Crimes at Cyber Headlines

Thursday, January 24, 2013

If You're Using 'Password1,' Change It. Now.

By Stacy Cowley | CNNMoney.com – Wed, 31 Oct, 2012 8:01 AM EDT



The number one way hackers get into protected systems isn't through a fancy technical exploit. It's by guessing the password.

That's not too hard when the most common password used on business systems is "Password1."

There's a technical reason for Password1's popularity: It's got an upper-case letter, a number and nine characters. That satisfies the complexity rules for many systems, including the default settings for Microsoft's widely used Active Directory identity management software.

Security services firm Trustwave spotlighted the "Password1" problem in its recently released "2012 Global Security Report," which summarizes the firm's findings from nearly 2 million network vulnerability scans and 300 recent security breach investigations.

Around 5% of passwords involve a variation of the word "password," the company's researchers found. The runner-up, "welcome," turns up in more than 1%.

Easily guessable or entirely blank passwords were the most common vulnerability Trustwave's SpiderLabs unit found in its penetration tests last year on clients' systems. The firm set an assortment of widely available password-cracking tools loose on 2.5 million passwords, and successfully broke more than 200,000 of them.

Verizon came up with similar results in its 2012 Data Breach Investigations Report, one of the security industry's most comprehensive annual studies. The full report will be released in several months, but Verizon previewed some of its findings at this week's RSA conference in San Francisco.

Exploiting weak or guessable passwords was the top method attackers used to gain access last year. It played a role in 29% of the security breaches Verizon's response team investigated.

[Related: Smartphone Features You Don't Really Need]

Verizon's scariest finding was that attackers are often inside victims' networks for months or years before they're discovered. Less than 20% of the intrusions Verizon studied were discovered within days, let alone hours.

Even scarier: Few companies discovered the breach on their own. More than two-thirds learned they'd been attacked only after an external party, such as a law-enforcement agency, notified them. Trustwave's findings were almost identical: Only 16% of the cases it investigated last year were internally detected.

So if your password is something guessable, what's the best way to make it more secure? Make it longer.

Adding complexity to your password -- swapping "password" for "p@S$w0rd" -- protects against so-called "dictionary" attacks, which automatically check against a list of standard words.

But attackers are increasingly using brute-force tools that simply cycle through all possible character combinations. Length is the only effective guard against those. A seven-character password has 70 trillion possible combinations; an eight-character password takes that to more than 6 quadrillion.

Even a few quadrillion options isn't a big deal for modern machines, though. Using a $1,500 computer built with off-the-shelf parts, it took Trustwave just 10 hours to harvest its 200,000 broken passwords.

"We've got to get ourselves using stuff larger than human memory capacity," independent security researcher Dan Kaminsky said during an RSA presentation on why passwords don't work.

He acknowledged that it's an uphill fight. Biometric authentication, smartcards, one-time key generators and other solutions can increase security, but at the cost of adding complexity.

"The fundamental win of the password over every other authentication technology is its utter simplicity on every device," Kaminsky said. "This is, of course, also their fundamental failing." To top of page.

For source: Click Here

Saturday, November 6, 2010

Police chief warns of rise in cyber crime

Britain is facing a rising tide of online crime such as bank fraud committed by computer hackers, the country's most senior policeman has warned. 

By Alastair Jamieson


Sir Paul Stephenson, the Metropolitan Police Commissioner, said organised crime gangs were increasingly turning to the internet in pursuit of illegal profits.

Writing in the Sunday Telegraph he said forces faced with a budget squeeze should not cut specialists tacking such complex crimes in order to maintain bobbies on the beat, adding "Uniform officers alone will not keep the streets safe."


Sir Paul said it would be "fundamentally misguided" to scale back efforts against internet crime when the growth of online shopping and banking has made Britons more vulnerable than ever to electronic fraud.

He warned: "My investigators tell me the expertise available to law enforcement is thin, compared to the skills they suspect are at the disposal of cyber criminals."



The warning comes after 11 suspects were charged last week in London, and 37 in New York, at the culmination of the year-long Operation Trident Breach investigation involving the Met and the FBI.Detectives believe a global fraud ring stole $70 million (£44 million) from online bank accounts using the Zeus Trojan, malicious software spread by email which infected thousands of computers and gained access to passwords.

Five more suspects arrested in the Ukraine were said to be kingpins.

In a separate case, another major cyber fraud trial will begin next week.

Sir Paul said organised criminals were "waking up to the profits and uses of e-crime" as an easier way to extort larger sums of money, adding: "The modern Tony Soprano-style crime lord will have a cyber expert on hand."

Yet he disclosed that of the 385 officers in England and Wales dedicated to online work, 85 per cent are fighting people-trafficking and child pornography – leaving fewer than 60 to fight financial crimes such as bank fraud.

Police forces are braced to bear their share of public sector budget cuts, with the Police Federation saying that as many as 40,000 jobs might be axed across England and Wales over the next four years.

Warning against political pressure to maintain the number of uniformed officers, Sir Paul said specialists working on e-crimes were "unseen officers, as far as the public and some politicians are concerned".

"Some commentators argue that we should concentrate on uniformed policing and draw back from specialised work that could be done by others," he said.

"Leave cyber crime to the banks and retailers to sort out, the argument runs. It's a fundamentally misguided argument.

"If the debate about police cutbacks gets bogged down in arguments about 'uniforms before specialists' we will not serve the public well."

He added that online fraud caused "deep distress" to victims and "threatens the integrity of our modern economy".

The Met's e-crime unit cost £2.75 million to run last year, but online fraud generated an estimated £52 billion worldwide in 2007.

It is estimated that the global 'virtual task force' of which the Met is part prevented £21 in potential theft for every £1 spent on it.

Sir Paul said police were only tackling 11 per cent of the 6,000 organised crime groups in England and Wales "in an operationally meaningful way".


source: Telegraph.co.uk

Friday, November 5, 2010

CYBER CRIME & YOU Part 1 ….. be vigilant you could be the next victim By Akubo Patricia NYSC MDGs Corps Member

A new report by the Internet Crime Complaint Center has named Nigeria, Africa’s largest telecom market by investment and subscription, number three in the world, and the top African nation in the U.S. Agency’s cybercrime rankings. This means that Nigeria has the highest number of cybercrime incidents in Africa and is right behind the U.S. and the U.K which have larger populations. The publicity surrounding Nigerian cybercrime is raising fears that the country may face a slowdown in international investment in the telecom as well as the financial sectors.
As more Africans use the internet for their banking needs, the number of fraudsters eyeing people’s bank accounts and online financial transactions has also multiplied.
The United Nations Office on Drugs and Crimes estimates that Nigeria has lost millions of dollars through cybercrime, and Nigerians have been impoverished through the activities of these fraudsters.
Characteristics of Cyber Fraud
•altering computer input in an unauthorized way. This requires little technical expertise and is not an uncommon form of theft by employees altering the data before entry or entering false data, or by entering unauthorized instructions or using unauthorized processes;
•altering, destroying, suppressing, or stealing output, usually to conceal unauthorized transactions: this is difficult to detect;
•altering or deleting stored data;
•altering or misusing existing system tools or software packages, or altering or writing code for fraudulent purposes. This requires real programming skills and is not common.
Other forms of fraud may be facilitated using computer systems, including bank fraud, identity theft, extortion, and theft of classified information.
A variety of Internet scams target consumers direct.

source: letsrealize.wordpress.com

Cyber crime poses threat to E-commerce

The past 12 months have been a banner year for cyber crime. And that could be bad news for the future of e-commerce.
“At current trends, in three or four years people will start to think twice about transacting on the Web, individuals and businesses,” said Michael Fraser, director of the communications law centre at the University of Technology Sydney.
“The way it’s trending now, the Web could be so full of rubbish that people won’t trust it,” Fraser said. “That could destroy the potential of the whole knowledge economy, which so many developed economies are counting on for the competitive advantage.”

According to antivirus maker Symantec, 87 percent of e-mail traffic in the past year was spam, compared to just under 70 percent in 2008. More than 40 trillion spam messages were sent according to Symantec, which monitors about a third of the world’s e-mail traffic. That’s about 5,000 spam messages for every person on the planet.
More of that spam is harboring malicious software, or “malware,” — 2 percent of spam contained malware, a 900 percent increase from the previous year.
Malware comes in a variety of forms that can search computers for bank information and personal details for identity theft, or hijack computers to become foot soldiers in a spamming army of zombie “botnets” — often unbeknownst to the owner. In Australia alone, an estimated 10 percent of computers are infected with malware, Fraser said. “And we’re relatively low because we have less (broadband penetration) than many other countries,” he said.
The past year saw an explosion of individuals on social networking sites such as Facebook having their accounts compromised and spam being sent to friends within their network.
In this way, cyber criminals have made the attacks more personal because they are sending out messages appropriating victims’ names, says Marian Merritt, an Internet safety advisor for Norton, the antivirus brand produced by Symantec. “In the past, people felt annoyed by spam, they didn’t really feel a sense of being attacked,” Merritt said. “But if your Facebook account is hacked, it’s embarrassing.”
The past year has seen the rise of “scareware” — malware that parrots a legitimate antivirus software program and then infects the computer with “the very malware it purports to protect against,” a Symantec report said. For a 12-month period ending June 30, Symantec received 43 million reports of scareware installation attempts.
“That took a lot of us in the industry by surprise the past year,” Merritt said. “You get a pop-up ad saying, ‘you have multiple viruses’ then asks you to download the antivirus software. Once you download those programs, they hold you hostage.”
The speed of news
The past year saw the rising speed and popularity of malware spam and Web sites with touts related to current events and celebrity news. “Who killed Michael Jackson?” “Get swine flu medicine here” and “Full eBook Harry Potter” were some popular online traps to open dangerous e-mail attachments or be directed to Web sites’ malware.
“If you want to know what spam will be hitting tomorrow, look at Google Trends today,” said Merritt, referring to Google’s site that shows hot topics and searches by its users.
One of the most alarming incidents in 2009 for governments and policy makers was the July 4 attacks on U.S. government sites, such as the White House, the New York Stock Exchange and Nasdaq — followed a few days later by similar attacks on Web sites in South Korea. According to a research paper by antivirus maker McAfee, both attacks were made by the same “botnet” of 50,000 computers, which spammed targets with so many e-mails their IT systems were overwhelmed.
Fact Box
Cybercrime Prevention
– Have antivirus software, anti-spyware and firewall
– Never respond to spam
– Don’t open suspicious emails or attachments
– Never provide passwords or personal information to unsolicited emails or Web sites
– When asked to ‘allow’ or ‘deny’ an application access to the Internet, choose deny unless you are confident in the safety of the site you are accessing
– When shopping or banking online, make sure website contains an “s” after http (as in https) . Look for the ‘lock’ icon in lower right corner
Sources: Symantec and Trend Micro
North Korea was suspected as the originator of the attack, leading Dmitiri Alperovitch, vice president of threat research at McAfee, to suggest one motivation of the attack “could have been to test the impact of flooding South Korean networks and the transcontinental communications between the U.S. government … (which) would provide them with a significant advantage in case of a surprise attack.”
The attack highlights the problem of security on the Internet — a transnational attack, using commercial services and tens of thousands of personal computers. To fight the attacks would take strong local and international laws on cyber security, a great deal of cooperation among commercial providers and effective systems to report the crimes — none of which is happening today, Fraser said.
“The community doesn’t know where to turn to when these crimes occur, and the police don’t know how to report it or record it, and prosecutors and court systems have a hard time coping with cases that involve gigabytes of evidence,” he said.
Looking ahead to 2010, antivirus maker Trend Micro predicts that there will be more attacks on Mac operating systems. Previously ignored by malware makers because of its relatively low market share, the booming popularity of iPhones is drawing the attention of cybercriminals.
“As the mobile OS landscape changes, and with devices comprising a huge amount of memory and storing a host of sensitive data, devices such as the iPhone and Google Android may increase as popular targets for bad guys,” Trend Micro reports in its December report, “the Future of Threats and Threat Technologies.”
The introduction this year of domain names in languages other than English — such as Russian, Chinese and Arabic — will also expand the hunting grounds for cyber crime, Trend Micro reports.

Report finds huge boom in online crime

Canadians are more likely to be a victim of crime on the web than on the streets, says a new survey commissioned by the Canadian Association of Police Boards.

 

OTTAWA - Canadians are more likely to be victims of crime on the Internet than they are on the streets, suggests a new survey commissioned by the Canadian Association of Police Boards.

Cyber crime - things such as identity theft, computer viruses and online harassment - is very close to surpassing illicit drugs as the top crime category in North America.

The survey, completed last January by Deloitte LLP, found that nearly half of the 567 respondents had been victims of cyber crime, and 70 per cent said they did not report the crime.

Almost everyone surveyed - 95 per cent - thought they were being targeted by cyber criminals.

“If that doesn’t scare you, I don’t know what will scare you,” said Calgary police Chief Rick Hanson during a news conference Wednesday.

“It’s huge and it’s getting worse,” said Ian Wilms, chair of the Canadian Association of Police Boards. “You lock your door at night time, but people don’t, when online, just take the 30 seconds to update the security patches on their computer.”

The report finds that the number of incidents has increased dramatically since 2001.

“The pool of victims grows larger every day while the pool of perpetrators also gets larger, younger and more sophisticated . . . this is a new era for police, fighting a new type of criminal,” said Wilms in a statement.

Staff Sgt. Dick Nyehuis, head of the Calgary Police Electronics Surveillance Unit, says his department has seen a 1,239 per cent increase in seized computers over the past three years.

“We’ve now seen that there is a need for an online presence so we can monitor website and chat rooms to try and look for and identify people who could be a danger,” said Nyehuis.

“It’s a growing industry and I think it’s going to take a different approach right across Canada to address it,” said Calgary police Chief Rick Hanson.

“We’ve known for some time that it’s a growing crime threat, locally and nationally and internationally. I think this survey shows that more needs to be done.

“Is it a surprise to us? No. But like anything else our resources need to grow with the magnitude of the problem.”

Digital law expert Michael Geist says the numbers seem a little inflated and that could pose a problem for law enforcement.

“It suggests that there is widespread concern about the issue,” said Geist.

“If we’re thinking about how we prioritize law enforcement and address these issues, we need to focus on whether there is significant financial harm or whether personal safety or personal privacy is put at risk.”

The most common definition of cyber crime is broad - a criminal offense involving a computer, meaning that major issues such as child pornography and fraud are lumped in the same category as viruses and spam.

Still, Wilms stressed that action is needed sooner rather than later.

“We can’t afford to let the Internet become a no man’s land.”

Tom Keenan, a University of Calgary professor of computer science said the good news is people are becoming more aware of cybercrime.

“The bad news is we’re not getting quite to the point where people take all the right precautions. We’re kind of locking the front door but then leaving the back door open.”

With files from the Calgary Herald

Friday, October 22, 2010

Computer Security Expert Busted for Spreading Viruses

By ThirdAge News Staff
Posted October 22, 2010 9:06 PM
 

Computer security expert, Matthew Anderson, is looking at a prison term, for spreading computer viruses.
The 33-year-old from Aberdeenshire, Scotland, has admitted being a key member of a sophisticated international gang of hackers.
He abused his knowledge to target hundreds of businesses with spam containing hidden viruses.


His criminal activities were discovered by Scotland Yard, which led an investigation into the viruses.
The gang, known online as the m00p group, were discovered infecting computers using viruses attached to unsolicited commercial emails.

The Scotsman reports that Anderson composed and distributed millions of spam messages with virus attachments before distributing them.
The viruses ran in the background on an infected computer and allowed Anderson to access private and commercial data stored on them. He was also able to activate webcams, effectively spying on users in their homes and sometimes taking screengrabs.
The hacker also made copies of private documents such as wills, medical reports, CVs, password lists and private photographs.
Anderson, will be sentenced on 22 November.


Read more: http://www.thirdage.com/news/computer-security-expert-busted-spreading-viruses_10-22-2010#ixzz13999MGtv

Tuesday, October 12, 2010

The government is preparing to issue the Information Security Guidelines to help control cyber crime that has been escalating in recent years.
Addressing a conference on cyber security, emerging cyber threats and challenges on Thursday, Rajan Raj Pant, controller of the Office of the Controller of Certification (OCC), said that the government was working to issue guidelines to help control the increasing trend of cyber crime such as e-mail threats, hacking, internet fraud and identity theft.
The guidelines are being planned by the government at a time when the use of the internet is increasing in sectors like banks and financial institutions (BFIs) and government offices that are sensitive in terms of data security.
“After the issuance of the guidelines, all the ISPs, BFIs and online operators have to abide by them,” said Pant.
“Government sites, sites belonging to banks and financial institutions and online operators must undergo a security audit by the government.” (Source:ekantipur)
source: ktm2day.com

Saturday, October 9, 2010

Cyber Crime On A Roll In India

cyber criminals are now targeting Enterprises and Consumers based in Tier III cities.
The ISTR (Internet Security Threat Report) by Symantec states after metro cities its now turn for the cities like Bhopal, Surat, Pune, Hyderabad and Noida which also features in top ten bot affected cities list. However it has not resulted to decline in metro cities. Cyber Criminals have now become more professional and commercial in developing, distributing and using the malicious codes, scripts and services.
The new technology and easy money stuff is responsible for the birth of new hackers and cyber criminals. The new hacking tools and viruses being exchanged among the hackers enable them to break into computer systems more easily than ever before. During the first six months, Symantec had observed an increase in multi-staged attacks. It is an initial attack that is not intended to perform malicious activities immediately but later on.
India is now taking steps to fight against the cyber crime, Indian Police are now being trained on how the Internet, e-mail, and other computer-based tools can be used by criminals to illegally obtain information stored in databases.
In the home to tech hot spots, Banglore, a lab is expected to come up very soon to train more than 1,000 police officers and other law enforcement personnel annually in cybercrime investigation techniques. It will be the third of its kind to provide such services by Indian government after Mumbai and Thane.
As cyber threats continue to grow in India with more than 30 million Internet users across the tier I and II cities, it has never been more important to remain vigilant and informed on the evolving threats,” says Vishal Dhupar, Managing Director, Symantec India.
Ankit Fadia, the 21-year-old computer whizkid and author of ‘The Unofficial Guide to Ethical Hacking’ said “I could hack a state-owned bank’s website or a government communications website which shows the vulnerability, thousands of Indian websites are being hacked each day”.
He also has announced his association with the Ghaziabad-based Institute of Management and Technology (IMT) for a one year diploma course in cyber security programme through distance learning. In near future such courses can help to take on cyber crimes.
source: www.watblog.com

Friday, October 1, 2010

Indian Police can now track your E-mails

RGXUECW54G5X
The police can now read your e-mails without prior permission from the home department.
The Parliament recently cleared an amendment to the Information Technology (IT) Act, allowing the police to intercept or decrypt online information without seeking the home department’s nod.
Rising instances of cyber crime have prompted the move aimed at cutting red tape.
The amendment empowers the inspector general of police to permit interception or decoding information in cyber space in an emergency.
This will help speedy detection of cyber crimes like phishing or sending offensive messages and in tracking terrorists who operate using the Internet.
Advocate I.P. Bagaria said the amendment was necessary.
“Every citizen has a right to privacy. However, this cannot be at the cost of the state or country,” he said.
The secretary in-charge of the state home department should be informed about the interception within three days of tracking.
The secretary the final sanctioning authority has to grant permission within seven days.
Once the sanction has been obtained, it has to be placed before the Review Committee within two months.
Senior advocate Amit Desai said this period should be reduced. “Otherwise there are chances of misuse of these powers.”
The police had to earlier take permission from the additional chief secretary, home or, in an emergency, the joint secretary.
“Liberalisation of interception is required when the world is dealing with terrorism,” said senior police officer-turned lawyer Y.P. Singh.
The amendment has increased the minimum punishment under the Act to three years and made the offense non-bailable.
Cyber expert Vijay Mukhi said there should be a mechanism to check misuse.
source:www.techchase.in

High-tech war on cybercrime

CYBER POLICE
Police from the cybercrime unit will be equipped with the latest high-tech gadgets to effectively combat online offences. Inspector-General of Police Tan Sri Ismail Omar said this was necessary, especially in the wake of recent postings on social networking sites such as Facebook and YouTube.

He said combating cybercrime would be a priority as police realised that the force had to adapt to an era where information travelled at rapid speed and was circulated locally as well as globally. “We will come up with a new mechanism and procedures to deal with cases involving the Internet, especially on Facebook,” he told reporters after his inaugural visit to the Johor police headquarters here yesterday.

“We are especially concerned with news or information on the Internet that can disrupt racial relations and the country’s harmony.”He was responding to a video on YouTube where a preacher in Kuching, Sarawak, allegedly insulted Islam.

Ismail said the police would cooperate with other agencies such as the MCMC to get to the bottom of the matter.

On Tuesday, pro tem president of the Muslim Bloggers Association Zainol Abideen drew attention to the video clip of a “priest” delivering a talk at a church in Kuching and allegedly insulting Islam and Prophet Muhammad.

“If there is an element where the police can act, then we will take action against the culprit,” Ismail said.

“The matter could be investigated under the Sedition Act.” Every­­­one needed to be mindful of the impact their statements could have, he added.

On another matter, Ismail said the police would act on unsolved cases if full cooperation was given by the complainant or victims of crimes. “We will act on old cases if new evidence or leads are discovered,” he said.

“We urge the public who want the police to act on old cases to come forward and give us their full cooperation.”

He also wanted people to go straight to the police if they had any grievances and not highlight the matter in the media.
Source: www.internetslife.com

Monday, September 27, 2010

Saudi Arabia's Commission for the Promotion of Virtue and Prevention of Vice, known as the Haia, is aiming to set up a unit to combat cyber crimes.

 By ITP.net Staff Writer
According to Arab News, the Haia will establish a cyber crime unit at its Riyadh headquarters, which will initially focus on the issue of women being blackmailed online.

Saudi has recently seen an increasing number of reports of men attempting to blackmail women by threatening to post their photographs online. Use of mobile phone cameras and MMS has increased the circulation of photographs of women's faces, which under the Kingdom's strict traditions and customs, should not be revealed to non-relatives.

The General Presidency of the Commission will set up a temporary office in Riyadh. The group will also monitor illicit websites in the Kingdom, and will co-operate with other authorities to close such sites, the report said.

Cyber crime lab goes online in Mass

As new technology changes the way we live, crime fighters are also taking steps to keep pace with the bad guys.

Today, Massachusetts is showing off a new lab. As NECN's Brad Puffer tells us, it's helping law enforcement follow high tech clues to solve crimes.

Dave Papargiris is head of the Cyber Crimes division at the Masschusett's Attorney General's office.

He's showing off a new lab designed to handle the increasing number of cases involving digital evidence.

“There's a lot of equipment for doing mobile phone, new phones are coming out monthly, we need to have enough tools to work with every phone that is coming out.” Papargiris says they work to assist District Attroney's across the state and offer free trainings to local police departments. All in an effort to respond more quickly.

“If we got a report of a missing child we could go right into that persons bedroom take their computer hard drive out start looking at who their were talking to who they were communicating with.” The Attorney General's office has gone from processing around 50 cases last year to more than 100 this year and they expect that number will only go up.

Martha Coakley: “Everything from cell phones to iPhones to Blackberry's to mobile computers and anything that stores information in a digital way.” Attorney General Martha Coakley says the new lab goes online Wednesday morning at a cost of almost 800-thousand dollars. Funding she says comes from grants, their own budget and the state.

“It's a major investment but in terms of what we need to do for solving crime and providing deterrence it is well worth it.” Investigators say they handle the evidence as carefully as DNA - checking evidence in and providing a static free environment to prevent any damaging shock The hope is to solve crimes faster but with strong evidence that will also convince a jury at trial.
this post is brought to you by: www.internetslife.com

Monday, December 14, 2009

Cyber Crime: A 24/7 Global Battle

VIRTUAL CRIMINOLOGY REPORT - CYBER CRIME: THE NEXT
WAVE         This is a post
from McAfee website :
Cyber crime is a grim reality that's growing
at an alarming rate, and no one is immune to the mounting threat. It is
costing consumers, businesses, and nations billions of dollars annually,
and there's no end in sight.

For an in-depth analysis of this global trend, read the annual McAfee
Virtual Criminology Report. We've consulted with more than a dozen
security experts at the world's premier institutions-NATO, the FBI, SOCA,
The London School of Economics, and the International Institute for
Counter-Terrorism-to get their insights on the complexities of the dark
side of the Internet.

  • The increasing cyber threat to national security

    An estimated 120 countries are leveraging the Internet for political,
    military, and economic espionage activities. Cyber crime has expanded
    from isolated attacks initiated by individuals or small rings to
    well-funded, well-organized operations using sophisticated technology
    and social engineering. Are we in the midst of a cyber cold war?
  • The increasing threat to individuals and industry

    As more of us rely on the web for shopping, banking, socializing, and
    carrying on everyday business activities, cyber criminals are
    capitalizing on every opportunity to commit fraud, identity theft, and
    extortion. Ingenious cyber criminals have evolved “super-strength”
    threats that are harder and harder to detect and can be modified on
    the fly. And, emerging technologies like voice over IP and smartphones
    are fostering new threats like "vishing” and “phreaking.”
    How will these developments affect consumer trust and purchasing
    behavior?
  • Hi-tech crime: a thriving economy

    Existing in parallel with legitimate ecommerce is a thriving
    underground black market economy run by cyber criminals. Greedy,
    malicious online fraudsters don't even need computer skills or a great
    deal of money to launch an attack. They can buy customized Trojans
    that steal credit card information, and botnets can be bought, sold,
    and leased. And the stolen data itself is bought and sold like any
    other commodity. But zero-day threats that exploit unpatched
    vulnerabilities are the biggest cause for concern of all. Should these
    activities eventually be legalized?

Get more details and answers by downloading your copy of the
McAfee Virtual Criminology Report today!

Wednesday, October 28, 2009

Email Fraud


Courtesy wikipedia
Fraud has existed perhaps as long or longer than money. Any new sociological change can engender new forms of fraud, or other crime. Almost as soon as e-mail became widely used, it began to be used to defraud people via e-mail fraud. E-mail fraud can take the form of a "con game" or scam. Confidence tricks tend to exploit the inherent greed and dishonesty of their victims: the prospect of a 'bargain' or 'something for nothing' can be very tempting. E-mail fraud, as with other 'bunco schemes' relies on naive individuals who put their confidence in get-rich-quick schemes such as 'too good to be true' investments or offers to sell popular items at 'impossibly low' prices. Many people have lost their life savings due to fraud.

Forms of e-mail fraud

Spoofing

E-mail sent from someone pretending to be someone else is known as spoofing. Spoofing may take place in a number of ways. Common to all of them is that the actual sender's name and the origin of the message are concealed or masked from the recipient. Many, if not most, instances of e-mail fraud use at least minimal spoofing, as most frauds are clearly criminal acts. Criminals typically try to avoid easy traceability.

Phishing for data

Some spoof messages purport to be from an existing company, perhaps one with which the intended victim already has a business relationship. The 'bait' in this instance may appear to be a message from 'the fraud department' of, for example, the victim's bank, which asks the customer to: "confirm their information"; "log in to their account"; "create a new password", or similar requests. If the 'fish' takes the 'bait', they are 'hooked' -- their account information is now in the hands of the con man, to do with as they wish. See Phishing.

Bogus offers

E-mail solicitations to purchase goods or services may be instances of attempted fraud. The fraudulent offer typically features a popular item or service, at a drastically reduced price.

Items may be offered in advance of their actual availability, for instance, the latest video game may be offered prior to its release, but at a similar price to a normal sale. In this case, the "greed factor" is the desire to get something that nobody else has, and before everyone else can get it, rather than a reduction in price. Of course, the item is never delivered, as it was not a legitimate offer in the first place.

Such an offer may even be no more than a phishing attempt to obtain the victim's credit card information, with the intent of using the information to fraudulently obtain goods or services, paid for by the hapless victim, who may not know they were scammed until their credit card has been "used up".

Requests for help

The "request for help" type of e-mail fraud takes this form. An e-mail is sent requesting help in some way, but including a reward for this help as a "hook," such as a large amount of money, a treasure, or some artifact of supposedly great value.

This type of scam has existed at least since the Renaissance, known as the "Spanish Prisoner" or "Turkish Prisoner" scam. In its original form, this scheme has the con man purport to be in correspondence with a wealthy person who has been imprisoned under a false identity, and is relying on the confidence artist to raise money to secure his release. The con man tells the "mark" (victim) that he is "allowed" to supply money, for which he should expect a generous reward when the prisoner returns. The confidence artist claims to have chosen the victim for their reputation for honesty.

Other form of fraudulent help requests is represented by romance scam. Under this, fraudsters (pretended males or females) build online relationships, and after some time, they ask for money from the victims, claiming the money is needed due to the fact they have lost their money (or their luggage was stolen), they have been beaten or otherwise harmed and they need to get out of the country to fly to the victim's country.

This confidence trick is similar to the face-to-face con, known as the "Stranger With a Kind Face," which is the likely origin of at least the title of the vaudevillian routine known by the same name, as "Niagara Falls," or as "Slowly I turned..."

The modern e-mail version of this scam, known variously as the "Nigerian scam", "Nigerian All-Stars," etc., because it is typically based in Nigeria, is an advance fee fraud. The lottery scam is a contemporary twist on this scam.

Avoiding e-mail fraud

Due to the widespread use of web bugs in email, simply opening an email can potentially alert the sender that the address to which the email is sent is a valid address. This can also happen when the mail is 'reported' as spam, in some cases: if the email is forwarded for inspection, and opened, the sender will be notified in the same way as if the addressee opened it.
E-mail fraud may be avoided by:

  • Keeping one's e-mail address as secret as possible.


  • Using a spam filter.


  • Ignoring unsolicited e-mails of all types, simply deleting them.


  • Not giving in to greed, since greed is often the element that allows one to be "hooked".

Many frauds go unreported to authorities, due to shame, guilty feelings or embarrassment.

above image is from techshout.com

Wednesday, September 30, 2009

Cyber Crime Investigations Targets Electronic Thieves





NEWPORT BEACH, Calif.--(BUSINESS WIRE)--Cyber Crime Investigations (CCI), the corporate theft analysis experts,
announced the launch of its electronic theft investigation services.
Established by industry veteran James Box, an ex-law enforcement
investigator, and Scott Sloan, an electronic forensics specialist, CCI
offers the ideal combination of skills, experience and expertise
required to effectively investigate and resolve electronic related
crimes.



“It is difficult to imagine in today’s world of high technology, mobile
communication, digital information and trend toward ‘paperless offices’
that a commercial and/or corporate theft can be committed without the
use of an electronic device,” stated James Box, private investigator.
“We live in an age where electronic computing and communication devices
have proliferated the work place. Add to the equation the internet and
the workplace has become vulnerable to a plethora of new types of
employee theft, corporate espionage and electronic crimes. We
established CCI to address the increasing rate of electronic thefts in
the workplace and to assist the unfortunate victims in quickly
establishing the theft and protect them against any further or future
loss.”



“For the past several years, Jim and I have worked together on civil and
criminal cases involving computer and electronic thefts and have enjoyed
an impressive track record of delivering successful conclusions for our
clients,” stated Scott Sloan, electronic forensics and network security
specialist. “Establishing CCI enabled us to continue to leverage our
complementary skills and experience and to provide a much needed
service. We are very experienced in collecting digital evidence and
preserving the data’s integrity for forensic investigation, and know how
best to protect metadata and maintain the data’s chain of custody. And
CCI is uniquely positioned to provide clients with a wealth of
experience and expertise in the appropriate collection and preparation
of evidence should the victim wish to pursue the matter in a civil
and/or criminal court action.”



CCI is an investigative firm specializing in electronic related thefts
through a combination of Electronic Forensic Investigation and
Traditional Criminal Investigation with a strong commitment to providing
clients with the highest level of professionalism and customer service.
CCI assists clients in discretely resolving the suspected electronic
theft, crime or intrusion in the most efficient and expeditious manner
with as little disruption and loss to the client as possible.



CCI focuses on Corporate Theft, Trade Secret Protection and Employment
Pre-Termination Investigations and offers a range of investigative
services to:




  • Establish the electronic theft or crime


  • Properly acquire, process, authenticate and secure evidence – ensuring
    proper chain of evidence


  • Identify and confirm the perpetrator through a combination of
    electronic forensic investigation and traditional investigative and
    interviewing techniques


  • Properly interview suspected employee and other employees to dispel
    any possible discrimination and avoid wrongful dismissal suits


  • Assist in the recovery of stolen assets where possible


  • Prepare the evidence and case to present to law enforcement and/or
    courts if the action is requested or required



In addition to these services, CCI provides a comprehensive range of
traditional and electronic investigative services as well as network
security services to large and small business, law firms, insurance
companies, government agencies and private citizens.



About CCI



Cyber Crime Investigations (CCI) is an investigative firm established by
James Box and Scott Sloan to assist individual and corporate clients in
the detection and analysis of electronic related intrusions, thefts and
crimes, and to protect them against further and/or future losses.



Mr Box is a well respected and established Private Investigator with
significant experience in the criminal justice system. Having spent 21
years in law enforcement, Mr Box left the Orange County District
Attorney’s office and established a very successful private
investigation business serving the greater Southern California area.



Mr. Sloan is an established IT Professional with over 20 years
experience in the Computer Sciences field. Mr Sloan currently works in
several areas of forensics and uses many different tools to obtain
critical key evidence for his clients.



With CCI you can be assured of expert handling of suspected perpetrators
and evidence in a professional and confidential manner. For more
information, visit www.cciforensics.com.



Saturday, September 26, 2009

Information on Cyber Crimes

Hacking in simple terms means an illegal intrusion into a computer system and/or network. There is an equivalent term to hacking i.e. cracking, but from Indian Laws perspective there is no difference between the term hacking and cracking. Every act committed towards breaking into a computer and/or network is hacking. Hackers write or use ready-made computer programs to attack the target computer. They possess the desire to destruct and they get the kick out of such destruction. Some hackers hack for personal monetary gains, such as to stealing the credit card information, transferring money from various bank accounts to their own account followed by withdrawal of money. They extort money from some corporate giant threatening him to publish the stolen information which is critical in nature.




Child Pornography

The Internet is being highly used by its abusers to reach and abuse children sexually, worldwide. The internet is very fast becoming a household commodity in India . It’s explosion has made the children a viable victim to the cyber crime. As more homes have access to internet, more children would be using the internet and more are the chances of falling victim to the aggression of pedophiles.


Cyber Stalking


Cyber Stalking can be defined as the repeated acts harassment or threatening behavior of the cyber criminal towards the victim by using internet services. Stalking in General terms can be referred to as the repeated acts of harassment targeting the victim such as following the victim, making harassing phone calls, killing the victims pet, vandalizing victims property, leaving written messages or objects. Stalking may be followed by serious violent acts such as physical harm to the victim and the same has to be treated and viewed seriously. It all depends on the course of conduct of the stalker.Read more...



Denial of service Attack

This is an act by the criminal, who floods the bandwidth of the victim’s network or fills his e-mail box with spam mail depriving him of the services he is entitled to access or provide



Virus Dissemination

Malicious software that attaches itself to other software. (virus, worms, Trojan Horse, Time bomb, Logic Bomb, Rabbit and Bacterium are the malicious



Software Piracy

Theft of software through the illegal copying of genuine programs or the counterfeiting and distribution of products intended to pass for the original.Read more...



IRC Crime

Internet Relay Chat (IRC) servers have chat rooms in which people from anywhere the world can come together and chat with each other.Read more...


Credit Card Fraud

The unauthorized and illegal use of a credit card to purchase property.



Net Extortion

Copying the company’s confidential data in order to extort said company for huge amount



Phishing

The act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has.


Computer Forensics In Criminal Defence

There is a lot of coverage within the media about how digital forensics have been used within a court case to prosecute. However, within the British judicial system, someone is innocent until proven otherwise.
With this in mind, there are many ways in which criminal defence law firms can use digital forensics to defending a client. Digital forensics covers the use of mobile phones, computers
and even satellite navigation units – in short, any digital device. . All of these can help the accused prove their innocence if looked in to correctly.
Computer forensics has helped many cases, primarily for prosecution, but it can be used to help people prove they have not committed the crime they have been accused of.
With the help of digital and computer forensics specialists, there are many ways a case can be helped if digital evidence has been presented against the accused. There are many strict rules and regulations that must be followed to extract evidence properly. If these rules have not been followed the evidence can be deemed invalid.
Any extracted evidence should have been done so by an approved analyst to be deemed an admissible source. If this is proven not to be the case, then the evidence is worthless and other sources will need to be found to support the case.
Alongside these points there are other factors that decide whether evidence extracted is usable. By choosing a reputable computer forensics company, they will be able to provide answers to such questions and know whether the evidence provided has been found legitimately or not.
The digital finger-prints we leave in today’s society means anything and everything can potentially be traced back. With this in mind it is important to remember that although we can extract data vital to proving conviction – or innocence, there are still procedures that need to be followed.
If the guidelines are not followed, extracted data is invalid, so ensure where any case is presented the facts are checked, and the only people to do this are the digital forensic professionals.
Written by Jenny Pilley

Cyber Crimes Center


The Cyber Crimes Center (C3) Child Exploitation Section (CES) investigates the trans-border dimension of large-scale producers and distributors of images of child abuse, as well as individuals who travel in foreign commerce for the purpose of engaging in sex with minors. The CES employs the latest technology to collect evidence and track the activities of individuals and organized groups who sexually exploit children through the use of websites, chat rooms, newsgroups, and peer-to-peer trading. These investigative activities are organized under Operation Predator, a program managed by the CES. The CES also conducts clandestine operations throughout the world to identify and apprehend violators. The CES assists the field offices and routinely coordinates major investigations. The CES works closely with law enforcement agencies from around the world because the exploitation of children is a matter of global importance.
C3 brings the full range of ICE computer and forensic assets together in a single location to combat such Internet-related crimes as:


  • Possession, manufacture and distribution of images of child abuse.

  • International money laundering and illegal cyber-banking.

  • Illegal arms trafficking and illegal export of strategic/controlled commodities.

  • Drug trafficking (including prohibited pharmaceuticals).

  • General Smuggling (including the trafficking in stolen art and antiquities; violations of the Endangered Species Act etc.)

  • Intellectual property rights violations (including music and software).

  • Immigration violations; identity and benefit fraud


C3 consists of four sections, three of which provide cyber technical and investigative services, the Cyber Crimes Section (CCS), the Child Exploitation Section (CES), and the Digital Forensic Section (DFS). The fourth section, the Information Technology and Administrative Section (ITAS), provides the technical and operational infrastructure services necessary to support the other three C3 sections. The center is a co-location of special agents, intelligence research specialists, administrative support, and contractors, all of which are instrumental in operational and technical continuity. Within each section, there are various program managers assigned to certain programmatic areas. These program managers are responsible for supporting ICE Internet investigations through the generation and the dissemination of viable leads. Program managers are available to provide guidance and training to field agents as well as to other law enforcement (foreign and domestic) upon request.



Child Exploitation


The C3 CES investigates large-scale producers and distributors of images of child abuse as well as individuals who travel in foreign commerce for the purpose of engaging in sex with minors. The CES employs the latest technology to collect evidence and track the activities of individuals and organized groups who sexually exploit children through the use of websites, chat rooms, newsgroups and peer-to-peer trading. The CES also conducts clandestine operations throughout the world to identify and apprehend violators. The CES assists the field offices and routinely coordinates major investigations. The CES works closely with law enforcement agencies from around the world because the exploitation of children is a matter of global importance.




  • Operation Falcon — A joint international images of child abuse investigation initiated by ICE that identified 39 websites distributing child pornography. Further investigation led to the arrest of 1,200 international downloader’s and more than 300 U.S. customers. Nine individuals from the United States and Belarus were identified and charged as the principals in this investigation. All principals were convicted on various charges related to money laundering, structuring and the production and distribution of images of child abuse.


  • Operation Mango — An extensive investigation that closed down an American-owned beachside resort in Acapulco, Mexico, which offered children to sexual predators. The resort was a haven for pedophiles that traveled to the facility for the sole purpose of engaging in sex with minors. The proprietor of the business was convicted. As a result of this investigation and others, the government of Mexico recently created a Federal task force to address crimes against children in its country.


  • Internet Crimes Against Children (ICAC) Task Force — The Department of Justice (DOJ) Office of Juvenile Justice Programs, ICAC Task Force comprises 45 task forces. The task forces were created in cooperation with the DOJ ICAC to provide reporting, a means to provide a virtual pointer system for Child Exploitation and images of child abuse cases and secure collaboration for various Federal, State, and Local law enforcement organizations, task forces, and affiliated groups around the world. DHS/ICE strongly supports the efforts of the ICAC task forces as demonstrated by ICE special agents being active members of the ICACs throughout the United States. The Northern Virginia/Metro DC ICAC is housed at the DHS/ICE C3.



Cyber Crimes Section



The Cyber Crimes Section (CCS) is responsible for developing and coordinating investigations of Immigration and Customs violations where the Internet is used to facilitate the criminal act. The CCS investigative responsibilities include fraud, theft of intellectual property rights, money laundering, identity and benefit fraud, the sale and distribution of narcotics and other controlled substances, illegal arms trafficking and the illegal export of strategic/controlled commodities and the smuggling and sale of other prohibited items such as art and cultural property.



The CCS is involved in the development of Internet undercover law enforcement investigative methodology, and new laws and regulations to strengthen U.S. Cyber-Border Security. C3 supports the ICE Office of Investigation’s (OI) domestic field offices, along with ICE foreign attachés offices with cyber technical, and covert online investigative support.




  • Operations Apothecary – The CCS, the ICE Commercial Fraud Office and the National Intellectual Property Rights (IPR) Coordination Center have partnered together and launched a comprehensive Internet pharmaceutical initiative designed to target, arrest and prosecute individuals and organizations that are involved in the smuggling of counterfeit pharmaceuticals of a controlled and non-controlled nature as well as scheduled narcotics via the Internet. The focus is also on the affiliates of the rogue pharmacies that are typically operated by criminal enterprises whose sole purpose is to generate large sums of money, with no regard to the health and welfare of the public.


  • Intellectual Property Rights - The CCS has encountered thousands of web sites based in the United States, as well as foreign that are engaged in the sale of counterfeit merchandise (including music and software) via the Internet. The CCS continues to work closely with the National IPR Coordination Center, the Computer Crimes and Intellectual Property Section (CCIPS) at the DOJ, and industry representatives to identify web sites responsible for the sale of the counterfeit items.


  • Arms and Strategic Technology - The CCS supports ICE’s mission to prevent proliferate countries, terrorists, trans-national criminals from obtaining strategic materials, funds and support and to protect the American public from the introduction weapons of mass destruction and other instruments of terror from entering the United States.


  • Identify Fraud Initiative - The availability and use of fraudulent identification documents has always been a concern to the law enforcement community. While traditionally available from street sources, fraudulent identification and travel documents, of all types, are also readily available for sale via the Internet. In the post 9-11 world, fraudulent identity and travel documents are of an even greater concern to ICE because of the alarming threat they pose to ICE's primary mission of protecting the United States, and its citizens, from threats arising from the movement of people and goods into and out of the country. With addressing these documents and their threat in mind, the CCS has sought to identify sources for fraudulent identity and immigration documents on the Internet. Those sources identified are pursued for criminal violations either locally or referred to other ICE field offices."




Digital Forensics Section


Digital evidence has become prevalent in every ICE investigative case category. Digital evidence is quickly replacing documentary evidence as the “smoking gun” in investigations. As a result, ICE investigations increasing demand that vital evidence be identified, seized, and recovered from a variety of electronic devices. ICE special agents need access to information stored on personal computers, complex business networks, personal digital assistants (PDA), cellular telephones, and multifunction communications devices.



Under legacy US Customs and US Immigration, ICE began training special agents to address this problem. The merger of the two agencies’ legacy computer forensic programs now provides ICE with more than one hundred and twenty-five special agents trained to process digital evidence.



The C3, Digital Forensic Section (DFS) provides programmatic oversight to the ICE Digital Forensics Program, operates the ICE National Digital Forensics Lab, and participates jointly with the US Secret Service and the Internal Revenue Service in the legacy Treasury Computer Investigative Specialist Training Program.



DFS Digital Forensic Agents (DFA) serve as the primary source for ICE field DFAs for technical forensic support issues, conduct research and development on new and emerging technologies, and develop and deliver training to field DFAs.



The DFS operates a state of the art Digital Forensics Lab that processes “strange and large” digital evidence seized by ICE field offices. Digital evidence resident on “non-standard” hardware or too voluminous for field office to process may be forwarded to the DFS for examination.



The DFS also provides ICE with advanced data exploitation capabilities. Digital evidence submitted by ICE field offices can be imported onto the DFS Lab network, indexed, and searched using advanced data exploitation tools. Large volumes of unrelated data can quickly and efficiently be mined for evidence of criminal activity.

Monday, September 21, 2009

Cyber Security

Security whether it is physical or virtual , is the primary concern of any organization. The proliferation of computer systems and network has created new situation where organizations, be it government or private, are becoming more and more relying on computers and network for day to day operations. This has resulted in a deep concern regarding the safety of information and infrastructure. Critical Infrastructure such as electricity, water supply , nuclear plants, financial institutions , etc. play an important role in economy and safety of the country. Any type of intrusions into such systems can jeopardize the safety of the country.
The wide spread use of computers and internet provides intruders an opportunity to sneak in and create havoc. There is a strong need to provide sufficient security to all computer systems and information residing in it.
Computer Security Institute (CSI) most of the computer security breaches are not reported. People keep quiet not to expose the vulnerability further. The CSI/FBI report Computer Crime and Security Survey 2006 shows alarming increase in cyber crimes. The key finding of the survey is
* Virus attacks are the major threat causing financial loss ( 74%)
* Percentage of organizations reporting intrusions have increased from 20 to 25 %
* Over 80% organizations conduct security audit.
It is a fact that most of the organizations don’t report the intrusions to avoid negative publicity it gets. One of the objective of this programme is to provide information and guidelines to protect computer systems against intrusions, data theft, etc. www.cyberkeralam.in

True Confession of Hackers





Watch the Hackers confession.!!
Do you think hackers are criminals of cyber world or those good people who help poor and dummy people at the cyber world by providing cracks to the internet world?