CHAPTER 6 - Computer Fraud and Abuse Techniques
Hacking
• Unauthorized access, modification, or use of a computer system or other electronic device
Social engineering
• Techniques, usually psychological tricks, to gain access to sensitive data or information
• Used to gain access to secure system or locations
Malware
• Any software which can be used to do harm
botnet– Robot Network
• Network or hijacked computers
• Hijacked computers carry out processes without users knowledge
• Zombie–hijacked computer
Denial-of-service (DoS) Attack
• Constant stream of requests made to a Web-server (usually via a Botnet) that overwhelms and shuts down service
Spoofing
• Making an electronic communication look as if it comes from a trusted official source to lure the recipient into providing
information
Types of Spoofing
Email
• E-mail sender appears as if it comes from a different source
Caller-ID
• Incorrect number is displayed
IP address
• Forged IP address to conceal identity of sender of data over the internet or to impersonate another computer system
Address Resolution Protocol (ARP)
• Allows a computer on a LAN to intercept traffic meant for any other computer on the LAN
SMS
• Incorrect number or name appears, similar to Caller-ID but for text messaging
Web page
• Phishing
DNS
• Intercepting a request for a Web service and sending the request to a false service
Hacking Attacks
Cross-Site Scripting
• Unawanted code is sent via dynamic Web pages disguised as user input
Buffer Overflow
• Data is sent that exceeds computer capacity causing program instructions to be lost and replaced with attacker instructions
SQL injection (insertion)
• Malicious code is inserted in the place of query to a database system
Man-in-the-Middle
• Hacker places themselves between client and host
Other Hacking Attacks
Password Cracking
• Penetrating system security to steal passwords
War Dialing
• Computer automatically dials phone numbers looking for modems
Phreaking
• Attacks on phone systems to obtain free phone service
Data Diddling
• Making changes to data before, during, or after it is entered into a system
Data Leakage
• Unauthorized copying of company data
Hacking Embezzlement Schemes
Salami Technique
CHAPTER 6 - Computer Fraud and Abuse Techniques
• Taking small amounts from many different accounts
Economic Espionage
• Theft of information, trade secret, and intellectual property
Cyber-bullying
• Internet, cell phones, or other communication technologies to support deliberate, repeated, and hostile behavior that
torments, threatens, harasses, humiliates, and embarrasses, or otherwise harms another person.
Internet Terrorism
• Act of disrupting electronic commerce and harming computers and communication
Internet Misinformation
• Using the internet to spread false or misleading information
Internet Auction
• Using an internet auction site to defraud another person
- Unfairly drive up bidding
- Seller delivers inferior merchandise or fails to deliver at all
- Buyer fails to make payment
Internet Pump-and-Dump
• Using the internet to pump up the price of a stock and then selling it
Social Engineering Techniques
Identity Theft
• Assuming someone else’s identity
Pretexting
• Inventing a scenario that will lull someone into divulging sensitive information
Posing
• Using a fake business to acquire sensitive information
Phishing
• Posing as a legitimate company asking for verification type information: passwords, accounts, usernames
Pharming
• Redirecting Web site traffic to a spoofed Web site
Type squatting
• Typographical errors when entering a Web site name cause an invalid site to be accessed
Tab napping
• Changing an already open browser tab
Scavenging
• Looking for sensitive information in items thrown away
Shoulder Surfing
• Snooping over someone’s shoulder for sensitive information
Lebanese Loping
• Capturing ATM and card numbers
Skimming
• double-swiping a credit card
Chipping
• painting a device o read credit card information in a credit card reader
Eavesdropping
• listening to private communications
Types of Malware
Spyware
• Secretly monitors and collects personal information about users and sends it to someone else
• Adware
- Pops banner ads on a monitor, collects information about the user's Web-surfing and spending habits, and forwards
it to the adware creator
Key logging
• Records computer activity, such as a user’s keystrokes, e-mails sent and received, Web sites visited, and chat session
participation
Trojan Horse
• Malicious computer instructions in an authorized and otherwise properly functioning program
CHAPTER 6 - Computer Fraud and Abuse Techniques
Time bombs / logic bombs
• Idle until triggered by a specified date or time, by a change in the system, by a message sent to the system, or by an event that
does not occur
More Malware
Trap Door / Back Door
• A way into a system that bypasses normal authorization and authentication controls
Packet Sniffers
• Capture data from information packets as they travel over networks
• Rootkit
- Used to hide the presence of trap doors, sniffers, and key loggers; conceal software that originates a denial-ofservice or an e-mail spam attack; and access user names and log-in information
Superzapping
• Unauthorized use of special system programs to bypass regular system controls and perform illegal acts, all without leaving
an audit trail