Grover Kearns, PhD, CPA, CFE Class 11 1
Videos 2 How works Spoofing spoofing-101/science-technology/ SMTP Spoofing =related Tracing an
Reading Headers From > Sat Aug 17 16:00: Return-Path: > Received: from exanpcn4.arinc.com ([ ]) by mta009.verizon.net (InterMail vM ) with ESMTP id for >; Sat, 17 Aug :00: Received: from exanpcn2.arinc.com (unverified) by exanpcn4.arinc.com (Content Technologies SMTPRS 4.1.5) with ESMTP id for >; Sat, 17 Aug :02: Received: by exanpcn2.arinc.com with Internet Mail Service ( ) \tid ; Sat, 17 Aug :00: Message-ID: From: "Conner, Richard C. \\(RCONNER\\)" > To: "my-home-address" > Subject: Hello Date: Sat, 17 Aug :00: MIME-Version: 1.0 X-Mailer: Internet Mail Service ( ) Content-Type: text/plain 3
Not required by SMTP
From > Sat Aug 17 16:00: Return-Path: > Received: from exanpcn4.arinc.com ([ ]) by mta009.verizon.net (InterMail vM ) with ESMTP id for >; Sat, 17 Aug :00: Received: from exanpcn2.arinc.com (unverified) by exanpcn4.arinc.com (Content Technologies SMTPRS 4.1.5) with ESMTP id for >; Sat, 17 Aug :02: Received: by exanpcn2.arinc.com with Internet Mail Service ( ) \tid ; Sat, 17 Aug :00: Message-ID: From: "Conner, Richard C. \\(RCONNER\\)" > To: "my-home-address" > Subject: Hello Date: Sat, 17 Aug :00: MIME-Version: 1.0 X-Mailer: Internet Mail Service ( ) Content-Type: text/plain unique message ID
From > Sat Aug 17 16:00: Return-Path: > Received: from exanpcn4.arinc.com ([ ]) by mta009.verizon.net (InterMail vM ) with ESMTP id for >; Sat, 17 Aug :00: Received: from exanpcn2.arinc.com (unverified) by exanpcn4.arinc.com (Content Technologies SMTPRS 4.1.5) with ESMTP id for >; Sat, 17 Aug :02: Received: by exanpcn2.arinc.com with Internet Mail Service ( ) \tid ; Sat, 17 Aug :00: Message-ID: From: "Conner, Richard C. \\(RCONNER\\)" > To: "my-home-address" > Subject: Hello Date: Sat, 17 Aug :00: MIME-Version: 1.0 X-Mailer: Internet Mail Service ( ) Content-Type: text/plain
7
8 From > Sat Aug 17 16:00: Return-Path: > Received: from exanpcn4.arinc.com ([ ]) by mta009.verizon.net (InterMail vM ) with ESMTP id < CWZT20372.mta009. for >; Sat, 17 Aug :00: Received: from exanpcn2.arinc.com (unverified) by exanpcn4.arinc.com (Content Technologies SMTPRS 4.1.5) with ESMTP id for >; Sat, 17 Aug :02: Received: by exanpcn2.arinc.com with Internet Mail Service ( ) \tid ; Sat, 17 Aug :00: Message-ID: From: "Conner, Richard C. \\(RCONNER\\)" > To: "my-home-address" > Subject: Hello Date: Sat, 17 Aug :00: MIME-Version: 1.0 X-Mailer: Internet Mail Service ( ) Content-Type: text/plain
From > Sat Aug 17 16:00: Return-Path: > Received: from exanpcn4.arinc.com ([ ]) by mta009.verizon.net (InterMail vM ) with ESMTP id for >; Sat, 17 Aug :00: Received: from exanpcn2.arinc.com (unverified) by exanpcn4.arinc.com (Content Technologies SMTPRS 4.1.5) with ESMTP id for >; Sat, 17 Aug :02: Received: by exanpcn2.arinc.com with Internet Mail Service ( ) \tid ; Sat, 17 Aug :00: Message-ID: From: "Conner, Richard C. \\(RCONNER\\)" > To: "my-home-address" > Subject: Hello Date: Sat, 17 Aug :00: MIME-Version: 1.0 X-Mailer: Internet Mail Service ( ) Content-Type: text/plain 9
Another Example – Partial Header Delivered-To: Received: by with SMTP id n7cs40710pbq; … Return-Path: … Received: from [ ] by omp1017.mail.bf1.yahoo.com with NNFMP; 20 Jun … Received: (qmail invoked by uid 60001); 20 Jun :58: Message-ID: Received: from [ ] by web mail.bf1.yahoo.com via HTTP; Mon, 20 Jun :58:58 PDT X-Mailer: YahooMailClassic/ YahooMailWebService/ Date: Mon, 20 Jun :58: (PDT) From: Grover Kearns Subject: Be Alert To: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Now get to work!
Mobile Phone Forensics Unauthorized photos, videos, audio recording Digital fraud and data duplication Industrial espionage Acceptable use policy 12
Mobile Phone Forensics SIM Cards- Subscriber Identity Module SD Cards- Secure Digital 13
Mobile Phone Forensics International Mobile Subscriber Identity Integrated Circuit Card Identifier (ICC-ID) Authentication Key (K i ) Location Area Identity SMS Message / Contact s Stored Data on SIM Cards 14
Mobile Phone Forensics Stored Data on SD Cards Call logs Text Messages Electronic documents Phonebooks Videos Music Photos Calendar 15
Smart Phone Videos How to Save Data to a Phone's Micro SD Memory Card sd-memory-card.html SIM Card Reader spy.html?gclid=CIfqu8zqwqkCFYgW2god9AZacwhttp:// spy.html?gclid=CIfqu8zqwqkCFYgW2god9AZacw Hacking the iPhone 16
Problems with Mobile Forensics Lack of single standards How cell phones store messages Multitude of models Generations: analog, PCS, 3G, 4G, ???
Remote Phone Wipes 18 All smart phones can be “wiped” remotely. Check the web for instructions for each phone.
Securing Mobile Phones Securing the mobile phone is the first action Turning it off will lose RAM If on it can be wiped remotely Wrap multiple times in foil or Place in empty paint bucket
21
SIMCon Reads SIM files Analyzes file content Recovers deleted text messages Manages PIN codes Exports data to spreadsheet files 22
Comparing 3G to 4G 3G Average download speed is 1 to 100 Mbps Allowed and Internet access Allows apps with music downloads and video calling Applies to all smartphones 4G A set of standards that hasn't really been clearly defined Average download speeds are about twice as fast as 3G at 4-6 Mbps More apps, More secure
Digital Networks CDMA – Uses full radio frequency spectrum. Sprint and Verizon use this. GSM – Used by AT&T and T-Mobile and standard in Europe and Asia. You can switch your SIM card with GSM! OFDM – Probably will be the chosen technology for 4G.
Smart Phones Contain: RAM, ROM, microprocessor, radio module, hardware interfaces. Many have memory cards (SIM). Store system data in EEPROM. OS is stored in ROM.
26
28
29
30
31
Jailbreaking & Unlocking Unlocking allows owner to switch SIM cards Could void warranty Jailbreaking allows owner to add apps that are not supported by vendor Not illegal 32
Recovering Deleted Files QnZY&feature=related 33
Web Sites - Spoofing 101/science-technology/ Tracing an How to find IP address and shutdown network computer uE&feature=related Restoring deleted files elated
Web Sites – Mobile Phones SIM Card Reader spy.html?gclid=CIfqu8zqwqkCFYgW2god9AZacw Hacking iPhone How to Save Data to a Phone's Micro SD Memory Card micro-sd-memory-card.html