Amazines Free Article Archive
www.amazines.com - Friday, April 19, 2024
Read about the most recent changes and happenings at Amazines.com
Log into your account or register as a new author. Start submitting your articles right now!
Search our database for articles.
Subscribe to receive articles emailed straight to your email account. You may choose multiple categories.
View our newest articles submitted by our authors.
View our most top rated articles rated by our visitors.
* Please note that this is NOT the ARTICLE manager
Add a new EZINE, or manage your EZINE submission.
Add fresh, free web content to your site such as newest articles, web tools, and quotes with a single piece of code!
Home What's New? Submit/Manage Articles Latest Posts Top Rated Article Search
Google
Subscriptions Manage Ezines
CATEGORIES
 Article Archive
 Advertising (133573)
 Advice (161671)
 Affiliate Programs (34799)
 Art and Culture (73855)
 Automotive (145712)
 Blogs (75614)
 Boating (9851)
 Books (17223)
 Buddhism (4130)
 Business (1330638)
 Business News (426446)
 Business Opportunities (366518)
 Camping (10973)
 Career (72795)
 Christianity (15848)
 Collecting (11638)
 Communication (115089)
 Computers (241953)
 Construction (38962)
 Consumer (49953)
 Cooking (17080)
 Copywriting (6733)
 Crafts (18203)
 Cuisine (7549)
 Current Affairs (20319)
 Dating (45908)
 EBooks (19703)
 E-Commerce (48258)
 Education (185521)
 Electronics (83524)
 Email (6438)
 Entertainment (159854)
 Environment (28970)
 Ezine (3040)
 Ezine Publishing (5453)
 Ezine Sites (1551)
 Family & Parenting (111007)
 Fashion & Cosmetics (196605)
 Female Entrepreneurs (11853)
 Feng Shui (134)
 Finance & Investment (310615)
 Fitness (106469)
 Food & Beverages (63045)
 Free Web Resources (7941)
 Gambling (30227)
 Gardening (25202)
 Government (10519)
 Health (630137)
 Hinduism (2206)
 Hobbies (44083)
 Home Business (91657)
 Home Improvement (251211)
 Home Repair (46243)
 Humor (4723)
 Import - Export (5459)
 Insurance (45104)
 Interior Design (29616)
 International Property (3488)
 Internet (191031)
 Internet Marketing (146687)
 Investment (22861)
 Islam (1161)
 Judaism (1352)
 Law (80506)
 Link Popularity (4596)
 Manufacturing (20914)
 Marketing (99316)
 MLM (14140)
 Motivation (18233)
 Music (27000)
 New to the Internet (9496)
 Non-Profit Organizations (4048)
 Online Shopping (129734)
 Organizing (7813)
 Party Ideas (11855)
 Pets (38165)
 Poetry (2229)
 Press Release (12689)
 Public Speaking (5643)
 Publishing (7566)
 Quotes (2407)
 Real Estate (126700)
 Recreation & Leisure (95495)
 Relationships (87674)
 Research (16182)
 Sales (80350)
 Science & Technology (110290)
 Search Engines (23514)
 Self Improvement (153300)
 Seniors (6220)
 Sexuality (36010)
 Small Business (49311)
 Software (83033)
 Spiritual (23516)
 Sports (116155)
 Tax (7663)
 Telecommuting (34070)
 Travel & Tourism (308304)
 UK Property Investment (3123)
 Video Games (13382)
 Web Traffic (11790)
 Website Design (56919)
 Website Promotion (36663)
 World News (1000+)
 Writing (35844)
Author Spotlight
ELLIOT CHANG

Financial analyst and author writing on economy and business. ...more
TAL BARNEA

Tal is an electrical engineer with over 25 years of expertise with hardware, software, mechanical an...more
MANMOHAN SINGH

Digital marketing professional with 8 years of experience. A good listner, Stratgist and fun loving ...more
LEMUEL ASIBAL

Lemuel Asibal is a web content writer who also ventures on writing articles and blog posts about any...more
TUSHAR BHATIA

Tushar Bhatia is the Founder President of EmpXtrack Inc with over 19 years of experience in the soft...more


The Case of the Teacher and the Teen Trickster by Steve Burgess





The Case of the Teacher and the Teen Trickster by
Article Posted: 11/05/2009
Article Views: 978
Articles Written: 43
Word Count: 1716
Article Votes: 0
AddThis Social Bookmark Button

The Case of the Teacher and the Teen Trickster


 
Computers,Humor,Law

CSI* - Computer Forensics Files: Real Cases from Burgess Forensics #9 The Case of the Teacher and the Teen Trickster Copyright 2009, by Steve Burgess

The stories are true; the names and places have been changed to protect the potentially guilty.

It was a grey October day, the kind of day when a guy likes to cozy up next to a bank of servers to keep warm, when the Teacher first called me. "They think I'm nuts!" were the words emanating from the phone. Well, just because you're paranoid doesn't mean they're not out to get you. I sat up and went to my desk, away from the noisy fans cooling off all those Gigahertzes. "What's the problem, Miss?"?

The young woman explained that she was a not-yet-tenured teacher in a New England (greyer there than here) high school with a problem. Seems that a student in one of her classes was repeating things in the classroom that she had uttered only the night before in the apparently illusory privacy of her own living room. This was happening on a repeated basis and this little freak was freaking her out. She made sure her windows were shut at night. She had someone else speak inside her house while she listened outside - no words escaped to be heard, much less repeated. She looked around for bugs…found only a few spiders.

She'd hired a P.I. to sweep for listening devices - none were found. She went to the police, who were uninterested without some evidence. Her supervisor at the school would not take it seriously. The principal at the school thought she was nuts. She felt that she was in danger of being fired and losing out on a career she'd savored. She was at her wit's end and sounded it.?

She began to suspect her computer was the means of access to invading her privacy, but had no idea how. She already had identified the subject individual and did an admirable amount of research on the subject of computer invasion. She sent me reams of chat logs, articles about cyberinvasions, firewall logs, and other suspicious-looking goings-on with her computer. ?

I put on my data galoshes and began to wade through the deluge to see what looked like a threat and what did not, and to see if I could find the means of remote access, if any.?

Like the old saying that to a hammer everything looks like a nail, then to a victim, everything begins to look suspiciously like an attack. When there are actual bogeymen around, every sound makes a person jump. Let's take on a few of the suspects. ?

Norton Antivirus had picked out some. One was "lsass.shutdown" - the Sasser Worm. A bad character indeed. By contrast, lsass.exe is a part of Windows XP itself. Sasser came in looking like something harmless, but shut down computers - sometimes before they even finished booting. Airline flights had to be cancelled. Satellite communications were blocked. Insurance companies and banks had to close down for a short while. The Sasser Worm was a bad actor, but it wasn't giving remote control access and after all, her antivirus program had used its own kind of handcuffs to subdue that particular intruder.?

Her computer told her that it was recovering orphaned files and security descriptions, replacing bad clusters and bad logfiles, and fixing unreadable security. All are signs of problems, but are messages generated by Windows' own repair programs, Chkdsk and Scandisk, and aren't openings for an intruder to walk into the computer unopposed.?Anther scary Norton message read, "NIS is protecting your connection to a newly detected network on adapter "WAN (PPP/SLIP) Interface". But this was just the program reporting on the computer's own wide area network adapter and Internet access being enabled.?

She noticed that an oddly named program called "Wild Tangent" seemed to be active. Turns out that Wild Tangent is a game network company. It is pretty active in using the computer's network resources, and puts a lot of advertisements on the user's computer. But as bothersome as some find it, it comes preinstalled on many computers, including the Teacher's Dell. Not a likely avenue for remote control by an unauthorized user.?

Our little heroine even learned to use Netstat (stands for "network statistics"). Netstat displays network connections, statistics, routing tables, and more juicy info. Linux users can directly invoke it. Windows users can bring it up through a DOS box (command shell) by clicking on "Start" then "Run", then typing in "CMD", and finally "netstat" in the window that comes up. Mac users can invoke it by first bringing up the "Terminal" available in the Utilities that come with a Macintosh. But netstat can bring up a screenloads of hard-to-understand information. Try it yourself with various switches (like "netstat -a" or "netstat -p"). Hers was unalarming to a jaundiced but practiced eye.?

She considered getting a firewall and watching the logs. But slogging through firewall logs is a scary nightmare when you don't know precisely what you're looking for, and don't completely understand what you're looking at. There are so many hundreds of roboprograms knocking at everyone's computer back door all day long that successfully identifying each could be all a person does all day, every day. It's like describing your entire day in detail, including what you said. "Today I said hello. Today I wrote that I said hello. Today I wrote about writing about saying hello. Today I noticed that I hadn't put "hello" in quotes and made a note about that. Today I cussed long and vociferously and stopped writing it down." You get the idea. "Today I got an idea!"?

Once I got hold of her computer, I of course first made an identical copy of the hard drive. I don't recall exactly, but I may have used Media Tools Professional from RecoverSoft.

I figured we were looking for a Remote Control Trojan.?

Like the original Trojan Horse, Trojans may come attached unnoticed to a free gift, such as a game, or attached to an email. Once inside the formerly secure walls of your computer, a payload is unleashed but unlike the original Trojans, may go unnoticed while the originator remotely, and often surreptitiously, takes control of your computer. I ran several anti-malware programs, including my favorite at the time, Ewido (later bought by Grisoft, itself then acquired by AVG). I also ran Norton, Panda, Spybot and more. Different programs catch different stuff. A few viruses were shoveled up, but for remote control Trojans - bupkis. I had to do something else.?

I'm no stranger to hare-brained ideas, so I dreamed up a DIY tool. I made a list of remote control Trojan names, aliases, and executables (the actual name of the file that does the dirty work) and compiled them into a table. I fired up trusty old EnCase Forensic, loaded the drive, and then input my table as a keyword list. I had EnCase search the entire hard disk - active and compressed files and unallocated space, file slack, MBR, and virtual memory file - for the entries on my new keyword list. From the results, I discarded everything that was part of an antivirus program or dictionary, and skimmed through what was left. ?

And…pay dirt! Sitting in the registry entries from old compressed system restore snapshot files were references to 30 instances of the setup files for one nasty Backdoor Trojan and for one desktop surveillance spyware program. They came complete with dates of installation and IP addresses of the point of origin. Quite a find. ?

It seems our freaky teen perp was a script kiddie. He'd apparently gone to a site that gives away prepackaged hacking and exploit programs to all-comers. Rather than give the teacher an apple, he'd apparently sent her an email with an evil payload. Once in place it was child's work - er, kiddie's work - to control her computer at will. At this point, it was no big deal to turn on our heroine's microphone, record her talking in her living room, download the file to his own computer, then repeat the content back to the Teacher the next day. Who wouldn't be set off-balance by that??

Finally we had enough evidence to let the police complete the job. I sent the report to the DA, who ran with the case. Being a minor, the terrible teen got off with a warning, some unwanted attention, and a transfer to a different classroom.? For the future, I first recommended completely reformatting or replacing her hard disk and securing her Windows Administrator account with a password.

Amazing but true, most people don't know there is an Administrator account on their computer, and leave it wide open and unsecured. Booting into Safe Mode (hold down the F8 key at boot up, select "Safe Mode"), then accessing the user accounts through the Control Panel allows the user to easily set passwords. I suggested getting a new AOL account (if she had to have AOL), and getting a relatively inexpensive hardware firewall. At the time, I suggested the Netgear FVS318.?

The happy ending: our worthy Teacher kept her job, validated her complaints, eventually finished her Master's degree and got to be something of a security expert in her own right. By the time we finished with all the back and forth, it was nearly Spring. As for me, I moved out of the server room and back to my place in the Sun. Okay, it's a desk; it's by a window; it's where I do my forensic thing. ?

This is just one of the many "CSI - Computer Forensics Files: Real Cases from Burgess Forensics." Stay tuned for more stories of deceit uncovered by computer forensics.

Steve Burgess is a freelance technology writer, a practicing computer forensics specialist as the principal of Burgess Forensics, and a contributor to the recently released Scientific Evidence in Civil and Criminal Cases, 5th Edition by Moenssens, et al. Mr. Burgess may be reached at www.burgessforensics.com or via email: steve at burgessforensics dot com

Related Articles - computer forensics, data recovery, fraud, cybercrime, cyberstalking, detective, humor,

Email this Article to a Friend!

Receive Articles like this one direct to your email box!
Subscribe for free today!

 Rate This Article  
Completely useless, should be removed from directory.
Minimal useful information.
Decent and informative.
Great article, very informative and helpful.
A 'Must Read'.

 

Do you Agree or Disagree? Have a Comment? POST IT!

 Reader Opinions 
Submit your comments and they will be posted here.
Make this comment or to the Author only:
Name:
Email:
*Your email will NOT be posted. This is for administrative purposes only.
Comments: *Your Comments WILL be posted to the AUTHOR ONLY if you select PRIVATE and to this PUBLIC PAGE if you select PUBLIC, so write accordingly.
 
Please enter the code in the image:



 Author Login 
LOGIN
Register for Author Account

 

Advertiser Login

 

ADVERTISE HERE NOW!
   Limited Time $60 Offer!
   90  Days-1.5 Million Views  

 

Great Paranormal Romance


TIM FAY

After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
LAURA JEEVES

At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
ALEX BELSEY

I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
GENE MYERS

Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
SUSAN FRIESEN

Located in the lower mainland of B.C., Susan Friesen is a visionary brand strategist, entrepreneur, ...more
STEVERT MCKENZIE

Stevert Mckenzie, Travel Enthusiast. ...more
STEPHEN BYE

Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
SHALINI MITTAL

A postgraduate in Fashion Technology. Shalini is a writer at heart! Writing for her is an expression...more
ADRIAN JOELE

I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
JAMES KENNY

James is a Research Enthusiast that focuses on the understanding of how things work and can be impro...more

HomeLinksAbout UsContact UsTerms of UsePrivacy PolicyFAQResources
Copyright © 2024, All rights reserved.
Some pages may contain portions of text relating to certain topics obtained from wikipedia.org under the GNU FDL license