module 3 (1)
module 3 (1)
b) Hoax emails:
These are deliberate attempts to deceive or trick a user into believing or accepting that
something is real when the whole actor knows it is false.
● It is difficult to sometimes recognize whether an E-mail is spam or a hoax. The
websites mentioned below can be used to check the validity of such hoax emails.
1. [Link].
2. [Link]
To maximize the chances that a recipient respond, the phisher might employ any or
all of the following tactics:
1. Names of legitimate organizations: Instead of creating a phony company from scratch, the
phisher might use a legitimate company's name and incorporate the look and feel of its website
(i.e., including the color scheme and graphics) into the Spam E-Mail.
2. “From" a real employee: Real name of an official, who actually works for the organization,
will appear in the "from" line or the text of the message (or both). This way, if a user contacts the
organization to confirm whether "Rajeev Arora" truly is "Vice President of Marketing" then the
user gets a positive response and feels assured.
[Link] that "look right”: The E-Mail might contain a URL (.e., weblink) which seems to be
legitimate website wherein user can enter the information the phisher would like to steal.
However, in reality the website will be a quickly cobbled copycat - a "spoofed website that looks
like the real thing, that is, legitimate website. In some cases, the link might lead to selected pages
of a legitimate website - such as the
real company's actual privacy policy or legal disclaimer.
[Link] messages: Creating a fear to trigger a response is very common in Phishing attacks -
the E-Mails warn that failure to respond will result in no longer having access to the account or
E-Mails might claim that organization has detected suspicious activity in the users' account or
that organization is implementing new privacy software for ID theft solutions.
Methods of phishing:
1. Dragnet:
● This method involves use of spammed emails bearing falsified corporate identification
which are addressed to a large group of people to websites or popup windows with
similarly falsified identification.
● Dragnet fishers do not identify specific prospective victims in advance.
● When the victim clicks on the links in the body of the e-mail. They are taken to the
websites or pop up windows where they are requested to enter bank or credit card
account date or other personal data.
2. Rod and reel:
● In this method, features identify specific prospective victims in advance and convey false
information to them to prompt their disclosure of personal financial data.
3. Lobster pot :
● This method focuses upon use of spoofed websites.
● It consists of creating bogus or phony websites similar to legitimate corporate ones,
targeting a narrowly defined class of victims.
● These attacks are also called content injection phishing.
● Phisher places a web link into an e-mail message to make it look more legitimate and
which takes the victim to a phony scam site which looks exactly like the official site.
● These fake sites are called spoof websites which can steal personal data.
4. Gillnet:
● In this technique. The phishers introduce malicious codes into emails and websites.
● Thick and misuse browser functionality by injecting hostile content into another site's
popup window.
● By opening such emails, the victims will be having Trojen horse introduced into their
systems.
● The malicious code will change the settings in the user system so that users who want to
visit legitimate banking websites will be redirected to look a like phishing sites.
● In other cases, the malicious code will record users keystrokes and passwords when they
visit legitimate banking sites and then transmit those data to freshers for later illegal
access to the user's financial accounts.
Phishing techniques:
● A phishing toolkit is a set of scripts or programs that allows a phisher to automatically set
up phishing websites that spoof the legitimate websites of different brands, including the
graphics displayed on these websites.
● Phishing toolkits are developed by groups or individuals and are sold to the underground
economy.
● These sophisticated kits are typically difficult to obtain or quite expensive and are more
likely to be purchased and used by well organized groups of phishers rather than average
users.
● Fishers use hypertext preprocessor PHP to develop fishing kits.
● Most of the fishing kits are advertised and distributed at no charge and they are also
called DIY fishing kits.
● These kits hide the back doors through which the phished information is sent to recipients
other than the intended users.
● It is used to refer to fraud that involves someone pretending to be someone else to steal
money or get other benefits.
● The person whose identity is used can suffer various consequences when he or she is held
responsible for the perpetrators actions.
● The ID theft is a punishable offense under the Indian IT Act, section 66C and section
66D.
● Federal Trade Commission, (FTC) has provided the statistics about each one of the
identity fraud mentioning prime frauds presented below.
● Card fraud. 26%.
● Bank fraud 17%.
● Employment fraud 12%.
● Government fraud 9%.
● Loan fraud 5%.
1 There is no way to protect yourself The risk of identity theft can be minimized by taking preventive
from identity theft. measures such as keeping financial records duly protected and
private.
2 Identity theft is only a financial Financial identity theft is theft of information for financial gain,
crime. which is most prevalent. However, other types of identity theft
are also equally dangerous.
3 It is my bank's fault if I become a Majority of the identity theft begins when personal information
victim of identity theft. may be stolen with low technology tools such as lost or stolen
wallet, checkbook, or a debit card or credit card. Oregon. More
highly technological methods such as skimming, phishing and
hacking.
4 It is safe to give your personal It is never safe to give personal information to unsolicited callers,
information over the phone if your no matter who they say they are.
caller ID confirms that it is your
bank.
[Link] Myth Fact
1 There is no way to protect yourself The risk of identity theft can be minimized by taking preventive
from identity theft. measures such as keeping financial records duly protected and
private.
5 Checking your credit card If anyone wants to be vigilant about identity theft, one should
periodically or using a credit check their credit card regularly and one should also review their
monitoring service is all you need bank and credit card statements regularly.
to do to protect yourself from
identity theft.
6 My personal contact information is That could be used by a thief to impersonate you should be
not valuable to an identity thief. protected.
7 Shredding my mail and other Shredding documents that contain personal information before
personal documents will keep me you throw them away is a great way to protect yourself from
safe. dumpster diving, which occurs when attackers search the trash
for personal information.
8 I don't use the Internet, so my Your personal information appears in more places. Like medical
personal information is not records, job applications, or school emergency contact forms.
exposed online.
9 Networking is safe. Social networking sites such as Facebook, Myspace, Twitter can
be fun to use. However, they are very dangerous when it comes
to your identity.
10 It is not safe to shop or bank Less social networking, shopping and banking online are safe as
online. long as you use common sense and make good choices about
where and how you do it.
2. Classified information.:
Confidential.: Information that requires protection and an unauthorized
disclosure could damage national security.
Secret: That requires substantial protection, and unauthorized disclosure could
seriously damage national security.
Top secret: Information that requires the highest degree of production and
unauthorized disclosure could severely damage national security.
==============
Techniques of ID theft:
Identity theft can affect all aspects of a victim's daily life and often occurs far from its
victims. The attackers use both traditional that is human-based methods as well as computer
based techniques.
1. Human based methods: Others are techniques used by an attacker without and/or or minimal
use of technology.
● Direct access to information: Have earned a certain degree of trust. Can obtain
legitimate access to a business or to a residence to steal the required personal
information.
● Dumpster diving: Retrieving documents from trash bins is very common.
● Theft of a purse or a wallet: While it often contains bank credit cards, debit cards,
driving license, medical insurance, identity card and many important documents. Pick
Pocketers, steal the wallets and in turn sell the personal information.
● Mail theft and rerouting: It is easy to steal the postal mails from mailboxes which has
pure security mechanism and all the documents available for the fraudster are free of
charge. Example bank mail. Administrative forms or partially completed credit offers.
The fraudster can use your name and other information that may prove to be harmful for
an individual in the near future.
● Shoulder surfing: Two lighter around the public facilities such as cyber cafes, near
ATMs and telephone booths can keep an eye to grab the personal information.
● False or disguised ATMs, (skimming): Just as it is possible to imitate a bank ATM, it is
also possible to install miniature equipment on valid ATM. This equipment captures the
card information using which duplicate card can be made and personal identification
number (PIN )can be obtained by stealing the camera films.
● Used or mistreated employees: An employee or partner with access to the personal file,
salary information, insurance files, or bank information can gather all sorts of
confidential information and can use it to provide sufficient damage.
● Telemarketing and fake telephone calls: This is an effective method for collecting
information from unsuspecting people. The caller who makes a cold call asks the victim
to verify account number immediately on the phone, often without much explanation and
verification. This attack is known as vishing.
[Link] based techniques: These techniques are attempts made by the attacker to exploit
the vulnerabilities within existing processes or systems.
● Backup theft: This is the most common method. In addition to stealing equipment from
private buildings, attackers also strike public facilities such as transport areas, hotels and
recreation centers. They get fully analyzed on equipment or backups, or recover the data.
● Hacking, unauthorized access to systems, and database theft: Besides stealing the
equipment or hardware, criminals attempt to compromise information systems with
various tools, techniques, and methods to gain unauthorized access to download the
required information.
● Phishing: Steals sensitive information through email.
● Farming: The attacker setup typo or matching domain names of the target and install
websites with similar look and feel. Hence, even if a user types incorrect URL, the user
gets the website with. The same look and feel.
● Redirectors: These are the malicious programs that redirect users' network traffic to
locations they did not intend to visit.
● Hardware: The attacker uses the hardware equipment that will be inserted into the
systems that can steal the identity of the users.
==============
Types of identity theft
Identity is stolen in order for someone to commit the crime. ID theft is related to many
areas.
1. Financial identity theft.
2. Criminal identity theft.
3. Identity cloning.
4. Business identity theft.
5. Medical energy theft.
6. Synthetic identity theft.
7. Child identity theft.
3. Identity cloning :
● Identity cloning may be the scariest variation of all ID theft.
● Instead of stealing the personal information for financial gain or committing
crimes in the victim's name, identity clones compromise the victim’s life by
actually living and working as the victim.
● Identity cloning is the act of a fraudster living a natural and unusual life similar to
victim’s life may be a different location.
● An Identity Clone will obtain as much information about the victim as possible.
● Identity Clone want as much personal information about the victim as they can
attain.
● The application of a computer for investigating computer based crime has little
development of a new field called computer forensics. Sometimes computer forensics is
also referred to as digital forensics.
● The computer forensics experts need digital evidence in cases involving data acquisition,
preservation, recovery, analysis and reporting, intellectual property theft, Computer
Misuse, Corporate policy violation, mobile device data acquisition and analysis,
malicious software application into your system, encrypted, deleted and hidden Files
recovery, confidential information leakage etc.
● Forensic science is the application of science to law, and it is ultimately defined by use in
court.
● The basic idea behind ensuring 'chain of custody' is to ensure that the evidence is not
tampered with.
● In a broader perspective, evidence includes everything that is used to determine or
demonstrate the truth of an assertion.
● Evidence can be used in court to convict people who are believed to have committed
crimes.
● Therefore, evidence must be handled in a careful manner to avoid later allegations of
tampering or misconduct that can compromise the case.
● The purpose behind recording the chain of custody is to establish the integrity of the
evidence.
● The police officer or detective will take charge of a piece of evidence, documents, its
collection and hand it over to an evident clerk for storage in a secure place.
● All such transactions, as well as easy succeeding transactions between evidence
collection and its appearance in court need to be completely documented to withstand
legal challenges to the authenticity of the evidence.
● The documentation must include conditions under which the evidence is collected, the
identity of all those who handled the evidence, duration of the evidence, custody security
conditions while handling or storing the evidence, and the manner in which evidence is
transferred to subsequent constraints each time such a transfer occurs.
========================
CYBER FORENSICS AND DIGITAL EVIDENCE:
There are number of contexts involved in actually identifying a piece of digital evidence:
[Link] context: It must be definable in its physical form. That is, it should reside on a
specific piece of media.
2. Logical context: It must be identifiable as to its logical position, that is, where does it reside
relative to the file system.
3. Legal context: We must place the evidence in the correct context to read it its meaning. It
may require looking at the evidence as machine language, for example ASCII code.
The path taken by digital evidence can be conceptually depicted as shown below.
The digital forensics process starts from preparation of the evidence to testifying it.
The following figure shows the process model for understanding seizure and handling of
forensics evidence legal framework.
Tools that are used to generate reports for code should be validated. There are many tools to be
used in the process. One should determine the proper tool . To be used based on the case.
Broadly speaking, a four and six life cycle involves the following phases.
1. Preparation and identification.
2. The collection and recording.
3. Storing and transporting.
4. Examination or investigation.
5 Analysis, Interpretation, and attribution.
6 Reporting.
7 Testifying.