Showing posts with label Supraja Sundar. Show all posts
Showing posts with label Supraja Sundar. Show all posts

Friday, 13 January 2017

PREVENTION OF CYBER STALKING


  • Be careful what personal information you share online including in email, on social networking sites like Facebook and Twitter and chat rooms. It is very easy to glean information about where you live, the places you love to go to in your area and the people you care about from posts and pictures.
  • Create a different email account for registering in social networking sites and other online spaces. It will help avoid spam and your personal email won´t be revealed if the online service doesn’t have a good privacy practice.
  • Do not feel obligated to fill out all fields when registering online or provide identifying information such as birthdates and place in required fields.
  • In your online user profile, use a photo that doesn’t identify you or your location, so you can’t be recognised.
  • Consider using a name that is not your real name or a nickname as your email name, screen name or user ID. And try not to use common dates such as your birthday as the digits in your email name or password. Instead, pick a name that is gender- and age-neutral. Treat your email and/or internet account like you would your credit card, ID or passport number – very carefully.
  • If you are breaking up with an intimate partner – especially if they are abusive, troubled, angry or difficult – reset every single password on all of your accounts, from email and social networking accounts to bank accounts, to something they cannot guess.
  • Services such as Facebook change their privacy policy all the time, so it isd idea to check your privacy settings to make sure you are sharing the information you want to share with people you trust and not the general internet public. Some sites have options for you to test how your profile is being viewed by others – test and make sure you only reveal what is absolutely necessary.
  • What information are family and friends posting about you? Let them know your concerns about privacy and help them learn better privacy settings.
  • Do an internet search of your name regularly and monitor where you appear online. If you find unauthorised info about yourself online, contact the website moderator to request its removal.
  • Make sure that your internet service provider (ISP), cell phone service, instant messenger (called internet relay chat, or IRC in some terms of service) network and other services you use has an acceptable privacy policy that prohibits cyberstalking. If they have none, suggest they create one and/or switch to a provider that is more responsive to user privacy concerns and complaints.
  • If you have a blog or personal website you maintain, please read the information on the next page.

What you should do if someone starts stalking you online?
  • Trust your instincts. If you feel uncomfortable or an online situation becomes hostile, remove yourself from the online space by logging off or surfing elsewhere, or block the other person´s access to you.
  • If you are receiving unwanted contact, make clear to that person that you would like him or her not to contact you again. Many women who have reported being harrassed do this and warn that any further contact will result in the filing of a police report. Depending on the harasser, engagement with the person can escalate or cease, so if you consider contact appropriate and necessary, do so once and document it.
  • Save all communications with the stalker for evidence. Do not edit or alter them in any way. Try using print screens, especially if the harrassment is happening in real-time.
  • If the harasser posts comments on your blog, keep copies but also consider unpublishing rather than deleting abusive posts.
  • Keep a record of your communications with internet system administrators or law enforcement officials if you report the stalker to authorities. Record-keeping is absolutely crucial so keep everything, even though the immediate desire might be to delete the communication from the stalker and try to forget about it. Back up these communications on another computer or removable memory stick or external hard drive.
  • Consider blocking or filtering messages from the harasser. Many email programs have a filter feature. Chat room contact can also be blocked, and you can activate the ‘IP address block’ option on your blog or website if someone posts harassing comments continuously.
  • If your internet searches reveal that the stalker is publishing harmful information about you in other online spaces, make a complaint to the moderators/managers of the external site. State that you view this as part of a continuing situation of online harassment towards you, and request that they either block the harrasser’s IP, remove posts, or caution the harrasser to cease or be blocked.
  • Tell your family and friends that someone is stalking you online. Being stalked – online or offline – is a traumatic experience and support from your family and friends is critical at this time to help you cope. Also check what they are revealing about you and their relationship with you in their online spaces, albeit inadvertently.
  • Tell your employer that someone is stalking you if you think this person may harass you in the workplace. Your employer will be more likely to back you up if they receive harassing or questionable messages about you from the cyberstalker, and they may be helpful in mitigating any professional damage.

   Where you are supposed to file a complaint.
  • If harassment continues after you have asked the person to stop and/or the harassment escalates, contact the harasser’s internet service provider. Most ISPs have clear policies prohibiting the use of their services to abuse another person. Often, an ISP can try to stop the conduct by direct contact with the stalker or by closing their account. If you receive abusive emails, identify the domain (after the “@” sign) and contact that ISP. Most ISPs have an email address such as abuse@domain name> or postmaster@domain name> that can be used for complaints. If the ISPhas a website, visit it for information on how to file a complaint. Follow up with the ISP and make sure action is being taken, and keep all communications with the ISP.
  • Check with your own ISP to assist in blocking a stalker’s access to you and consider changing services if they are insensitive to your requests or have no policies.
  • Check out which bodies or agencies are available in your country and community that can investigate and take action in online harassment cases. Contact the police or other relevant agency and inform them of the situation in as much detail as possible, providing copies of your documentation of the harrassment.
  • Remember to keep all communications with police as a record of evidence as well. Depending on your country, harrassment and stalking may not be typified as a crime, or local police may not be aware of recent applications of harassment law to cyberstalking. If you are not finding local recourse, consider appealing to national cyber-police mechanisms and/or women’s safety advocates. If you are having trouble contacting the right body, write to help@takebackthetech.net. We’ll see if we can point you in the right direction.
  Stalking is something which is very popular among common man, even your facebook account can be stalked. In simple words, stalking is nothing but just viewing your account by someone else, but if that  person uses in an illegal way, then it becomes a big problem. They may take the photos you posted and morf your photo with someother person to do some illegal actions against you (blackmail). These things are very common nowadays. So stalking can happen anywhere and by anyone, I request you all to take security measures and keep your account secured  by not letting unwanted people to view your account. First learn to know who all are viewing your profile, be aware about that person who is stalking your profile often, then take necessary actions.

 

SALAMI SLICING


Salami slicing refers to a series of many small actions, often performed by clandestine means, that as an accumulated whole produces a much larger action or result that would be difficult or unlawful to perform all at once. The term is typically used pejoratively. Although salami slicing is often used to carry out illegal activities, it is only a strategy for gaining an advantage over time by accumulating it in small increments, so it can be used in perfectly legal ways as well.

An example of salami slicing, also known as penny shaving, is the fraudulent practice of stealing money repeatedly in extremely small quantities, usually by taking advantage of rounding to the nearest cent (or other monetary unit) in financial transactions. It would be done by always rounding down, and putting the fractions of a cent into another account. The idea is to make the change small enough that any single transaction will go undetected.

DETECTING SALAMI SLICING

There is no software application or algorithm for detection of salami slicing. Identifying this type of publication misconduct is complex because salami publications do not often include text plagiarism so that manuscripts can easily evade strict software checking. Only under the rare circumstances of encountering both the original and the salami manuscript can some editors or reviewers suspect salami publication. Even though there are no objective ways to detect this sort of redundant publication, manuscripts suspected of being salami publications often report on identical or similar sample size, hypothesis, research methodology and results, and very often have the same authors.
An example for salami slicing
 In January 1993, four executives of a rental-car franchise in Florida were charged with defrauding at least 47,000 customers using a salami technique.
In Los Angeles, in October 1998, district attorneys charged four men with fraud for allegedly installing computer chips in gasoline pumps that cheated consumers by overstating the amounts pumped.
In 2008, a man was arrested for fraudulently creating 58,000 accounts which he used to collect money through verification deposits from online brokerage firms a few cents at a time.

Here are few prevention tips for salami slicing, 

• Contrast programs and files that may contain checksums with backup versions to determine the veracity loss.
• Write-protect the diskettes, more than ever when testing an untrusted computer program.
• Prevent booting a hard disk drive system from a diskette.
• While transferring files from one computer to the  another, use diskettes that does not have an executable files that strength  to be infected.
Source: wikipedia
Salami slicing is not so popular, but still it happens in few places. In movies also salami slicing has taken its role, For example movies like SUPERMAN III, HACKERS and OFFICE SPACE, where the special characters are being the role model and inspiration for the younger generations, but even in movies they teach en number of illegal activities which is really not required for real life. actually salami slicing was introduced by orthodox communist leader MATYAS RAKOSI in the year 1940, to describe the action of the Hungarian Communist Party. Then, it was used by the nazi party to attain the full power of Germany in 1933. And now they use it for many unlawful purposes. As I already mentioned humans are capable of doing correct things in a wrong way, each and every thing are used in unlawful way to threaten others and fulfill their own unethical desires.

TYPES OF PHISHING

These are the types of phishing:

·         Deceptive Phishing. The term "phishing" originally referred to account theft using instant messaging but the most common broadcast method today is a deceptive email message. Messages about the need to verify account information, system failure requiring users to re-enter their information, fictitious account charges, undesirable account changes, new free services requiring quick action, and many other scams are broadcast to a wide group of recipients with the hope that the unwary will respond by clicking a link to or signing onto a bogus site where their confidential information can be collected.

·         Malware-Based Phishing refers to scams that involve running malicious software on users' PCs. Malware can be introduced as an email attachment, as a downloadable file from a web site, or by exploiting known security vulnerabilities--a particular issue for small and medium businesses (SMBs) who are not always able to keep their software applications up to date.

·         Keyloggers and Screenloggers are particular varieties of malware that track keyboard input and send relevant information to the hacker via the Internet. They can embed themselves into users' browsers as small utility programs known as helper objects that run automatically when the browser is started as well as into system files as device drivers or screen monitors.

·         Session Hijacking describes an attack where users' activities are monitored until they sign in to a target account or transaction and establish their bona fide credentials. At that point the malicious software takes over and can undertake unauthorized actions, such as transferring funds, without the user's knowledge.

·         Web Trojans pop up invisibly when users are attempting to log in. They collect the user's credentials locally and transmit them to the phisher.

·         Hosts File Poisoning. When a user types a URL to visit a website it must first be translated into an IP address before it's transmitted over the Internet. The majority of SMB users' PCs running a Microsoft window operating system first look up these "host names" in their "hosts" file before undertaking a Domain Name System (DNS) lookup. By "poisoning" the hosts file, hackers have a bogus address transmitted,taking the user unwittingly to a fake "look alike" website where their information can be stolen.

·         System Reconfiguration Attacks modify settings on a user's PC for malicious purposes. For example: URLs in a favorites file might be modified to direct users to look alike websites. For example: a bank website URL may be changed from "bankofabc.com" to "bancofabc.com".

·         Data Theft. Unsecured PCs often contain subsets of sensitive information stored elsewhere on secured servers. Certainly PCs are used to access such servers and can be more easily compromised. Data theft is a widely used approach to business espionage. By stealing confidential communications, design documents, legal opinions, employee related records, etc., thieves profit from selling to those who may want to embarrass or cause economic damage or to competitors.

·         DNS-Based Phishing ("Pharming"). Pharming is the term given to hosts file modification or Domain Name System (DNS)-based phishing. With a pharming scheme, hackers tamper with a company's hosts files or domain name system so that requests for URLs or name service return a bogus address and subsequent communications are directed to a fake site. The result: users are unaware that the website where they are entering confidential information is controlled by hackers and is probably not even in the same country as the legitimate website.

·         Content-Injection Phishing describes the situation where hackers replace part of the content of a legitimate site with false content designed to mislead or misdirect the user into giving up their confidential information to the hacker. For example, hackers may insert malicious code to log user's credentials or an overlay which can secretly collect information and deliver it to the hacker's phishing server.

·         Man-in-the-Middle Phishing is harder to detect than many other forms of phishing. In these attacks hackers position themselves between the user and the legitimate website or system. They record the information being entered but continue to pass it on so that users' transactions are not affected. Later they can sell or use the information or credentials collected when the user is not active on the system.

·         Search Engine Phishing occurs when phishers create websites with attractive (often too attractive) sounding offers and have them indexed legitimately with search engines. Users find the sites in the normal course of searching for products or services and are fooled into giving up their information. For example, scammers have set up false banking sites offering lower credit costs or better interest rates than other banks. Victims who use these sites to save or make more from interest charges are encouraged to transfer existing accounts and deceived into giving up their details.
Source: wikipedia

The important types of phishing have been covered and explained, they are still many types of phishing, but these are the main types of phishing which has to be covered and published.

 

COMPUTER FORGERY


The next important crime we are going to discuss is  computer forgery.

Any person who creates, alters, or deletes any data contained in any computer or computer network, who, if such person has created altered, or deleted a tangible document or instrument would have committed forgery shall be guilty of the crime of computer forgery.

Here is an example for Computer Forgery,

Type of Case: family law
Court: Tarrant County in Fort Worth, TX
Plaintiff: Jane Doe
Defendant: Richard Roe

Description: Jane Doe and Richard Roe divorced. Once Richard Roe had remarried, a few years later Jane Doe decided to sue Richard Roe for additional assets. Jane Doe presented a document, purported to be a contract outside of the divorce decree between Richard Roe and her. This case was filed as a civil suit and was referred back to Family Court.

Summary

Timeline
Purported contract signed: June 5, 2003
Divorce finalized: June 20, 2003
Jane Doe purchased new computer: June 1, 2005
Suit filed: September 26, 2005

Claims of Plaintiff
Jane Doe claimed the contract was provided to her by Richard Roe in return for her agreeing to the divorce settlement. Jane Doe further claimed the contract was lost by her,  only to be rediscovered just prior to her filing the suit.

Defendants’ Response
Richard Roe claims the contract was a forgery.

Computer Forensic Evidence Recovered

There were three computers available to Jane Doe on which the purported contract could have been created. Only one of the computers contained information to support Richard Roe’s claims. Jane Doe purchased a new computer on June 1, 2005 but did not begin to install the computer until June 10, 2005. On June 28, 2005, Jane Doe performed her first login on the new computer.

Protegga was able to recover, more than seven months after the document was deleted, in excess of 75% of the purported contract from Jane Doe’s new computer system. Data was recovered from both unallocated file system space and from slack space at the end of newer files. While all metadata was completely overwritten, and, therefore, not recoverable, a timeline was established based upon dates that data was overwritten and from the Microsoft Windows Registry.

Through a detailed analysis of the computer system, it was verified that the contract was created between the dates of June 28, 2005 and July 3, 2005. Further editing continued until August 31, 2005. The computer forensic evidence indicated that at least six different edits occurred from July 20, 2005 to August 31, 2005.

Through interviews with Richard Roe and his new spouse, Protegga learned that Richard Roe, his new spouse, and his two children were on a 14-day pleasure cruise during the time frame in which the contract was created.

Jane Doe created a purported contract, she used it as a weapon to get some of Roe’s assets. The contract was adjusted to three pages and the final page had Richard Roe’s signature, which helped her in a greater way to cheat him. Doe was clever enough to make it with an accurate timeline so that no one could suspect her. Through computer forensic evidence they proved  that was a fake contract and Doe created it between the dates of  JUNE 28, 2005 and JULY 3, 2005.

 

This is an accurate example for computer forgery. In this world we have to be clever enough to prove ourselves correct and the opponent is guilty, you got to be aware about the fraudulent behaviour of others which would affect yourself, some may even try to destroy your identity. I hope everyone will be alert and prevent yourself from such activities. PREVENTION IS BETTER THAN CURE. 

Wednesday, 7 December 2016

HACKING CCTV CAMERAS


Hacking is the main part of Cyber crime, which we are talking about, for the past few days. So here, it is about hacking of cameras, which is considered to be a very big crime, as people tend to do some unwanted/ criminal activities by hacking surveillance cameras.
Now let me ask you a simple question. Do you think your CCTV cameras are physically safer? No... Actually they aren’t! They seem to be safer, but some hackers used to hack without your knowledge, by using simple techniques.
New research from cloud-based video surveillance company cloud view suggest that the majority of CCTV systems can be hacked, providing an open door to cyber attacks.
A report says that they are major vulnerabilities in DVR-based CCTV systems and cloud-based video systems as well. Humans are more talented in doing these things. Those hackers easily hijack connection to the device’s IP address, putting a lot people’s property and their data at risk.
Hackers usually have special knowledge to hijack ones data. Any device that is not secured is targeted and they attack.
A research by ANDREW TIERENEY, an independent consultant, said that, “It can easily provide a gateway to their entire network, enabling anyone with malicious intent to corrupt all their systems or extract huge amounts of data.”
The traditional DVR-based systems had a problem of port forwarding and dynamic DNS and also firmware updates like leaving the device open to backdoors. According to the report, one device was hacked within few minutes, while the rest were done and dusted within a day. They didn’t say which device was the first, and the last to fall, though. CCTV cameras are even hacked through android phones. There is actually an app called Angry IP scanner, hackers downloads that app, which is accessible for entire foremost Operating system.
 In a movie, they actually showed how to hack a surveillance camera through mobile, the person is actually a student who stays in hostel, he goes out every night, since he shouldn’t be noticed, he hacked all the cameras for few seconds, by that time he goes out of the campus. Even in movies they teach how to hack cameras, without their knowledge they exploit others. There are many websites which teaches hacking. They even show videos, which exactly tells how hackings are done. And these apps should be banned, as it makes people to indulge in unwanted activities. I request everyone to be aware about the hackers, they don’t seem to be noticeable but within few minutes they hack your cameras and can delete some of the important recordings.