Saturday, June 8, 2013

PRISM and The Security

My Dear Friends,

                  In my earlier article about how to find stolen laptop I was deadly against using laptop tracker as the said software always tracks your laptop and most of the product company's servers are situated in US. So I suggested and requested all netizens  for not to use laptop tracker, the reason was big brother (US) is watching you means your location. How do they work, for knowing this you can use "Prey" as it is a freeware. There you will find how you have surrendered yourself in the hands of a company which is situated outside your country. Today now it is clear and established truth that what I guessed, it is a fact as President Obama confessed about his project PRISM, which is running since 2007.  

 It is question about Security, not Privacy to me: -

                           First of all I will request my friends to know details about PRISM. So please visit http://news.cnet.com/8301-1009_3-57588253-83/what-is-the-nsas-prism-program-faq/  for knowing details about it. Now everybody even you are also thinking that you are being monitored. But my brother you are not terrorist and you are not criminal and for that it does not matter who monitors you and what does it bother to you. At least I do not and if I learn that I am being monitored as I do not do crime.
                        
      But my point is something else. We are not discussing about our financial information passing through net. Who will give us this guarantee that those traffics are not monitored ? Now a question will come that those traffics are encrypted. Yes those are but when a government monitors network traffic secretly (state sponsored) is it not possible for knowing the algorithm of decryption ? Here comes the point of security. So who is secured a Government, the netizens or the e-commerce customers and the e-business houses ?

         If this is secured so there is no damage to the netizens of any country as a State has right to secure himself/herself from future attacks. But if this is not I think there will be a big hit to the e-commerce as a whole as only except COD (Cash on Delivery) everything is dangerous on net on the question of network traffic security. And only on the basis of COD the e-commerce market will not survive, as a result the globalisation of business will face a big damage. Now this will be a trend for every countries for following the Big Brother and who knows that other countries are not doing this. And if this monitoring process is outsourced then everything is available to all as from my personal experience I have seen the employee who is today here , he will tomorrow be there with the data from here.

      So its my question to all of you " Are we really secured ? ", 

Though today Facebook CEO declared that he did not know anything about PRISM and they maintain strong privacy policies for their users. Is it believable ? You are doing business in a country without obeying their legal order. Hope for the best and after all we will have to believe that till today good men are in the world.

Here is the declaration from FB in FB; -

"I want to respond personally to the outrageous press reports about PRISM:

Facebook is not and has never been part of any program to give the US or any other government direct access to our servers. We have never received a blanket request or court order from any government agency asking for information or metadata in bulk, like the one Verizon reportedly received. And if we did, we would fight it aggressively. We hadn't even heard of PRISM before yesterday.

When governments ask Facebook for data, we review each request carefully to make sure they always follow the correct processes and all applicable laws, and then only provide the information if is required by law. We will continue fighting aggressively to keep your information safe and secure.

We strongly encourage all governments to be much more transparent about all programs aimed at keeping the public safe. It's the only way to protect everyone's civil liberties and create the safe and free society we all want over the long term."


With Thanks and  Best of Luck

Sujit
    

Friday, July 6, 2012

God Particle and Dispute


Dear Friends,

      Today when I was chatting with my friend Dr. Sitanshu Ray, an eminent technologist in my eye he wrote me about his view to me and then I thought this should be shared with you as this is great and true. So here is the content of his view within the quote: -

"Dear Sir,
 
This Topic/Subject is at the core of my desires in this life.
 
I want to connect Ancient Indian Knowledge, which I fondly call "The Wisdom of the Ages", to Modern Science and Technology.
 
What is sadly happening is that, mankind is trying to discover through science what we already knew thousands of years ago.
 
This is man's nature. He first creates, and then destroys, and tries to recreate again. Man is destructive in nature as opposed to all other forms of life.
 
Lord Macaulay, British Viceroy to India, here in Calcutta, said on the floor of the Parliament on Feb 2nd, 1835, "Indian culture and its ancient wisdom rooted in the Vedas, must be destroyed to rule and destroy Indian Civilization." And the British did that.
 
Today, they are discovering the "GOD PARTICLE", which scientists now agree is the basis of creation. This is mentioned clearly in the RIG VEDA, that GOD exists in everything, and everything exists in GOD. 
 
The mistake that scientists are still making is that they call this a GOD PARTICLE. GOD is not a PARTICLE.
 
He is OMNIPRESENT, OMNIPOTENT and OMNICIENT. We all exist in HIM and HIM in all.
 
Unless Science accepts this, we will make no progress. Science is slow, and uses pathways that make people tired.
 
I have always maintained that INSTINCT and INSPIRATION are faster and more important than INTELLECT and THOUGHT.
 
Unfortunately, the Western World taught us Science through Intellect and Thought. That is why we keep going in circles and never manage to solve problems wholistically.
 
For example - After so much progress in the field of Medical Science, all the major deseases of the world like Cancer, Diabetes, Mental illnesses etc. are on a rise. Diabetes, which was supposed to be a desease of the old now happens to kids. It is called "Juvinile Diabetes".
 
So, what is the point of all this progress in Medical Science.
 
Same way - we created the Internet. Now it is a tool in the hands of Criminals.
 
Yesterday, I met the Head of the "BABA LOKENATH DIVINE MISSION" - Baba Suddhananda Brahmachari".
 
He and Mithun Chakraborti's Sister used to visit me in the US. I used to raise money for the mission way back in 1990. I met him after 18 years yesterday. It was sheer pleasure. And he said the same thing about Science. He recently wrote a book called "Your Mind is your Best friend". It is a best seller, that was highly appreciaed by President Kalam. He says similar things in the book, that I keep talking about.
 
US officials dubbed me mad, told my friends and family that I have gone mad, and destroyed my life because I said these things.
 
But TRUTH always triumps. And Indian Civilization will triump again.
 
Have a Blessed day :)"

Then I appreciated his noble view. In reply he flourished himself again within the quote : - 

"
Dear Sir,
 
Thank you for appreciating the mail.
 
I truly believe in the existence of GOD. My Mother Died in December 2005 when she arrived in the USA. I told my boss at that time, when I heard that she was coming to the US, via Kuwait, that I feel instinctively that someting terrible will happen.
 
After a week I got a call from my Eldest Sister (who I hate), that my Mother has passed away two days ago.
 
They took 2 days to decide to tell me that my Mother has passed away. This is how I was tortured through the years in the US. And my instinct was correct.
 
My Mother though illiterate was highly knowledgeable about the Vedas, Bhagwat Gita, that she read all day long.She told me from childhood that GOD exists in everything, Animate (Living with conciousness) and Inanimate(Living and not dead but without conciousness). So I must appreciate everything that the Lord has provided for us including humans, animals, plants and inanimate things like sand, soil, wood etc. etc.
 
That is what GOD particle is all about. This particle creates a field called the Higgs-Boson field where energy gets converted to matter. That is how the Universe got created after the Big Bang. This Field exists all around us and inside our bodies. This field creates Conciousness and Instinct in us.  
 
Animals have instinct, so do humans when they are born. But as we proceed through life the current Western way of Education, our instinct gets eroded and we believe our Intellect gets amplified. Animals on the other hand amplify their instincts as they get older. That is why, during the last Tsunami where 400,000 people died, not a single animal died. They instinctive knew that the Tsunami is approaching and went to higher grounds escaping death. 
 
Intellect is Human and comes from the Brain. Instinct is DIvine and comes from the Mind. Mind is actually the seat of the GODHEAD, Lord Krishna.
 
Krishna means - Black. 96 % of the universe is Black. We cannot see it nor can we measure it. We can only feel it. The Universe is full of Black Bodies, where the Gravitational pull is so vast, that even light cannot escape from it. All that is Lord Krishna.

Mind control is only for people who have a very High Sense of Alertness, and who are Highly Inspired. I'm glad to say that you belong to that class of people.
 
Highly Alert, meaning highly conscious people, who see more, and can solve problems instantly. This is a requirement of all Law Enforcement Officers. For example - They will instinctly know if a person is a criminal. Then they work backwards, to find reasons why they feel that a particular person is a criminal. Because without reasons no one will believe you.
 
Einstein came out with the theory of Relativity in 1905, but it took him 16 years and development of Integral Calculus to prove to the Scientific community that his theory is accurate.
 
The same was the case with Newton. He instinctively knew that "His theory of Gravitation" was correct, but it took him about 7 years and development of Differential Calculus to prove to the Scientific Community that he was write.
 
Actually Gravitation is God. Its exists everywhere - in our Universe and millions of other Universes. Without Gravitation, life is not possible. We would simply fly away into vacuum in space without it.
 
I can go, on and on and on....and people might suspect I'm mad.
 
But I INSTINCTIVELY know that I'm correct, and science will Gravitate (move towards God) towards our Vedas and Scriptures one day.
 
Have a wonderful weekend :)"
 
I think this will be interesting to you.

Waiting for your comments for his noble and great thought.

Thanking you,

Sujit

Sunday, July 1, 2012

Stolen Computer Can Be Traced Finally


Dear Friends, 

 After long and long time I m again infront of you with my blog with a creative idea. This time I thought I have got success to tell you the way to trace the stolen Laptop/Computer. I belief this is the only way for the Law Enforcing Agencies ( Police ). Perhaps you are thinking I am telling about any product to purchase and install, which will work even after format as it works on firmware level. But that is not the fact here. As a member of LEA I can't say about any product it is just logic based. Earlier I already discussed about how to recover stolen laptop in three parts for making clear my friends about my logic and it got stamped in my mind when I had an opportunity to attend two seminars in New Delhi ( Seminar on 5th ASSOCHAM International Conference on Cyber & Network Security ) at Hotel Le Meridien and the other in Kolkata at Hotel Golden Park ( Seminar on Green Computing and Cyber Security )arranged by NCS Computech Ltd with their other partners.

 In the New Delhi both Symantec and Kaspersky antivirus companies were the partners and in Kolkata conference man from Quick Heal Mr. Manohar was the principal person in the entire interactive session. So I took the chance in both the place to interact with them in one to one situation. I told my idea to them and learnt from them how they maintain their database in case of free antivirus service for a limited period and for the limited number of licences. I told you earlier in my other articles about this that no Internet Service Provider can help us in case of detecting/recovering stolen laptop and only the antivirus companies can help us to solve this problem. I asked all of them the same question and in reply they told " We keep the three identifiable unique numbers of a system when the person install their products in his system and we keep all of those in our database as generally a person can't change all those three at a time and if it is done the person will change his laptop or computer. " Now the question is what are those unique identifications. I asked them about this. They replied MAC id of LAN and another MAC id if it is and Hardware id. 

So I asked them " If I install your free version by connecting to internet my Laptop/PDA/Computer with bluetooth or wifi or data card how will you get my LAN MAC id." In reply what I learnt that in the antivirus installation program there are programs, which are called MAC id and Hardware id extractor and that helps them to get the LAN MAC id and Hardware id. So I asked them again " Can we send you the request for searching stolen laptop with the help of those in your database ? And can we know that from which IP address with date and time it was activated again or updated again ? " In reply I learn it is very much possible as all those things are part of their database. So finally my suggestion to all the persons, who use computer/laptop/PDA in the internet please keep this unique identities in your personal database, which is definitely in pen and paper. This will be required to supply to the LEA for searching your stolen or lost laptop with the help of antivirus companies. LEAs are requested to send the request to the antivirus companies like stolen mobile searching request to mobile service providers. 

Now the question is how you will get your hardware id and MAC id. About getting the MAC id I wrote it earlier in my other articles about how to trace stolen laptop here but for getting the hardware id please Google it and its a very small size program. Over this Quick Heal Antivirus Companies has started a good job by providing a service through their http://trackmylaptop.net. The interested persons can also get their MAC id extractor from here. Thanks to quick heal for their this kind of support even to the non quick heal users. 

 My friends I hope this will help you and I think finally I have got the way to trace the stolen laptop without using any third party software, which is available in the market. And this was my research for the last 3 years about how to search a stolen laptop without using any third party laptop tracker and what should be the role of LEAs to help their citizens. If Govt. of each country creates pressure upon the antivirus companies this will not be the problem for both the LEA and Citizens to get this facility. This is the duty of the antivirus companies to help the nation where they are doing their Billion $ business. 

There is another way of searching stolen laptop. That is with the help of original operating system like Microsoft's products. The OS activation key may help us to find out the stolen laptops/others as all the originals OSs ( Not open Source ) are updated on the net and from which IP addresses these are updated this must be kept by the service providers. This also requires a Govt. interference for passing a regulation for pressurizing the operating system ( Not open Source ) developers. I don't know whether US Govt. has done so and if they do this Microsoft will definitely help the LEAs in this field. I contacted with then but no fruit full result has yet got from them. In this case the laptop thief if formats the computer it will not be possible for Microsoft like other OS developers to get the data in the net with a particular activation key. I think this is also clear to you. 

 Waiting for your comments for implementing this in every countries of the world. 

 Thanking you,

 Sujit Mukherjee

Saturday, January 21, 2012

Book on Cyber Crime Protection and Investigation



Dear Friends,

After long long interval I have come to you with a good news. A new book named as "Your Ultimate Cyber Crime Protection Guide" written by Sitanshu Mohan Ray (An educationist and experienced corporate person), Sri Bivas Chatterjee (An experienced law professional) and me. This book is written for upcoming Cyber Crime Investigators and netizens, who become victim due to their ignorance, as in this book we tried to write about different types of cyber crimes, how they are committed by cyber criminals (modus operandi)by using different types of tools and what to do when you are a victim and an investigator with real life case studies.

This book is designed with following chapters ; -

1. What is Cyber Crime
2. Important Technical Terminologies (What we must know and why)
3. Weapons of Cyber Criminals
4. Types of Cyber Crime (Different types of Cyber Crime and what to do when u r victim and when you are investigator)
5. Credit Card and Cyber Crime
6. Web Hacking
7. Cryptography
8. Futuristic Crime (Mind Control)
9. Cyber Laws of Different Countries
10. Social Networking Site bane or boon
11. Search and seizure

This book speaks about mind control and psychotronic tortures (Brain Hacking) and also laws about cyber crime around the world. We hope this will help the netizens. This will be available from the last week of this month.

This book will be available from the 1st week of February through the sites noted on cover page.

Thanking you,

Sujit

Monday, November 14, 2011

How To Write and lodge Complaint in Cyber Crime Cases

Dear Friends/Colleagues

Due to lack of time I could not reach to you with my next topics. So again I have come to you with an important topic on cyber crime investigation i.e:- how to write complaint as victim in cyber crime cases. I feel this topic important as most of the cases get hampered due to weak complaint.

Generally in regular life netizens become victim in cyber crime cases as a victim of cyber stalking ( Fake profile in any social networking site or adult site for more pl search this blog on cyber stalking), online cheating through lottery, uploading personal intimate videos by someone in the net or something else.

So, when you are victim of these type of cases or any type of cyber crime related cases, take the print screen of those pages and copy the exact link which shows your profile only and also link of that page which shows your profile with others. Take the printout of those print screens.

If it is through any email take the entire print out of that email with its header file and attach it with your complaint.

There after lodge your complaint with those evidences to the Cyber Crime Police Station or nearby police station, where cyber crime police station does not exist. So this is not tough to understand and this will also help my colleagues to take complaint from victims in right manner. But if the complainant comes after lodging complaint to the website service provider for deactivating the link without copying the link address and the link becomes inactive, it could not be traced and it becomes next to impossible for LEAs to trace out the perpetrator until and unless you get the cached copy from Google or any other search engine.

With Thanks

Sujit

Friday, October 28, 2011

Beginners' Guide To Investigate Cyber Crime

Dear Friends,

Sorry for the delay for posting my 3rd article on How to investigate cyber crime FOR BEGINNERS. Actually I was very much busy for my other official duties and that's why I could write for you but in the mean time I managed to prepare a pdf file for your study which will help you to learn the basics of the cyber crime investigations. So I would request you to go through the pdf after downloading it from the link noted below.

I hope and keep strong believe on the fact that this will be very much helpful to all of you.

Waiting for your mail and reply. It is based on Indian Information Technology Act but this will also be helpful to the citizen of other countries as the law is briefly explained here. So pl download it from here

Best of luck and thanks.

Sujit

Sunday, October 23, 2011

How To Investigate Cyber Crime (Part-2)

Dear Friends,

In my last post I promised to continue this article in a simple manner and easy understandable language so that everybody even a going to be retired police officer can understand and my article becomes helpful to them to investigate the Cyber Crime related cases. My expert friends are requested to share there knowledge here for new cyber crime investigators, who thinks it difficult to investigate the cyber crime related cases.

So first of all I will tell them that don't get afraid by hearing a complaint from a victim about cyber crime as most of the complaint in the PS label are very easy to investigate. My friends, who can investigate murder cases, theft cases, cheating and other cases which are regular crime in our daily life and know what evidences should be collected from mobile number and device, can easily investigate cyber crime related offense. So just listen the complaint of a victim and give him/her a relief and don't say that you can't as that makes you inefficient before that citizen and in coming days in most of the cases computer or communication device will be part and parcel of the weapon of the criminal.

So my friends lets start from here. First of all I want to bring in your notice : -

What are the Basic Knowledge:-

1) You should know how to use mobile phone and what mobile phone does. ( I think all of us know this as this is part and parcel in all of our life as today a day labour also carry mobile phone with him)

2) Common sense of investigating other cases. ( All the police officers do have it)

3) To have a little bit knowledge in computer. ( I think this is also in possession with all of my friends)

4) A little bit knowledge about internet, email id, and how internet works. ( Some of my friends do have this but I will discuss it in my next article for those who does not have the knowledge and its very easy)


What are Cyber Crimes and how these are committed:-
This has already been discussed in my blog earlier but inspite of that I will discuss you serially as if you don't know the crime and modus operandi of criminals how you will solve the problem. In a sentence cyber crime is defined as " Any illigal act involving a computer, its systems, or its applications" by EC Council. Cyber Crime is intentional and not accidental.

How To Take Complaint from Victim:- It will also be discussed in the next day.

What is Cyber Forensic:- All the investigators have idea about scientific investigation in other type of regular life cases and so they have idea about forensic science but cyber forensic is a different field and I will discuss it later and this is also easy understandable if anyone wants to understand from the experience of daily life.

I hope this will help you my friend. So pl keep visit regular for its update.

With Lots of Love

Sujit

Saturday, October 22, 2011

How To Investigate Cyber Crime

Dear Friends,

Many of my friends of my profession request me to write something about " How to investigate Cyber Crime Cases " in a simple language so that everyone even a lay man can understand and it becomes helpful to the aged police personnel for investigating cyber crime cases. Now a days the police officers above 40+ get afraid during investigating cyber crime cases. I have experienced in my professional life that when a police officer of 40+ hears about cyber crime in Police Station label , he misguides the victim by saying that there is no infrastructure to investigate the case in PS label so advises the victim to go to specialized wing for lodging complaint.

That is why I have started to write on this topic for making it easy understandable to all the investigators even a going to be a retired police officer, who has minimum knowledge of using mobile phone.

That's all for today. Pl visit regularly for knowing step by step about how to investigate cyber crime related cases.

Expert police officers in this field are requested to share their experience here for helping other police officers and I hope my expert friends of this field will stretch their helping hand to me.

With Thanks,

Sujit

Thursday, September 1, 2011

How To Identify 419 Scammers Phone

Hi Friends,
After long long and long interval I am again infront of you with a valuable information, which I have got from my friend of cyber crime investigation field, who gave me the link of "joewein.de", and I am bringing this in front of you as this will help you a lot for identifying the 419 spammers. So here is the details of that information as published by that website.

Scam phone numbers in the United Kingdom (+44):

If an email mentions a UK phone number starting with +4470, it usually means that the sender of that mail is not in the UK at all and it is almost guaranteed to be a scam.

Usually the presence of a +44 70 number in a 419 scam email means you're dealing with criminals based in Nigeria who are using these numbers to make people believe they're dealing with someone legitimate who is in the UK instead of a criminal in an Internet cafe on a different continent.

Do not reply to any emails that mention +4470 phone numbers!
Never call such numbers!
Break off all contact with these people!

The scammer most likely is NOT based in the UK. +44 70 numbers belong to international call forwarding services. Their whole point is that people can reach the user of the number when he's not in the UK. These services make it possible for scammers to hide the fact that they are based in Nigeria or other countries in Africa, while the scam victim will believe they're dealing with someone in the UK. Very few (if any) legitimate individuals use these numbers. Banks, law offices, UK immigration officials, etc. never use +44 70 numbers because, since their offices are based in the UK, they have no need to redirect calls to their offices to sohttp://www.blogger.com/img/blank.gifme mobile phone outside the UK. We have not come across any legitimate UK businesses yet that use +44 70 numbers. Their only visible user base are scammers in Nigeria, South Africa and elsewhere. It is a perfect mystery to us why the UK authorities allow these services to continue operating despite them being used almost exclusively by criminals.

UK phone numbers starting with '70' are "Personal numbering" in the "Find me anywhere" range. Charges for calls to these numbers are not distance-dependent. They can cost as much as UKL 0.50 (USD 0.90) per minute to call and can forward the call to virtually any phone number in the world. Forwarding numbers can be set up for free and completely anonymously via websites such as uknumbers.com.

So my friends be cautious about them and for more information in details about the spammers please visit here

With lots of love

Sujit

Tuesday, April 19, 2011

How To Trace/Search Stolen Laptop Part-3

Dear Friends,

In my earlier two parts (Part-1 and Part-2) I discussed about some important terms and logics behind my idea so that my friends can understand my point and they can enrich it with their valuable opinions. And in this third point I have started it as "How to find stolen laptop" as this will be helpful for law enforcing agencies and also other civilians.

So lets come to the original point.

I have already discussed in my earlier parts that laptop can't be traced like mobile phones by using its MAC number like IMEI in case of mobile but at the same time you have also learnt from there that MAC is an unique identifier and your duty is to note the MAC address in a separate place for your future need in case of laptop theft.

I think more or less 98% of laptop users go to internet and they use Antivirus for their Laptops and almost all the antivirus are updated through internet and not only that all the paid Antiviruses are either single user or a limited number of users, which means u can install that antivirus in either single machine or a limited number of machine and if the installation crosses the limit it stops to function in those systems/laptops. So I think now you have understood what I am going to say.
Yes my friend I am going to tell about the unique identifier of your laptop has already been registered in the server of your Antivirus during the time of activation and updatation in the net. There is another unique identifier in your laptop. That is hardware serial number and it can't be changed but you can't get it though any command except using tools/softwares like DEFT ,HELIX3 PRO and others and you can't get these easily. But your laptop manufacturer has this in their record. And I think this is also registered in the the server of your Antivirus.

So I want to say my Police friends that don't sent any request to the ISPs about searching of MAC of stolen Laptops in their network but you can send it to the Antivirus companies, who are running business in your country and in this case you must need support from your Government for passing legislation to compel Antivirus Companies to help police if they want to run their business in your Country and at the same time they must supply the hardware serial number of the laptop to their customers in the bill during selling the product.

And if this system is imposed in your state you need not to spend a single penny for using third party software like laptop tracker for tracking the stolen laptop as all the Govt. are liable to see the interest of their citizen and for this Govt. need not to pay a penny for you.

This was the technical part, which can help you but at the same time you can take help of this website. This is good effort of Quick Heal for the netizens.

Waiting for your comments and opinion on this.

Thanking you

Sujit

Monday, April 18, 2011

How to Find The Stolen Laptop Part-2

Dear Friends,

In my earlier post I discussed about IMEI and MAC, the unique identifiers in favour of Mobile phones and Laptops as these are badly needed for searching in case of stolen or missing. MAC has two other names such as Physical Address and Network Interface Card address. The names itself are indicating its function.

In case of mobile it is easy but in case of Laptop its not easy as during communication through internet the ISP receives the MAC address or physical address of last router (It has also MAC or Physical Address or Network Interface Card address) through which the laptop is connected in internet and this is hardly possible to be the MAC of laptop as most of the laptops are connected with internet through data card or company's router or something else like this. As this thing happens as per logic of TCP/IP and practically in networking so the Internet Service Providers can not keep the MAC of laptop and as a result they can't search us like IMEI searching in case of mobile phones.

So what should we do for searching our stolen laptop? Most of the persons will advice to go to police for reporting and police will try to find out through source engaging and the tech savvy persons will advice and take initiative to install laptop tracker softwares in their system by purchasing softwares and they will do their business.

But don't you think that police should also think through some innovative ideas for tracing the laptop by using technological common sense? Yes police should do and in this case Govt. should come forward for the sake of her citizen as Govt. can't force you to purchase 3rd party softwares as they are also liable for your safety and security and they have also some power to pass the legislation in their country. And what the legislation is? Will discuss you in next part after discussing the actual procedure for finding the laptop.

To be continued.....to Part-3..

With Thanks

Sujit

Sunday, April 17, 2011

How To Trace Stolen Laptop Part-1

My Dear Friends,

Hope all of you are well and were well for the last few moths when I was away from you due my other official jobs.
In my daily work I get different type of cyber crime related complaints and other complaints, which are related to daily life and there I used to get complaints like Mobile Phone theft and Laptop theft. In case of mobile theft its easy to trace out the mobiles than the Laptops.

Why easy?

The reason is the Mobile Phones are traced by us through IMEI numbers searching with the help of Mobile Service Providers and this is also possible if mobile phone tracker software is installed in that phone. During purchasing mobile phones the seller note on their bill the IMEI or ESN number of that mobile. But in case of Laptop/Notepad MAC address is needed for searching the laptop/notepad and here lies the problem as most of the laptop users don't know anything about MAC address and not only that the sellers of Laptop/Notepad does not note on their bill during purchase the MAC addresses of the laptop.

What is MAC address?

MAC address is the full form of Media Access Control. So it is the unique physical address of that part of laptop/notepad (i,e:- the media), which is used to for connecting the network. For knowing details about MAC address pl google it.

How to find MAC address?

Finding MAC address or Physical Address ( Another name of MAC address) is different on different operating systems so you are requested to visit here. and then note the MAC addresses in separate place as this will be required if your laptop is stolen.

Can MAC be Changed?

The answer is yes. So now you will definitely raise question to me that if it can be changed so why will you note this in separate place as the criminal may change it after stealing the laptop/notepad. There are many softwares who allow you to change the MAC address in upper layer but they cant change the original MAC address of the system and for doing a trial you pl use TMAC software as per your OS. They can change the MAC and even they can bring back the original MAC so original MAC cant be changed and thats my original point of discussion in Part-2

To be continued..............Part-2

Thanking you,

Sujit

Saturday, December 11, 2010

Case Study on Cyber Stalking

Dear Friends,

Just few days ago one of my valuable reader from USA mailed me and asked me whether I had an experience on real life critical cyber-stalking case investigation or not and I mailed him some of my real life investigation experiences but I did not published those in my blog, so I want to share one of my critical case investigation on very recent complaint about cyber-stalking, which made the life of a gentle lady hell.

Before reading this case study I would request you to visit here for knowing details about cyber stalking.

This is a case where, a multinational renowned corporate house A complained that someone had been continuously sending offensive and abusive email to their customer care mail id with some obscene pictures as attachment in the name of a lady of another company B. All the mail was clearly disclosing the name of that lady and the content was written in such a manner that it seemed to company A that the mail was sent by the lady herself due poor package to her. Here company A outsourced his customer care work from company B.

During enquiry it came into light that the mail id in the name of lady of company B was created by a guy as his love offer was not accepted by that lady. The guy became so violent that one day he assaulted the husband of the lady badly and searching the address of the lady from Telephone Directory he dialed her neighbors in different names from different booths and tried to prove her prostitute in her locality. Investigating agency during investigation further revealed that the said guy also did same kind of work one year ago and at that time he sent mail to Police authority by sending a challenge to explode bomb in a renowned temple on the night of a Puja celebration. At that time also she used another girls email id as she also turned him down. His intention in both the cases was to make hell the life of the lady of his target. He thought Police would arrest those ladies as their names came openly in the email.
Finally he was arrested and all the evidences were collected against him by the investigating agencies in both the cases.

Someone may call this guy Erotomanic or love obsessional cyber stalker. Whatever it may be but they are really dangerous to the society as a large. If these kind of guys are refused by his desired one they can do anything.

So my friends beware from them. Best of luck.

Thanking you,

Urproblemmysolution Team

Thursday, December 2, 2010

What are Different types of Phishing

Hi My Friends,

I had already discussed you a lot about phishing but I think I have made you clear about the meaning and style of phishing but now the time has come to tell you about different types of phishing. I think you are thinking about online lottery fraud, job offer fraud, and fund transfer fraud and so on but my friends it’s not like that. I am going to tell about “Old wine in new bottle”. What does it mean? It is the style of business men to bring their old product in new style and in some specific style. I did not mention it earlier as all of these are phishing but some of friends told me to write about these topics otherwise writing about phishing will be incomplete.
Initially all the experts in the cyber world called all these activities are phishing and as time moves the experts started to christen the name of style of phishing as follows:-

A) Spear Phishing: - This comes in the form email like updating banking password, email id password and so on but this kind of email comes to a specific group of persons like the employees of a company or a government organization or same group and so on. It seems that the mail has come from your employer for divulging important information.

B) Smishing: - This comes in the form of SMS message. Like your mobile number has won $5 bln in a lottery and you are requested to contact Mr. G…… in his email id a….@hotmail.com and so on. And you are trapped.

C) Vishing: - This style of phishing happens through VoIP i.e:- Voice over Internet Protocol . Actually this is a combination of ‘Voice’ and ‘Phishing’. You are getting a net call from someone, who is asking you about your personal important information in the name of a company, where you have stake or you are a stake holder, employee or some other style. You will see an example of vishing in this blog here.

D) Whale-Phishing: - I think all of you know about whale. Whale is a big fish in the sea. So if you consider the net is a sea where we all are fish then if the phisher catches the most important person by his technique, he is a whale phisher. So I think you have understood about whale phishing. It’s a style of phishing where phisher targets the most important person of the concern like CEO of a company.

So my friends now you are clear about the types of phishing which are used to catch the netizens. Be cautious and divulge your personal information to him only, whom you trust after proper verification.

For reading other case studies on cyber crime pl visit.

Best of luck.

Thanking you,

Urproblemmysolution Team

Wednesday, November 24, 2010

Link of Identity Theft, Phishing and Cheating

My Dear Friends,

Now I am going to share you few live case studies,which I got for the last 6 months in the field of my daily work in investigating cyber crime related cases. I am sharing this real life stories with you as my moto of writing this blog is to make you aware about the cyber crime and keep you away from cyber criminals.

This is the crime of phishers in disguise of HR of a renowned company. Now read step by step what they are doing for cheating a person, who is in search of a job.

Step 1:- They are sending mails by offering a lucrative job to different persons, who had enlisted their names on online job searching portals, as an HR of a renowned company such as IBM, Videocon, Sony by creating false email id in the name of that company. Like:- hr_sony@gmail.com, hr.videoconindia@hotmail.com and so on.

Step 2:- Then the mail receiver is receiving the offer and communicating with them over a telephone number as provided by them.

Step 3:- They are claiming security deposit for that good job and asking them to deposit that money in the bank accounts as supplied by them. Thereafter they are telling them to send the scan copy to them to their email id.

Step 4:- They are stopping to communicate with the victim.

Now you will be perplexed to know that the victims are educated guys even the the experienced guys of IT sector. I am telling you about a girl from Cog....... company became a victim and came to me for lodging a complaint. I asked her about her qualification and what he told that seemed to me that she is educated with specialization in IT sector.

You will definitely call me so what this thing may happen to anyone but my friends you should keep in mind that an HR of a company like Sony will not have an email id of other domain i.e gmail or yahoo or rediff or others their email id must end with @sony.com or some domain name which belongs to Sony. Its an example. So my dear friends before depositing any amount in any one's bank account pl verify the person who has sent you the mail as in most of the cases the address of phone numbers and bank account numbers are fake and they can't be traced.

So I would suggest you not to accept this kind of online offers until you are confirmed about the caller or sender and please find the original website of the employer company and make a communication with them to know the genuinity of your offer letter. I think now you will remain alert from this scoundrels and if you can't understand me pl mail me I will respond or comment here and I will respond.
Best of luck and be ahead and beware of phishers, who are stealing identity of another and cheating the educated job aspirants.

Thanking you

Love your Country.

Tuesday, November 16, 2010

Case Studies on Net Banking Hacking

Hi Friends,

I think all of you are well and you have enjoyed a lot in your life in the festive season of India and also in other countries. Today I am going to tell you another style of phishers for your net banking hacking for making you aware from the hackers or cyber criminals. But before learing this you will have to read my earlier posting here. Here you found how they got your URN no. for activating third party in your bank account. But what they are doing that is as follows:- After step 2 of that article ;-

Step 3:- They take attempt to add the bank account of their agents with the hacked bank account. And then as per the banking security system the URN no goes to the mobile no of the person, who actually owns the bank account.

Step 4:- They call the person by claiming that they are from the ...... bank in which the bank of the customer exists and then they ask him/her to give the said number which reached in his/her mobile through sms as they were testing the genuinity of the mobile number of the customer.

Step 5:- The account holder gives the said URN no as he does not know anything about it. Now they get success to transfer the amount to their agent's account.
Thats all.

So my friends be cautious and don't do the mistake in future. I am really very very sorry and beg a pardon from you as I ought to tell you earlier but what to do I was very much busy with my official work so I was absent from my blog so many days.

Wish all of best of luck and thanking you,

Urproblemmysolution Team

Wednesday, June 16, 2010

How to secure your wifi


How To Secure Your Wifi

Dear Friends,

I told you earlier that the final episode of my wifi series is yet to come and that is the most important part of this series as this will tell you how to secure the wifi connections of everybody.

So lets go to that part:-

Wi-fi implementations vary from one application area to another. Like Home to Enterprise to Public Hotspots.

The Above Table summarises the minimum requirements that need to meet in each case in order to ensure adequate security.

I shall explain the terms very briefly to make this table meaningful to the users. Interested users may google these terms to get further detail very easily.

MAC Binding: This technology is used to allow only MAC addresses of few known devices to associate with the Access Point. This is suitable for very small sized network and is not scalable. Also this is prone to MAC spoofing attack.

Hide SSID: SSID is the identification string of a wi-fi network. The default behaviour of any access point is to broadcast SSID in beacon. This helps the users to easily identify the networks available to them. Wireless best practice guidelines suggests to hide SSID so that it is not visible through casual attempts to locate a wi-fi network. However there are plenty of scanners available those can detect hidden SSIDs.

Captive Portal: This is an authentication portal which is kept captive either inside the access point or any user authentication system. If this is implemented, whenever a user tries to use the wi-fi network for internet browsing for the first time, he is challenged with this portal by automatically redirecting his URL request in browser to the authentication portal page. On successful authentication, the originally requested URL is returned to the user's browser and access to the network is granted. However on failure access to the network is denied.

WPA2-PSK: Discussed earlier.

WPA2-802.1x: Discussed earlier. 802.1x implementation would require a RADIUS server and optional directory databases like LDAP/Active Directory/NDS etc.

SSL: SSL in this context is a PKI mechanism clubbed with 802.1x. This will require the presence of one or more digital certificate servers. This is applicable to different variants of EAP authentication - EAP/TLS, PEAP,LEAP etc.

SMS Auth: TRAI has mandated that in any public hotspot the owner must architect the user authentication process to prove the identification of the user against a photo identity card. Now an indirect process of complying this is SMS Auth. In this process an access PIN is system generated and consequently system delivered to the User’s mobile phone number upon successful user authentication. Now this indirectly takes care of the user’s identity verification against any valid photo-identity proof because the same has been done before this mobile phone number was allotted against the user’s name by the service provider.

Logging: Logging is a Facility to generate data and record the same to identify who with what MAC address and IP address had associated with which access point when for what duration. Most of the access points would generate such data. It is not a good idea to store the log data in the device itself. This will allow a hacker to remove all the traces of work very easily. It is required that the logs be stored on a Syslog server.

LWAP: Light Weight Access Points are APs those do not store the configurations locally on the devices. Rather the configurations are done and maintained in a central device called Controller. These are particularly required in a large wi-fi network. Centralised configuration ensures tight security policy enforcement all across.

AAP: Autonomous access points store configurations locally. These should be used in homes and very small office networks only.

I think it will be very helpful for you and please don't forget to say thanks to my friend Sudipto.

Thanking you

Urproblemmysolution team

Sunday, June 13, 2010

What is latest cyber attack

What is the Latest cyber attack?

Dear Friends,

In this world both good and bad mentality persons exist. Someone wants to safe his country and someone pays money to criminals for committing crime and they get the benefit and steal all the requirements. This thing is happenning in the world and now in the cyber world. The countries with evil power are attacking the network system of their neighbour. So here is an example for you which has been published very recently. So pl read it and raise hatred to them.:

South Korea – Two South Korean government websites were struck by the second cyberattack in a week, but suffered no major damage, the government said Saturday.

Most of the computers trying to access the websites were traced to China, the Ministry of Public Administration and Security said in a statement.

The Korean Culture and Information Service and the Justice Ministry were the targets of the so-called denial of service attacks on Friday, in which large numbers of computers try to connect to a site at the same time to overwhelm the server, the statement said.

The security ministry said it quickly blocked access by 274 computers with Internet Protocol addresses — the Web equivalent of a street address or phone number — mostly in China.

On Wednesday, similar attacks originating from China occurred on a site run by the security ministry.

The statement said it was investigating who was behind the attacks.

Last year, government websites in South Korea and the U.S. were paralyzed by similar cyberattacks that South Korean officials believed were conducted by North Korea.

South Korean media have reported that North Korea runs an Internet warfare unit aimed at hacking into U.S. and South Korean military networks to gather information and disrupt service. Source (news.yahoo.com)

So after few years all of we will see that a country has taken responsibility to make cyber terrorists.

With Thanks

urproblemmysolution Team

Saturday, June 12, 2010

The First Birth Aniversary of our Blog

To my Thousands of Readers and Commentators/Experts,

I, Sujit Mukerherjee, Adminstrator of this blog started this project a year ago solely for the purpose of making Netizens around the globe aware of the acuteness and seriousness of Cyber Crime that is pervading around us and spreading so quickly that it has become increasingly difficult for Law Enforcement alone to fight this menace. You Netizons have to fight too - almost on a daily basis. That was the reason for the birth of this Blog.

The Blog has received such a fantastic response - thanks to all of you who have contributed through articles and comments.

There is an important announcement to make. I started this Blog on the 12Th of June 2009, and four days later someone booked a domain by the same name - who has nothing todo with this Blog. Please ignore that domain.

"urproblemmysolution" is my brainchild and I wanted to extend this Blog later to a proper domain (dotcom), but that will not happen. Someone already booked that domain name. Please remember that the dotcom site has nothing to do with us. I will announce a domain name through this blog on a future date whenever I'm ready to move this blog to a proper domain name.

Till then please continue reading this blog and bless me with your valuable comments and articles - just as you have been doing so far.

Wishing this Blog a very happy Birthday and Thanking you profusely,

This is your Admin Sujit Mukherjee.....

PS: Today on the first Aniversary of this Blog I have given birth to another Blog that I'm sure will provide very interesting reading material for all of you.

Please await my first posting at www.dailypapercutting.blogspot.com

Wednesday, June 9, 2010

Cybercriminals and Phishers are in the FIFA 2010 World Cup





My Dear Friends,

I have already discussed about details of wifi except one part and I think now you are thinking that what is that part. I will tell you that later. But now I am going to tell you what is the latest threat to the netizens related to the forthcoming world cup i.e: FIFA WOrld Cup 2010.

Not only me most of the invabitants of the earth are mad about FIFA WORLD CUP as Maradona, Messi, Kaka, Drogba, Roonie, Robinho many many players will show their skill in this world football championship and most of us will try to enjoy this game through television direct telecast or reach to South Africa to see the games directly by sitting in the gallery and their are 6 official partners and Visa is one of them.

Cybercriminals and phishers are using this sentiments of football lovers. Now definitely a question has come in your mind that what are they doing with these? So I will tell you now what are they doing with these. The cyber criminals and phishers are using malwares with the attachments in the form of tickets and lottery winning mails in the name of Visa and so on. They are also sending you the world cup playing charts of different teams with an attachment and when you open it a malware will be installed in your computer and your computer will be used as zombie by the cyber criminals. For knowing about zombie you are requested to read my previous postings. Not only that the phishers will take your money in their previous style.

Here are two pictures for you, enlarge it. So be cautious. Don't open any unknown mail about FIFA world Cup 2010 and don't download any attachment from this mail as this includes zero day vulnarability, which will not be traced by any antivirus.

Thanking You

Urproblemmysolution Team