<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>E-Discovery and Microsoft Technology : POP3</title><link>http://blogs.technet.com/ediscovery/archive/tags/POP3/default.aspx</link><description>Tags: POP3</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>POP! Goes the Evidence.</title><link>http://blogs.technet.com/ediscovery/archive/2008/07/18/pop-goes-the-evidence.aspx</link><pubDate>Fri, 18 Jul 2008 07:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3090472</guid><dc:creator>chris.chalmers</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ediscovery/comments/3090472.aspx</comments><wfw:commentRss>http://blogs.technet.com/ediscovery/commentrss.aspx?PostID=3090472</wfw:commentRss><description>&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;Who could resist a catchy title like this: "Court-ordered forensic search of CEO's laptop?"&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When I first saw that, I immediately wondered, "Just how many Michael Bolton MP3s were on there?"&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But if you read the tale of Treppel v. Biovail on the K&amp;amp;L Gates E-discovery blog, you'll discover a far less insidious finding (unless "This is the Time: The Christmas Album" was involved).&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;The Judge ordered the defendants to produce documents (email) in "native format," and wouldn't you know it, the documents weren't forthcoming - even after a couple of trips to the backup tapes. The court noted that the “unique procedure” by which the CEO’s email was downloaded to his personal laptop and then deleted from Biovail's servers resulted in his email not being preserved on the backup tapes. The forensic scan was ordered in an attempt to retrieve the emails, since they weren't available by less onerous means.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;See the original post here: (&lt;A href="http://www.ediscoverylaw.com/2008/04/articles/case-summaries/inadequate-preservation-efforts-necessitate-restoration-and-production-of-email-from-backup-tapes-and-forensic-search-of-ceos-laptop/" mce_href="http://www.ediscoverylaw.com/2008/04/articles/case-summaries/inadequate-preservation-efforts-necessitate-restoration-and-production-of-email-from-backup-tapes-and-forensic-search-of-ceos-laptop/"&gt;http://www.ediscoverylaw.com/2008/04/articles/case-summaries/inadequate-preservation-efforts-necessitate-restoration-and-production-of-email-from-backup-tapes-and-forensic-search-of-ceos-laptop/&lt;/A&gt;)&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-WEIGHT: bold; FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;Intentionally configuring your email system with a "unique procedure" so messages don't get backed up?&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;This should be interesting. Setting aside the legal implications of a "shred all" retention policy for the moment, let's see how that would work in Exchange 2007. Since I have absolutely no knowledge of which email server the defendant actually used, let's take the generic case of Contoso Corporation, our make-believe company running a very real Exchange 2007 server. &lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;If you want to copy the email &lt;EM&gt;off&lt;/EM&gt; the server to read later, you need to copy it &lt;EM&gt;on&lt;/EM&gt; to the client laptop. There are three protocols for clients to retrieve email from Exchange servers: POP3 (Post Office Protocol), IMAP4 (Internet Message Access Protocol), and MAPI (Messaging API, sometimes called MAPI/RPC). &lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;By default, Outlook uses MAPI to retrieve email: Email is always on the server, the Outlook client merely provides an easy way to manage and control it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If the Outlook client is using "Cached Exchange Mode," then there are two copies of each email: one on the laptop, and one on the server. (Outlook has technology to keep the two copies in sync).&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;POP is different. The email client has the option to "leave email on the server" which is a lot like MAPI or IMAP. But if the client hasn't chosen to "leave email on the server," then it is deleted as soon as the client has downloaded it. &lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;&lt;SPAN style="FONT-WEIGHT: bold"&gt;Is it hard to do?&lt;/SPAN&gt; &lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;Not in the least. The Exchange Administrator needs to do two things: 1) Enable the Client Access servers to support POP (it's turned off by default), and 2) enable the user's mailbox to allow POP access. &lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;1) Here's the instructions for enabling POP3. As usual, it's a one-liner in PowerShell:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;(&lt;A href="http://technet.microsoft.com/en-us/library/bb124934(EXCHG.80).aspx" mce_href="http://technet.microsoft.com/en-us/library/bb124934(EXCHG.80).aspx"&gt;http://technet.microsoft.com/en-us/library/bb124934(EXCHG.80).aspx&lt;/A&gt;)&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-WEIGHT: bold; FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;Set-service msExchangePOP3 -startuptype automatic&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;2) And here's the instructions for enabling a user for POP. Another one-liner:&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-WEIGHT: bold; FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;Set-CASMailbox -identity&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;"Don Hall" -Popenabled $true&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;The only gotcha is having to restart the POP service each time you enable new users (yet another one-liner) (&lt;A href="http://technet.microsoft.com/en-us/library/bb124578(EXCHG.80).aspx" mce_href="http://technet.microsoft.com/en-us/library/bb124578(EXCHG.80).aspx"&gt;http://technet.microsoft.com/en-us/library/bb124578(EXCHG.80).aspx&lt;/A&gt;)&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-WEIGHT: bold; FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;Did the forensic scan of the CEO's laptop find anything?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;It's not clear from the K&amp;amp;L Gates blog post, but it's quite possible something incriminating was uncovered. Craig Ball, a certified computer forensic examiner, lays out some concrete steps for a client-side email scan in his "4 on Forensics: 4 Articles on Computer Forensics for Lawyers" at&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;A href="http://www.craigball.com/CF4_0807.pdf" mce_href="http://www.craigball.com/CF4_0807.pdf"&gt;http://www.craigball.com/CF4_0807.pdf&lt;/A&gt;. Favorite spots on the laptop&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;to search include Microsoft Outlook caches like the .ost file and .pst files, as well as other email clients' equivalent folders.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;And in the ultimate irony, the server may STILL have copies of the email, even after configuring it for POP. Exchange 2007 has a "Deleted Items Retention" feature, where emails that users have deleted aren't really erased for another 14 days. This feature is designed to keep sys admins from pulling their hair out when end users call looking for email they accidentally erased. &lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="FONT-SIZE: 11pt; MARGIN: 0in; FONT-FAMILY: Calibri"&gt;In the end, POP3 works like an actual magic trick. It provides the illusion of making something disappear, but in actuality it's just hidden behind another curtain.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3090472" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ediscovery/archive/tags/Exchange+2007/default.aspx">Exchange 2007</category><category domain="http://blogs.technet.com/ediscovery/archive/tags/POP3/default.aspx">POP3</category></item></channel></rss>