FOCA (Fingerprinting Organizations with Collected Archives), is a free tool by informatica64 of Spain, which is intended for extracting and analyzing the hidden info of some particular file types. DEFCON 17 released a descriptive presentation called Tactical Fingerprinting using metadata, hidden info and lost data using FOCA. Audio, Slides, White Paper Here.
Some related tools, such as Libextractor/Metagoofil/OOMetaExtractor, were also referred in the slides, with solutions and useful defending tips discussed.
Functions
- Search for documents in Google and Bing
- Automatic file downloading
- Capable of extracting Metadata, hidden info and lost data
- Cluster information
- Analyzes the info to fingerprint the network.
Target File Types
*.doc, *.docx, *.ppt, *.pptx, *.pps, *.ppsx, *.xls, *.xlsx, *.odp, *.odt, *.ods, *.odg, *.pdf, *.wpd, *.sxw, etc.
What FOCA extract
- Metadata: Information stored to give information about the document. (Creator, Organization, etc.)
- Hidden information: Information internally stored by programs and not editable. (Template paths, Printers, database structure, etc.)
- Lost data: Information which is in documents due to human mistakes or negligence, because it was not intended to be there. (Links to internal servers, data hidden by format, etc.)
Continue reading ‘FOCA: Deeper Mining of Particular File Types’




