee or wipes sensitive data from their computer if they determine the tool is being run on their own machine.

"That might make life difficult for the computer cops when they try to dash-and-grab data from a suspicious PC," he added.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

0%

11%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Application Security SME, Penetration Tester / Ethical Hacker

Application Security SME, Penetration Tester / Ethical...

Java Developer

Java Developer Thomas Cook Online is the business unit...

Contract Systems Administrator, Windows £320 per day

Contract Systems Administrator, Southampton My...

PHP Web Developer, PHP, to £30k + 30% bonus

PHP Web Developer required to join my market-leading...

To send to more than one email address, simply separate each address with a comma.