<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Want Some COFEE? Microsoft Computer Online Forensic Evidence Extractor</title>
	<atom:link href="http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Sun, 07 Sep 2008 16:56:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-124580</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Sat, 16 Aug 2008 09:40:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-124580</guid>
		<description>Hmm helix looks good akin to Knoppix STD (There was a good distro, shame it hasn't been updated much), I'll have to give it a go. I remember I posted on this ages ago with my Changlinn moniker, I changed to my real name as there is no point, I am the only one that uses Changlinn so it is easy enough to trace back to me.
I saw some of these windows tools, they are horribly crippled compared to their OSS counterparts. Netmon, pahlease give me wireshark and libpcap capable routers anyday.</description>
		<content:encoded><![CDATA[<p>Hmm helix looks good akin to Knoppix STD (There was a good distro, shame it hasn&#8217;t been updated much), I&#8217;ll have to give it a go. I remember I posted on this ages ago with my Changlinn moniker, I changed to my real name as there is no point, I am the only one that uses Changlinn so it is easy enough to trace back to me.<br />
I saw some of these windows tools, they are horribly crippled compared to their OSS counterparts. Netmon, pahlease give me wireshark and libpcap capable routers anyday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-124493</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Wed, 13 Aug 2008 11:32:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-124493</guid>
		<description>Helix.. Yah. I heard about that great tool too. Added tools you can use in forensics, the FTK imager, Mediawiper, and Firefly write blocker.</description>
		<content:encoded><![CDATA[<p>Helix.. Yah. I heard about that great tool too. Added tools you can use in forensics, the FTK imager, Mediawiper, and Firefly write blocker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Howard</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123126</link>
		<dc:creator>Howard</dc:creator>
		<pubDate>Wed, 21 May 2008 04:23:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123126</guid>
		<description>Mr davenix........Please explain</description>
		<content:encoded><![CDATA[<p>Mr davenix&#8230;&#8230;..Please explain</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: davenix</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123125</link>
		<dc:creator>davenix</dc:creator>
		<pubDate>Tue, 20 May 2008 23:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123125</guid>
		<description>I am guessing 3/4 of you are total fanboy, script kiddy douchenozzles...and the other 1/4 are IT managers who know nothing.</description>
		<content:encoded><![CDATA[<p>I am guessing 3/4 of you are total fanboy, script kiddy douchenozzles&#8230;and the other 1/4 are IT managers who know nothing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Howard</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123073</link>
		<dc:creator>Howard</dc:creator>
		<pubDate>Sat, 17 May 2008 20:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123073</guid>
		<description>Let me ask the silly question....Would this be a good tool for the beginner because reading all of the comment it might have goods and bads....How did you learn,I fell on my but sometimes before succeding and I think most of us have.I am not an expert but a newbie that is still filtering and is loking for good training and if the case be falling software.I am reluctant to say good or bad but is it something we can learn from so we dont make up tools that are not the best in the land.

You know if I continue to listen to all here I will learn faster than any program,no one holds back excellant setup Darknet thanks</description>
		<content:encoded><![CDATA[<p>Let me ask the silly question&#8230;.Would this be a good tool for the beginner because reading all of the comment it might have goods and bads&#8230;.How did you learn,I fell on my but sometimes before succeding and I think most of us have.I am not an expert but a newbie that is still filtering and is loking for good training and if the case be falling software.I am reluctant to say good or bad but is it something we can learn from so we dont make up tools that are not the best in the land.</p>
<p>You know if I continue to listen to all here I will learn faster than any program,no one holds back excellant setup Darknet thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Allen</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123055</link>
		<dc:creator>Robert Allen</dc:creator>
		<pubDate>Thu, 15 May 2008 19:24:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123055</guid>
		<description>Don't forget about Helix... &lt;a href="http://www.e-fense.com/helix" rel="nofollow"&gt;http://www.e-fense.com/helix&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t forget about Helix&#8230; <a href="http://www.e-fense.com/helix" rel="nofollow">http://www.e-fense.com/helix</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123052</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Wed, 14 May 2008 18:30:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123052</guid>
		<description>@ Roger Halbheer

Thanks for the added info, but I guess we are really more interrested in what you put on the stick.</description>
		<content:encoded><![CDATA[<p>@ Roger Halbheer</p>
<p>Thanks for the added info, but I guess we are really more interrested in what you put on the stick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roger Halbheer</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123051</link>
		<dc:creator>Roger Halbheer</dc:creator>
		<pubDate>Wed, 14 May 2008 14:07:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123051</guid>
		<description>Sorry, that I did not come back earlier. I had some days off and was on the road. You said that you want more info on my blog. I am not sure whether I cover all your needs (no, there is no list with all the commands) but there you go: http://blogs.technet.com/rhalbheer/archive/2008/05/14/support-for-law-enforcement-and-cofee.aspx
Roger</description>
		<content:encoded><![CDATA[<p>Sorry, that I did not come back earlier. I had some days off and was on the road. You said that you want more info on my blog. I am not sure whether I cover all your needs (no, there is no list with all the commands) but there you go: <a href="http://blogs.technet.com/rhalbheer/archive/2008/05/14/support-for-law-enforcement-and-cofee.aspx" rel="nofollow">http://blogs.technet.com/rhalbheer/archive/2008/05/14/support-for-law-enforcement-and-cofee.aspx</a><br />
Roger</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mik3NL</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123031</link>
		<dc:creator>Mik3NL</dc:creator>
		<pubDate>Tue, 13 May 2008 14:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123031</guid>
		<description>;)

Does the term "U3 Switchblade" ring a bell to anyone here?

Needed:
---------
* U3 USB key
* Universal Costumizer (for modding the U3 bootdisk)
* VNC/keyloggers/PWDump/nirsoft.net etc!  (You get the picture!)
* some batch scripting power
* Windows machines with autorun enabled! ;)
* Imagination!

No need for RT's or anything..</description>
		<content:encoded><![CDATA[<p> <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Does the term &#8220;U3 Switchblade&#8221; ring a bell to anyone here?</p>
<p>Needed:<br />
&#8212;&#8212;&#8212;<br />
* U3 USB key<br />
* Universal Costumizer (for modding the U3 bootdisk)<br />
* VNC/keyloggers/PWDump/nirsoft.net etc!  (You get the picture!)<br />
* some batch scripting power<br />
* Windows machines with autorun enabled! <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
* Imagination!</p>
<p>No need for RT&#8217;s or anything..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/05/want-some-cofee-microsoft-computer-online-forensic-evidence-extractor/#comment-123026</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Tue, 13 May 2008 04:22:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=849#comment-123026</guid>
		<description>Just thought I'd recommend a good program for those of you on a computer that you can log into and can run .msi/.exe programs.

Its called SIW.

This program will basically tell you about every aspect of the computer including saved password, registry keys used for all the software, WEP/WPA keys, hardware, etc etc. You get where I'm going with this.</description>
		<content:encoded><![CDATA[<p>Just thought I&#8217;d recommend a good program for those of you on a computer that you can log into and can run .msi/.exe programs.</p>
<p>Its called SIW.</p>
<p>This program will basically tell you about every aspect of the computer including saved password, registry keys used for all the software, WEP/WPA keys, hardware, etc etc. You get where I&#8217;m going with this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
