Showing posts with label Haritha Venkat.. Show all posts
Showing posts with label Haritha Venkat.. Show all posts

Friday, 13 January 2017

PREVENTION OF CYBER DEFAMATION


How do you avoid being sued for defamation? That’s easy. Don’t ever say anything interesting. If you do want to say something that might reflect negatively on someone else, there is always a chance that they will sue you for defamation.

It doesn’t matter how careful you are. Some people will sue out of spite or revenge, or to cause you financial pain, or because they feel they have to be seen to defend their reputation.

Some will sue to try to force you to retract, even though they know you’re right. Some sue for sport. But it’s rare. Usually people don’t sue, even when they have been defamed.

Still, defamation lawsuits, when they occur, are usually expensive, technical, drawn-out, stressful affairs. You are better off avoiding them if you can. So it makes sense to minimise the risks. You can do that by writing in a way that makes it hard to sue you.

Here are my twelve golden rules for minimising the risks of getting sued for defamation.

1. Be aware of what you’re saying

In defamation cases, you are liable not just for what you say expressly, but what ordinary people will read between the lines. You are also liable for publishing a defamatory statement made by someone else, even if you quote them accurately. You need to identify any “stings” in what you write the barbs that affect someone’s reputation. What will ordinary, reasonable, fair-minded people take it to mean?

2. Control the meaning

The first battle in a defamation case is usually over what the words mean. Don’t leave this to chance. Plaintiffs like to exploit ambiguity, claiming that the audience will understand it in a defamatory sense. You should try to eliminate ambiguity and convey your meaning precisely.

3. Only say what you can prove

Truth is usually the most important defence in a defamation claim. Ask yourself what evidence you could put before a court if someone challenged you, and how convincing that evidence would be.

Do you have sources? Are they credible? Do they have first-hand knowledge? Would they be willing to give evidence? If you’re relying on documents, do you have someone who can authenticate them?

4. Pick the right “tier” of meaning

Many defamatory statements involve some sort of accusation or allegation. The courts distinguish between different “tiers” of allegation, depending on how equivocally the accusation is put. At one end is an allegation of guilt – Jack is corrupt.

Next down is the suggestion that there are reasonable grounds to believe or suspect guilt – Jack is suspected of corruption; or Is Jack corrupt? Then there is an inference that there are reasonable grounds for inquiry – Police should investigate whether Jack is corrupt. It’s much easier to prove a third tier meaning like this than a first tier one. You only need evidence pointing to guilt rather than proof of it.

Rules 1 and 2 above suggest that you should pick out the tier that you know you can prove.

The safest thing to do is to use the exact language of the courts: There are reasonable grounds to suspect Jack is corrupt. That may be clunky, but it will seldom leave any ambiguity for plaintiffs to exploit.

5. Say what you don’t know

This follows from the above rules. If you are open with your audience about what you don’t know, and what you’re not alleging, then it’s very hard for a plaintiff to argue that readers will take more from it than that.

6. Use the language of opinion

There’s a defence called honest opinion (it used to be fair comment) for those who are expressing genuine opinions on accurate facts that are set out or understood by the audience. So make it clear that you’re expressing or republishing a view.

Say “I think”, “he believes”, “she reckons”, “they claim”. Say whose opinion it is. Use phrases that are evaluative, not factual – “I think his behaviour was disgraceful”. Use rhetorical questions rather than assertions of fact. Use visuals to clue readers in to the fact that they’re getting opinions, as in a letters to the editor page.

Instead of making factual allegations, use the word “seems” or “appears” (Jack seems to be corrupt), which at least opens the door for an opinion defence.

7. Make sure the opinion is based on true facts

Ideally, you should set those facts out, and keep them separate from the opinion. The facts don’t need to justify the opinion, they just need to provide a platform for it, so that the audience can tell it’s an opinion and have some idea about what it concerns.

If the facts are already in the public domain, you don’t need to do more than nod toward them.

8. Put them together

Why not take advantage of several defences at once? Jack is a police officer, I saw him at a caf being given a package by Nick; shortly afterward, the charges against Nick were dropped and Jack bought a yacht, so I think there are reasonable grounds to suspect Jack of corruption.

9. Take particular care with allegations of criminality and allegations about what’s going on in someone’s mind

If you’re accusing someone of a crime, or of (for example) lying, you need to have particularly strong evidence. It is difficult to prove someone’s state of mind, so you are better off talking about the person’s conduct itself (what she said was false/misleading) rather than stating baldly that she lied.

10. Take advantage of privilege defences

The Defamation Act lists a set of events that are more or less safe to report on: council meetings, press conferences, public inquiries and the like.

Even if people are slagging each other during those occasions, you are insulated from defamation if you report on them in a fair and accurate manner and in good faith. Get familiar with these rules.

You should also note that you have slightly more leeway in publishing criticisms of politicians, as long as you’re engaging in genuine political discussion and acting responsibly.

11. Act ethically

In many ways, this is your best protection against a lawsuit. If you act ethically, you’re less likely to make defamatory mistakes. If you do, the people you defame are less likely to sue you.

If they do sue, you’re more likely to have a defence. Even if you don’t have a defence, the judge and jury are likely to be sympathetic to you and damages are likely to be lower. How do you act ethically? Conduct obvious checks. Don’t rely on biased sources. Don’t say more than you know. Put your criticisms to those you are criticising before you publish, and include their responses. Be measured.

Be prepared to issue a correction and apology if you get something wrong. These steps will also position you well to argue for a defence of qualified privilege. Although this defence is in flux, it may be available to publications on matters of public interest where the publisher has acted responsibly.

You should try to position yourself to take advantage of the possibility that this defence will be available.

12. Bear in mind who you’re dealing with

Some people are much more likely to sue than others. Politicians, for example. Business people. Celebrities. People whose reputation is important to their livelihood and have the resources to take action. Also, take extra care writing about police and journalists. And, of course, lawyers.

 


 

CREDIT CARD AND CHEQUE FRAUD


Here we are going to talk about credit card and cheque fraud happening around this world.

First, what a credit card fraud is?

Credit card fraud is a wide-ranging term for theft and fraud committed using or involving a payment card, such as a credit card or debit card, as a fraudulent source of funds in a transaction. The purpose may be to obtain goods without paying, or to obtain unauthorized funds from an account. Credit card fraud is also an adjunct to identity theft. According to the United States Federal Trade Commission, while the rate of identity theft had been holding steady during the mid 2000s, it increased by 21 percent in 2008. However, credit card fraud, that crime which most people associate with ID theft, decreased as a percentage of all ID theft complaints for the sixth year in a row.

People misuse credit cards and they purchase merchandise for thousands of dollars before the card holder realizes his card has been stolen. The only common security measure on all cards is a signature panel, but, depending on its exact design, a signature may be relatively easy to forge. Some merchants will demand to see a picture ID, such as a driver's license, to verify the identity of the purchaser, and some credit cards include the holder's picture on the card itself. In some jurisdictions, it is illegal for merchants to demand card holder identification. Self-serve payment systems (gas stations, kiosks, etc.) are common targets for stolen cards, as there is no way to verify the card holder's identity. There is also a new law that has been implemented that identification or a signature is only required for purchases above $50, unless stated in the policy of the merchant. This new law makes it easier for credit card theft to take place as well because it is not making it necessary for a form of identification to be presented, so as long as the fraud is done at what is considered to be a small amount, little to no action is taken by the merchant to prevent it.

Famous credit card attacks.

Between July 2005 and mid-January 2007, a breach of systems at TJX Companies exposed data from more than 45.6 million credit cards. Albert Gonzalez is accused of being the ringleader of the group responsible for the thefts.In August 2009 Gonzalez was also indicted for the biggest known credit card theft to date — information from more than 130 million credit and debit cards was stolen at Heartland Payment Systems, retailers 7-Eleven and Hannaford Brothers, and two unidentified companies.

In 2012, about 40 million sets of payment card information were compromised by a hack of Adobe Systems. The information compromised included customer names, encrypted payment card numbers, expiration dates and information relating to orders Chief Security Officer Brad Arkin said.

In July 2013, press reports indicated four Russians and a Ukrainian were indicted in New Jersey for what was called “the largest hacking and data breach scheme ever prosecuted in the United States.” Albert Gonzalez was also cited as a co-conspirator of the attack, which saw at least 160 million credit card losses and excess of $300 million in losses. The attack affected both American and European companies including Citigroup, Nasdaq OMX Group, PNC Financial Services Group, Visa licensee Visa Jordan, Carrefour, J. C. Penny and JetBlue Airways.

Between 27 November 2013 and 15 December 2013 a breach of systems at Target Corporation exposed data from about 40 million credit cards. The information stolen included names, account number, expiry date and Card security code.

From 16 July to 30 October 2013, a hacking attack compromised about a million sets of payment card data stored on computers at Neiman-Marcus. A malware system, designed to hook into cash registers and monitor the credit card authorisation process (RAM-scraping malware), infiltrated Target’s systems and exposed information from as many as 110 million customers.

On September 8, 2014, The Home Depot confirmed that their payment systems were compromised. They later released a statement saying that the hackers obtained a total of 56 million credit card numbers as a result of the breach.

On May 15, 2016, in a coordinated attack, a group of around 100 individuals used the data of 1600 South African credit cards to steal 12.7 million USD from 1400 convenience stores in Tokyo within three hours. Using a Sunday and acting in another country than the bank which issued the cards, they are believed to have won enough time to leave Japan before the heist was discovered]

Second, what a cheque fraud is?

Cheque fraud refers to a category of criminal acts that involve making the unlawful use of cheques in order to illegally acquire or borrow funds that do not exist within the account balance or account-holder's legal ownership. Most methods involve taking advantage of the float (the time between the negotiation of the cheque and its clearance at the cheque-writer's bank) to draw out these funds. Specific kinds of cheque fraud include cheque kiting, where funds are deposited before the end of the float period to cover the fraud, and paper hanging, where the float offers the opportunity to write fraudulent cheques but the account is never replenished.

Types of cheque fraud

Cheque kiting

Embezzlement

Bad cheque writing

Abandonment

Combating cheque fraud

In most jurisdictions, passing a cheque for an amount of money the writer knows is not in the account at the time of negotiation (or available for overdraft protection) is usually considered a violation of criminal law. However, the general practice followed by banks has been to refrain from prosecuting cheque writers if the cheque reaches the bank after sufficient funds have been deposited, thereby allowing it to clear. But the account holder is normally held fully liable for all bank penalties, civil penalties, and criminal charges allowable by law in the event the cheque does not clear the bank.

Only when the successful clearance of a cheque is due to a kiting scheme does the bank traditionally take action. Banks have always had various methods of detecting kiting schemes and stopping them in the act. Computer systems in place will alert bank officials when a customer engages in various suspicious activities, including frequently depositing cheque bearing the same, large monthly total deposits accompanied by near-zero average daily balances, or avoidance of tellers by frequent use of ATMs for deposits.

New technology in place today may make most forms of cheque kiting and paper hanging a thing of the past. As new software rapidly catches illegal activity at the teller/branch level instead of waiting for the nightly runs to the back office, schemes are not only easier to detect, but may be prevented by tellers who deny customers illegal transactions before they are even started.

Part of how banks are combating cheque fraud is to offer their clients fraud protection services. Because it is impossible for banks to know every cheque that a customer writes and which may or may not be fraudulent, the onus is on the clients to make the bank aware of what cheques they write. These systems allow customers to upload their cheque files to the bank including the cheque number, the amount of money, and in some cases, the payee name. Now, when a cheque is presented for payment, the bank scrubs it against the information on file. If one of the variables does not match, then the cheque would be flagged as a potentially fraudulent item.

These services help with external fraud but they do not help if there is internal fraud. If an employee sends information to the bank with fraudulent items, then the bank would not know to deny payment. A system of dual controls should be put into place in order to not allocate all capabilities to one person.

Before the passage of the Check Clearing for the 21st Century Act when cheques could take 3 or more days to clear, playing the float was fairly common practice in the USA in otherwise-honest individuals who encountered emergencies right before payday.

Circular and abandonment frauds are gradually being eliminated as cheques will clear in Bank B the same day they are deposited into Bank A, giving no time at all for non-existent funds to become available for withdrawal. With image-sharing technology, the funds that temporarily become available in Bank A's account are wiped out the same day.

While there may still be some room for retail kiting, security measures taken by retail chains are helping reduce such incidents. Increasingly, more chains are limiting the amount of cash back received, the number of times cash back can be offered in a week or a given period of time, and obtaining transactional account balances before offering cash back, thereby denying it to those with low balances. For example, Walmart's policy is to determine account balances of those obtaining cash back, and some Safeway locations will not offer cash back on any accounts with balances under $250, even when funds are sufficient to cover the amount on the cheque. Customers who are noted to obtain cash back frequently are also investigated by the corporation to observe patterns.

Some businesses will also use the cheque strictly as an informational device to automatically debit funds from the account, and will return the item to the customer thereafter. However, in the United States this is done through the Automated Clearing House (ACH); though faster than traditional check clearing, contrary to popular belief the ACH is not instantaneous. Though this practice reduces the room for kiting (by reducing float), it does not always eliminate it.

These frauds are happening everywhere in this world. This is to make people to be aware about the cases that might really destroy you. Make sure you handle your credit and debit cards safely and do not take it out in unwanted places and take care of your belongings. Make a complaint as soon as possible, when you realise you lost your card, so that the bankers will block the card, which eventually ensures no transactions through that card.

Saturday, 10 December 2016

VIRUS DISSEMINATION


For the past few days we were talking about hacking of devices, today we are going to talk about virus dissemination.




 In today's world where everyone is attached with the tools and applications of the modern era, where the technology facilitates every persons in all aspects throughout the world in different manners according to their goals and objectives. In the process to facilitate the people in this era Internet and Network Technologies plays a great role the main role of this is it combines and connects people in a couple of seconds no matter how far they are physically.



Internet facilitates peoples in Business, Banking, Education, Medical, Bio-Medical Technologies, Security Personnel, Government bodies etc etc. so in this global mess there are several kinds of risks involved. This main risk and threat is on information sharing and UN-authorize access of the information, Simply called Hacking.



There are three types of Hackers White Hat hackers, Grey Hat hackers and Black Hat hackers in this post i.e. related to Virus Dissemination we are talking about Black Hat Hackers.

BLACK HAT HACKERS:



Black Hat Hackers are the persons also know as "Intruders" who hackers the information that is not for them simply the stole the information and compromises the computer systems by using various kinds of tools and techniques. This is not an issue that we start talking here about the tolls and techniques they are using to hack the information simply want to say that "If you think that you have a safe lock where you keep the important things safely, then there is a key you have to access the safe after locking it". It's just like if there is a lock then there should a key to open it if there is no key then there is no safe or secure mechanism to call a safe, lock or anything else.



Virus Dissemination is a process of a Malicious software that attaches itself to other software. (virus, worms, Trojan Horse, Time bomb, Logic Bomb, Rabbit and Bacterium are examples of malicious software that destroys the system of the victim.



Several Trojan-generator tools enable hackers to create their own Trojans. Such toolkits help hackers construct Trojans that can be customized. These tools can be dangerous and can backfire if not executed properly. New Trojans created by hackers usually have the added benefit of passing undetected through virus-scanning and Trojan-scanning tools because they don’t match any known signatures. Some of the Trojan kits available in the wild are Senna Spy Generator, the Trojan Horse Construction Kit v2.0, Progenic Mail Trojan Construction Kit, and Pandora’s Box.



Viruses and worms can be used to infect a system and modify a system to allow a hacker to gain access. Many viruses and worms carry Trojans and backdoors. In this way, a virus or worm is a carrier and allows malicious code such as Trojans and backdoors to be transferred from system to system much in the way that contact between people allows germs to spread.


A
virus and a worm are similar in that they’re both forms of malicious software (malware). A virus infects another executable and uses this carrier program to spread itself. The virus code is injected into the previously benign program and is spread when the program is run. Examples of virus carrier programs are macros, games, email attachments, Visual Basic scripts, and animations. A worm is similar to a virus in many ways but does not need a carrier program. A orm can self-replicate and move from infected host to another host. A worm spreads from system to system automatically, but a virus needs another program in order to spread.

Viruses and worms both execute without the knowledge or desire of the end user.


Types of virus



Viruses are classified according to two factors: what they infect and how they infect. A virus can infect the following components of a system:

i) System sectors

ii) Files

iii) Macros (such as Microsoft Word macros)

iv) Companion files (supporting system files like DLL and INI files)

v) Disk clusters

vi) Batch files (BAT files)

vii) Source code

A virus infects through interaction with an outside system. Viruses need to be carried by another executable program. By attaching itself to the benign executable a virus can spread fairly quickly as users or the system runs the executable. Viruses are categorized according to their infection technique, as follows:


Polymorphic Viruses These viruses encrypt the code in a different way with each infection and can change to different forms to try to evade detection.  

Stealth Viruses These viruses hide the normal virus characteristics, such as modifying the original time and date stamp of the file so as to prevent the virus from being noticed as a new file on the system.  

Fast and Slow Infectors These viruses can evade detection by infecting very quickly or very slowly. This can sometimes allow the program to infect a system without detection by an antivirus program.  

Sparse Infectors These viruses infect only a few systems or applications.

Armored Viruses These viruses are encrypted to prevent detection.  

Multipartite Viruses These advanced viruses create multiple infections.  

Cavity (Space-Filler) Viruses These viruses attach to empty areas of files.  

Tunneling Viruses These viruses are sent via a different protocol or encrypted to prevent detection or allow it to pass through a firewall.  

Camouflage Viruses These viruses appear to be another program.  

NTFS and Active Directory Viruses These viruses specifically attack the NT file system or Active Directory on Windows systems.



Note: This information is purely for educational purpose not for any experimental or destructive purpose or to effect any organization, government and any other person. So please kindly do not use it in unethical manner. Rest you will find yourself in trouble.