Module-1
Module-1
Cyberspace:
“cyberspace” is where users mentally travel through matrices of data. Conceptually,
“cyberspace” is the “nebulous place” where humans interact over computer networks. The term
“cyberspace” is now used to describe the Internet and other computer networks. In terms of
computer science. “cyberspace” is a worldwide network of computer networks that uses the
Transmission Control Protocol/internet Protocol (TCP/IP) for communication to facilitate
transmission and exchange of data.
Cyberterrorism:
Cyberterrorism is the premeditated, politically motivated attack against information,
computer systems, computer programs and data which result in violence against noncombatant
targets by sub national groups or clandestine agents.
Cybercrime Definition:
Cybercrime can be defined as “a crime conducted in which a computer was directly and
significantly instrumental.” This definition is not universally accepted.
Here is yet another definition: “cybercrime (computer crime) is any illegal behavior, directed by
means of electronic operations, that-targets-the-security of computer systems and the data
processed by them. In a Wider sense, “computer-related crime” can be any illegal behavior
committed by means of, or in relation to, a computer system or network; however, this is not
cybercrime.
Computer-related crime, Computer crime, Internet crime, E-crime; High-tech crime, etc.
are the other synonymous terms. Cybercrime specifically can be defined in a number of ways: a
few definitions are:
1. Crime committed using a computer and the Internet to steal a person's identity (identity theft)
Cybercrime refers to the act of performing a criminal act using cyberspace as the
communications vehicle. Some people argue that a cybercrime is not a crime as it is a crime
against software and not against a person or property.
However, while the legal systems around the world scramble o introduce laws to combat
cybercriminals, two types of attack are prevalent:
1. Techno-crime: A premeditated act against a system or systems, with the intent to copy,
steal, prevent access, corrupt or otherwise deface or damage parts of or the complete computer
system.
2. Techno Vandalism: It is a term used to describe a hacker or cracker who breaks into a
computer system with the sole intent of defacing and or destroying its [Link] Vandals
can deploy 'sniffers' on the Internet to locate soft (insecure) targets and then execute a range of
commands using a variety of protocols towards a range of ports. If this sounds complex - it is!
The best weapon against such attacks is a firewall which will hide and disguise your
organization's presence on the Internet.
+ Hobby hackers;
+ terrorist organizations.
+ Psychological perverts;
Thus, the typical “motives” behind cybercrime seem to be greed, desire to gain power
and/or publicity, desire for revenge, a sense of adventure, looking for thrill to access forbidden
information, destructive mindset and desire to sell network security services.
===============================================================
Classification of Cybercrimes:
[Link] against individual
● Forgery
● Cyberterrorism
● Web jacking
Email Spoofing:
A spoofed E-Mail is one that appears to originate from one source but actually has been sent
from another source.
Spamming:
● Repeating keywords
● Use of keywords that do not relate to the content on the site
● Use of fast meta refresh
● change to the new page in few seconds.
● Redirection
● IP cloaking:
● including related links, information, and terms.
● Use of colored text on the same color background
● Tiny text usage
● Duplication of pages with different URLs
● Hidden links
Cyber defamation:
The tort of cyber defamation is considered to be the act of defaming, insulting, offending or otherwise
causing harm through false statements pertaining to an individual in cyberspace.
Example: someone publishes defamatory matter about someone on a website or sends an containing
defamatory information to all friends of that person. It may amount to defamation when-
● If imputation to a deceased person would harm the reputation of that person, and is intended to be
hurtful to the feelings of his family or other near relatives
● An imputation is made concerning a company or an association or collection of people as such.
● An imputation in the form of an alternative or expressed ironically
● An imputation that directly or indirectly, in the estimation of others, lowers the moral or intellectual
character of that person, or lowers the character of that person in respect of his caste or of his calling,
or lowers the credit of that person.
Types of defamation
When failed to prove, the person who made the allegations may still be held responsible for defamation.
It Occurs when an unauthorized person uses the Internet hours paid for by another person. It
comes under hacking because the person get access to someone else’s ISP user ID and password,
either by hacking or by gaining access to it by illegal means and uses the internet without the
other person’s knowledge. This theft can be identified when Internet time is recharged often,
despite infrequent usage. This comes under “identity theft”.
They are used for committing financial crimes. The alterations made are so insignificant that in a
single case it would go completely unnoticed. Example: a bank employee inserts a program, into
the bank’s server that deduces a small amount from the account of every customer every month.
The unauthorized debit goes unnoticed by the customers, but the employee will make a sizable
amount every month.
Data diddling:
Data diddling involves changing data input in a computer. In other words, information is
changed from the way it should be entered by a person typing in the data. Usually, a virus that
changes data or a programmer of the database or application has pre-programmed it to be
changed. For example, a person entering accounting may change data to show their account, or
that or a friend or family member, is paid in full. By changing or failing to enter the information,
they are able to steal from the company.
Forgery:
The act of forging something, especially the unlawful act of counterfeiting a document or
object for the purposes of fraud or deception. Something that has been forged, especially a
document that has been copied or remade to look like the original. Counterfeit currency notes,
postage, revenue stamps, marksheets, etc., can be forged using sophisticated computers, printers
and scanners.
Web jacking:
This term is derived from the term hi jacking. In these kinds of offenses the hacker gains
access and control over the web site of another. He may even change the information on the site.
The first stage of this crime involves “password sniffing”. The actual owner of the website does
not have any more control over what appears on that [Link] may be done for fulfilling
political objectives or for money.
Hacking:
Every act committed toward breaking into a computer and/ or network is hacking.
Purpose Greed, Power, Publicity, Revenge, Adventure, Desire to access forbidden information,
Destructive mindset. Hacking vs. Cracking - Malicious attacks on computer networks are
officially known as cracking , while hacking truly applies only to activities having good
intentions. Most non-technical people fail to make this distinction, however. Outside of
academia, its extremely common to see the term "hack" misused and be applied to cracks as
well.
Online frauds:
Fraud that is committed using the internet is “online fraud.” Online fraud can involve
financial fraud and identity theft. Online fraud comes in many forms. viruses that attack
computers with the goal of retrieving personal information, to schemes that lure victims into
wiring money to fraudulent sources,
“phishing” s that purport to be from official entities (such as banks or the Internal
Revenue Service) that solicit personal information from victims to be used to commit identity
theft, to fraud on online auction sites (such as Ebay) where perpetrators sell fictional goods.
spoofing to make the user to enter the personal information : financial fraud
Means any visual depiction, including but not limited to the following: Any photograph
that can be considered obscene and/ or unsuitable for the age of child viewer.
Software piracy
Theft of software through the illegal copying of genuine programs or the counterfeiting
and distribution of products intended to pass for the original. It can be done byEnd-user copying,
Hard disk loading with illicit means, Counterfeiting, Illegal downloads from internet.
Getting untested software that may have been copied thousands of times.
No warranty protection
Computer sabotage
In Internet usage, an bomb is a form of net abuse consisting of sending huge volumes of
to an address in an attempt to overflow the mailbox or overwhelm the server where the address is
hosted in a denial-of-service attack. It involves to Construct a computer to repeatedly send to a
specified person’s address. The attacker can overwhelm the recipient’s personal account and
potentially shut down the entire system.
An intrusion detection system (IDS) inspects all inbound and outbound network activity
and identifies suspicious patterns that may indicate a network or system attack from someone
attempting to break into or compromise a system. The practice of strong password can prevent
this type of attacks.
Password sniffing
Password sniffers are programs that monitor and record the name and password of
network users as they login, jeopardizing security at a site. Through sniffers installed, anyone
can impersonate an authorized user and login to access restricted documents.
Credit card fraud is a wide-ranging term for theft and fraud committed using or involving
a payment card, such as a credit card or debit card, as a fraudulent source of funds in a
transaction. The purpose may be to obtain goods without paying, or to obtain unauthorized funds
from an account. Credit card fraud is also an adjunct to identity theft.
Identity theft
Identity theft is a fraud involving another person’s identity for an illicit purpose. The
criminal uses someone else’s identity for his/ her own illegal purposes. Phishing and identity
theft are related offenses
Examples:
Renting an apartment
===========================================================
These criminals take advantage of the widespread and lack of awareness about cybercrimes and
cyberlaws among people who are constantly using the IT infrastructure for official and personal
purposes.
→ Few terminologies
Hacker: A hacker is a person with strong interest in computers who enjoys learning and
experimenting with them. Hackers are usually very talented, smart people who understand
computers better than the others.
Brute force Hacking: it is a technique used to find passwords or encryption keys. It involves
trying every possible combination of letters, numbers, etc., until the code is broken.
Cracker: a cracker is a person who breaks into computers. They are computer criminals. Their
act include vandalism, theft and snooping in unauthorized areas.
Cracking: it is the act of breaking into computers. Cracking is a popular, growing subject on the
internet. Many sites are devoted to supplying crackers with programs that allow them to crack
computers (like guessing passwords)
Cracker tools: these are programs that break into computers. Like password crackers, Trojans,
viruses, war dialers and worms.
Phreaking: this is notorious art of breaking into phone or other communication systems.
War dialer: it is program that automatically dials phone numbers looking for computers on the
other end. It catalogs numbers so that the hackers can call back and try break in.
========================================================
Categories of Cybercrime:
Cybercrime can be categorized based on the following:
I. Crimes targeted at individuals: The goal is to exploit human weakness such as greed
and naivety. These crimes include financial frauds, sale of non-existent or stolen items,
child pornography copyright violation, harassment, etc. with the development in the IT
and the Internet; thus, criminals have a new tool that allows them to expand the pool of
potential victims. However, this also makes it difficult to trace and apprehend the
criminals.
2. Crimes targeted at property: This includes stealing mobile devices such as cell
phone, laptops, personal digital assistant (PDAs), and removable medias (CDs and pcn
drives); transmitting harmful programs that can disrupt functions of the systems and/or
can wipe out data from hard disk, and can create the malfunctioning of the attached
devices in the system such as modem, CD drive, etc.
[Link] targeted at organizations: Cyberterrorism is one of the distinct crimes
against organisations/governments. Attackers (individuals or groups of individuals) use
computer tools and the Internet to usually terrorize the citizens of a particular country by
stealing the private information, and also to damage the programs and files or plant
programs to get control of the network and/or system
4. Single event of cybercrime: It is the single event from the perspective of the victim.
For example, unknowingly open an attachment that may contain virus that will infect the
system (PC/laptop). This is known as hacking or fraud.
5. Series of events: This involves the attacker interacting with the victims repetitively.
For example, attacker interacts with the victim on the phone and/or via chat rooms to
establish relationship first and then they exploit that relationship to commit the sexual
assault.
=============================================
● Passive attacks:
● Involves gathering information about the target without his/ her knowledge.
● It is done usually by internet searches or by googling
○ Google or yahoo search: to locate information about employees
○ Surfing online community group: facebook; to gain information about an
individual
○ Organizations website: for personnel directory or information about key
employees; used in social engineering attack to reach the target
○ Blogs, newsgroups, press releases, etc
○ Going through job postings
● Network sniffing: information on Internet Protocol address ranges, hidden
servers or networks or services on the system.
● Tools used during passive attacks
○ Google earth
○ Internet Archive: permanent access for researchers , historians and
scholars to historical collections
○ Professional community: linkedIn
○ People Search
○ Domain Name Confirmation
○ WHOIS
○ Nslookup
○ Dnsstuff
→Active Attacks :
● It is called as rattling the doorknobs or Active reconnaissance
● Involves probing the network to discover individual hosts to confirm the
information gathered in the passive attack phase. Can provide confirmation to an
attacker about security measures in place.
● Tools used during active attacks
○ Arphound
○ Arping
○ Bing
○ Bugtraq
○ Dig
○ DNStacer
○ Dsniff
○ Filesnarf
○ FindSMB
2. Scanning and Scrutinizing gathered information
Is a key step to examine intelligently while gathering information about the target. The
objectives are:
● Port scanning
● Network scanning
● Vulnerability scanning
Port Scanning:
★ It is the act of systematically scanning a computer's ports.
★ Since a port is a place where information goes into and out of a computer, port scanning
identifies open doors to a computer.
★ It is similar to a thief going through your neighborhood and checking every door and
window on each house to see which ones are open and which ones are locked.
★ There is no way to stop someone from port scanning your computer while you are on
the Internet because accessing an Internet server opens a port, which opens a door to
your computer.
★ There are, however, software products that can stop a port scanner from doing any
damage to your system.
★ TCP (Transmission Control Protocol) and UDP (User Datagram Protocol) are two of
the protocols that make up the TCP/IP protocol suite which is used universally to
communicate on the Internet.
★ Each of these has ports 0 through available so essentially there are more than 65,000
doors to lock.
★ The first 1024 TCP ports are called the Well-Known Ports and are associated with
standard services such as FTP, HTTP, SMTP or DNS.
★ Some of the addresses over 1023 also have commonly associated services, but the
majority of these ports are not associated with any service and are available for a
program or application
★ A port scan consists of sending a message to each port, one at a time. The kind of
response received indicates whether the port is used and can therefore be probed for
weakness.
★ The result of a scan on a port is usually generalized into one of the following categories:
1. Open or accepted : The host sent a reply indicating that a service is listening on the
port.
2. Closed or not listening: The host sent a reply indicating that connections will be
denied to the port
3. Filtered or blocked: There was no reply from the host.
Scrutinizing phase Called as “enumeration” in the hacking world. The objective behind
this step is to identify:
● After scanning and scrutinizing, the attack is launched using the following steps:
○ Crack the password
○ Exploit the privileges
○ Execute the malicious command/ applications
○ Hide the files
○ Cover the track – delete access logs, so that there is no trail of illicit activity.
================================================================
=======================================================
● Use antivirus and anti-spyware :It is important to remove and/or quarantine the viruses.
The settings of these softwares should be done during the installations so that these
softwares get updated automatically on a daily basis.
● Install updates: OS companies issue the security patches for flaws that arc found in
these systems.
● Use firewall : A firewall is a software and/or hardware that is designed to block
unauthorized access while permitting authorized communications. It is a device or set of
devices configured to permit, deny, encrypt, decrypt, or proxy all (in and out) computer
traffic between different security domains based upon a set of rules and other criteria. A
firewall is different from antivirus protection. Antivirus software scans incoming
communications and files for troublesome viruses vis-I-vis properly configured firewall
that helps to block all incoming communications from unauthorized sources.
● Disconnect internet when not in use : Attackers cannot get into the system when the
system is disconnected from the Internet. Firewall, antivirus, and anti-Spyware softwares
are not foolproof mechanisms to get access to the system.
● Downloading the freeware only from websites that are known and trustworthy: It is
always appealing to download free software(s) such as games, file-sharing programs,
customized toolbars, etc. However, one should remember that many free software(s)
contain other software, which may include Spyware.
● Check regularly the folders in the mailbox — "sent items" or "outgoing" — for
those messages you did not send: If you do find such messages in your outbox, it is a
sign that your system may have infected with Spyware, and maybe a part of a Botnet.
This is not foolproof; many spammers have learned to hide their unauthorized access.
● Take an immediate action if your system is infected: if your system is found to be
infected by a virus, disconnect it from the Internet immediately. Then scan the entire
system with fully updated antivirus and anti-Spyware software. Report the unauthorized
accesses to ISP and to the legal authorities. There is a possibility that your passwords
may have been compromised in such cases, so change all the passwords immediately.
================================================================
Attack vector
● An attack vector is a path or means by which a hacker (or cracker) can gain access to a
computer or network server in order to deliver a payload or malicious outcome.
● Attack vectors enable hackers to exploit system vulnerabilities, including the human
element.
● Attack vectors include viruses, attachments, Web pages, pop-up windows, instant
messages, chat rooms, and deception. All of these methods involve programming (or, in a
few cases, hardware), except deception, in which a human operator is fooled into
removing or weakening system defenses.
● To some extent, firewalls and anti-virus software can block attack vectors.
● But no protection method is totally attack-proof.
● A defense method that is effective today may not remain so for long, because hackers are
constantly updating attack vectors, and seeking new ones, in their quest to gain
unauthorized access to computers and servers.
● If vulnerabilities are the entry points, then attack vectors are the ways attackers can
launch their assaults or try to infiltrate the building.
● In the broadest sense, the purpose of the attack vectors is to implant a piece of code that
makes use of a vulnerability. This code is called the payload, and attack vectors vary in
how a payload is implanted.
● The most common malicious payloads are viruses (which can function as their own
attack vectors), Trojan horses, worms, and spyware.
● If an attack vector is thought of as a guided missile, its payload can be compared to the
warhead in the tip of the missile.
● Different ways to launch Attack Vectors:
○ Attack by E-Mail: The hostile content is either embedded in the message or
linked to by the message, Sometimes attacks combine the two vectors, so that if
the message does not get you, the attachment will, Spam is almost always carrier
for scams, fraud, dirty tricks, or malicious action of some kind. Any link that
offers something “free” or tempting is a suspect.
○ Attachments (and other files): Malicious attachments install malicious computer
code. The code could be a virus, Trojan Horse, Spyware, or any other kind of
malware. Attachments attempt to install their payload as soon as you open them.
○ Attack by deception: Deception is aimed at the user/operator as a vulnerable
entry point. It is not just malicious computer code that one needs to monitor.
Fraud, scams, hoaxes, and to some extent. Spam, not to mention viruses, worms
and such require the unwitting cooperation of the computer's operator to succeed.
Social engineering and hoaxes are other forms of deception that are often an
attack vector too
○ Hackers : Hackers: Hackers/crackers are a formidable attack vector because,
unlike ordinary Malicious Code, people are flexible and they can improvise.
Hackers/crackers use a variety of hacking tools, heuristics, and social engineering
to gain access to computers and online accounts. ‘They often install a Trojan
Horse to commander the computer for their own use
○ Heedless guests (attack by webpage): Counterfeit websites are used to extract
personal information, Such websites look very much like the genuine websites
they imitate. One may think he/she is doing business with someone you trust.
However, he/she is really giving their personal information, like address, credit
card number, and expiration date. They are often used in conjunction with Spam,
which gets you there in the first place. Pop-up webpages may install Spyware,
Adware or Trojans.
○ Attack of the worms : Many worms are delivered as E-Mail attachments, but
network worms use holes in network protocols directly. Any remote access
service, like file sharing, is likely to be vulnerable to this sort of worm. In most
cases, a firewall will block system worms. Many of these system worms install
Trojan Horses. Next they begin scanning the Internet from the computer they
have just infected, and start looking for other computers to infect. If the worm is
successful, it propagates rapidly. The worm owner soon has thousands of
“zombie” computers to use for more mischief.
○ Malicious macros: Microsoft Word and Microsoft Excel are some of the
examples that allow macros. A macro does something like automating a
spreadsheet, for example. Macros can also be used for malicious purposes. All
Internet services like instant messaging, Internet Relay Chart (IRC), and P2P file-
sharing networks rely on cozy connections between the computer and the other
computers on the Internet. IF one is using P2P software then his/her system is
more vulnerable to hostile exploits.
○ Foistware (sneakware): Foistware is the software that adds hidden components
to the system on the sly. Spyware is the most common form of foistware.
Foistware is quasi-legal software bundled with some attractive software. Sneak
software often hijacks your browser and diverts you to some “revenue
opportunity” that the foistware has set up.
○ Viruses : These are malicious computer codes that hitch a ride and make the
payload. Nowadays, virus vectors include E-Mail attachments, downloaded files,
worms etc.