Subscribe by Email


Showing posts with label Email Spoofing. Show all posts
Showing posts with label Email Spoofing. Show all posts

Tuesday, November 26, 2013

Security - What is meant by a spoofing attack?

A spoofing attack can be described as a situation in which a program is successfully masqueraded by another person or program in the area of network security. This is done by falsification of inbound data through which the masquerading program gains an advantage, of the illegitimate kind. A number of TCP/ IP protocols do not have mechanisms for the source and destination authentication of the messages. This makes them too much vulnerable to the spoofing attacks. Thus some extra precautions have to be taken by the applications for verification of the sending and receiving host identity. A source IP address is forged using which IP packets are created. This is done for impersonation of identity of some other computer system and to conceal the sender’s identity. Thus, IP protocol is the basic one that is used for sending data across the networks. Each packet consists of numerical addresses. The header field of the packet is usually forged so that it appears as if it is from someone else.
The man-in-the-middle attacks against the network’s hosts are often carried out with the help of two types of spoofing namely ARP spoofing and the IP spoofing.
The implementation of firewalls having capability of inspecting the packets deeply can prevent the spoofing attacks from taking advantage of the TCP/ IP protocols. This can also be done by taking measures for the verification of the message sender and the recipient’s identity. There are sites which are pay sites and they can be accessed only through a certain log-in page that is approved by them. This enforcement is made by referrer header checking in the HTTP request. This is so because the referrer header can be changed by the unauthorized users to gain access to the site content. This is called referrer spoofing.
Sometimes the copyright holders also use spoofing for inserting un-listenable and distorted versions of works on networks where file is shared. This is termed as poisoning the file – sharing networks. Another type of spoofing attack is the caller ID spoofing. Caller ID info is often provided by the public telephone networks including the name and number of the caller. VoIP (voice over IP) is one such technology in which the caller ID info can be forged by the callers so as to present names and numbers that are false. This false information is then forwarded by the gateways that connect public networks and allow spoofing.
It is also possible that the origination of the spoofed call might be some other country. In that case the laws in the country of the recipient might not be applicable to the caller. This has also limited the effectiveness of the laws against the caller ID spoofing. This results in a lot of scams. Another type is email spoofing or email address spoofing. The information of the sender that you see in the emails can be easily spoofed. Spammers use this technique quite often for hiding their information. This creates problems such as spam backscatter, misdirected bounces and so on.
A GPS receiver can be deceived by GPS spoofing attacks. In this the counterfeit GPS signals are broadcasted that have been structured to appear same as the normal GPS signals. This can also be done with original signals and rebroadcasting them at some other point. Because of the receiver will estimate its position wrongly. One variant of GPS spoofing attack is the carry off attack. This attack involves synchronization and broadcasting of the signals and genuine signals together. This gradually increases the power of the counterfeit signals which causes them to drift away from the genuine signals.


Wednesday, March 7, 2012

What is meant by email spoofing in detail?

What is meant by Email or Electronic Mail?

- Email or electronic mail is the most popular and convenient means for exchange of digital messages and information in the modern world.

- E- Mail facility is harnessed through a computer network probably over an internet connection.

- Earlier the email can be used for sending messages only when both the sender and the recipient were online and such messages were called instant messages.

- But, today the email system is somewhat changed and is entirely based up on a store and forward model.

- When an email is sent, it is stored by the server and later is delivered accordingly.

- The sender and recipient do not require being online though they need to connect to the particular email server in order to send and receive the emails.

- The whole email system is today governed by the simple mail transfer protocol or SMTP rather than FTP or file transfer protocol that was used earlier.

Problems faced by Email Systems
These email system like any other system has too got many problems like:

1. Attachment size limitation
2. Overloading of information
3. Spamming
4. Computer viruses
5. Email spoofing
6. Email bombing
7. Tracking of sent and received emails
8. Privacy concerns

This article is dedicated to the worst problem being faced by the email today i.e., “email spoofing”.

Introduction to Email Spoofing

Most of us are aware about the content spoofing; the email spoofing is also somewhat same only with the only difference being that it affects emails rather than web sites or web applications.

"An email is said to have been spoofed when its sender’s address as well as its header part have been altered to make it seem as though it has been originated from a source different from the actual source."

What makes these emails so vulnerable to email spoofing?

- More and more emails fall victims to email spoofing since the simple mail transfer protocol (SMTP) does not provide any techniques or methodologies for the authentication of these emails.

- It becomes comparatively easy for the attackers to forging and impersonating the emails.

- In some cases there might be legitimate causes for forging an email but in other cases the cause can be quite mischievous like phishing and spamming in order to hide the origination of the email.

- The attacker can easily change the email properties like its return path, reply to and from fields etc and make it appear as though somebody else had sent the email hiding the identity of the actual email sender.

- The recipient comes in to believing that the email has been received from the address as altered and stated in the “from” field when it is actually form a different source.

- Such emails are said to be spammed and bear the address of the spam email in the “reply to” field.

- Most of the spam emails are malicious in nature and may be infected with a Trojan, virus or worm and so on.

- Some might be just for the sake of advertisement of some cause.

- Earlier before the advent of the spam, the legitimately spoofed emails were used as a viable business model.

- Consequently the spam emails came to be recognized as an annoying problem. This problem called for the need of anti spam methodologies.

- Spoofing the IP address is somewhat difficult as compared to spoofing of the email content.

- This is so because of the great bit size of the IP address.

- To overcome such spoofing problems techniques such as following are used:
1. PGP cryptographic signatures technique
2. Using SSL or TLS in mail transfer software
3. Other encryption techniques.

Proper authentication is the only solution for preventing spoofing and bombing of emails.


Facebook activity