SlideShare une entreprise Scribd logo
1  sur  3
 HYPERLINK 
http://www.neerajaarora.com/embezzlement-of-telephonic-minutes-a-case-study-on-data-theft-by-hacking/
 Embezzlement of Telephonic minutes: A Case Study on Data Theft by Hacking NET4INDIA Case: The present case pertains to online theft of prepaid internet telephony minutes belonging to the complainant company maintained on its server by one of its employees. The said employee unauthorisedly accessed the server containing the PINS of the Internet Telephony minutes which was restricted by password and access was available to only few key employees. The unauthorized access was noticed from unknown (Internet Protocol address) IPs which the offender used to make unauthorized access. The brief facts of the case: The company N4India Ltd. (N4India) is engaged in providing a range of internet related services including internet telephony and voice over IP network services. It markets its internet telephony services under the brand name of “Phonewala.com”.  Track Online Net India (P) Ltd. is the US Arm of N4India which buys bulk internet telephony minutes from US Companies like; Net2phone, Go2Call etc. The Internet Telephone Minutes (TM) sold in India as (1) Cash Calling Cards (2) Online Cash Cards. The PIN Number of TM is kept online at server of Net2Phone USA (Vendor) under its control –Restricted/protected by passwords to key employees of N4I.  The management noticed the theft of internet telephony minutes which was most surprising as the access to the server was restricted by password which was available to few key employees only. The prepaid Internet Telephony cards belonging to N4I were available at cheaper rates in market not sold by Net4India causing it huge revenue loss.  How the culprit was caught: Obviously, it appeared to be handiwork of some insider. The investigating agency advised the company to change the password and give access to few select key employees. The idea was to trap the person who is making unauthorized access to the server of Net2phone where the PINS of Internet Telephony minutes belonging to Net4India were stored. The intruder making unauthorized access would surely leave behind its footprint in the form of IP address. As predicted, failed unauthorized access was noticed at the web application of US Company Net2Phone server from a specific set of IP addresses. IP Address captured by Web Application Net2Phone’s application recorded failed/successful login from the IP addresses shown below:- Table A: IP AddressDateTimeEvent221.134.63.15119/08/200502.00 AMIncorrect Password221.134.63.15119/08/200502.04 AMIncorrect Password221.134.63.15119/08/200502.07 AMIncorrect Password221.134.63.820/08/200500.30 AMLogin Success221.134.63.820/08/200500.36 AMLogin Success Thus, someone was trying to make unauthorized access to the web application. Who is the intruder? It was noticed that an engineer of the N4India has accessed his email ID harish.s@n4i.net during the same time (as per IST) from the same IP addresses as above. Thus, he was the culprit and mouse trapped. The log detail of the email ID of Mr. Harish was obtained from ISP: Table B: IP addressDateTimeEvent202.71.133.1218/08/0506.10 PMIP belongs to N4I221.134.63.15119/08/0501.57 AMUser ID: Harish.s@n4i.netMachine ID: 10.251.132.151Franchise Details:B1-43, Near East End Apartments, New Ashok Nagar202.71.133.1219/08/0506.45 PMIP belongs to N4I221.134.63.820/08/0500.28 AMUser ID:Harish.s@n4i.netMachine ID: 10.251.132.151Franchise Details:B1-43, Near East End Apartments, New Ashok Nagar The comparative analysis of the Table A vis-à-vis Table B was made which revealed the following: Unauthorised access made by Harish to the web application but he failed.  Harish made unauthorised entry to the Corporate office of the N4I at Noida.  He accessed his email account unauthorisedly from the network of one colleague  He collected the updated authentication details and sent it by his official mail harish.s@n4i.net to his personal E-mail account.  After this he returned home and he tried to access the Net2phone application but his login failed.  He again came to the corporate office and managed to get the appropriate password from the computer at corporate office.  He returned home and accessed his email account and made a successful login to the Net2Phone application  Accused persons arrested: The accused Harish was arrested. He confessed his involvement. He emailed the unauthorized PIN Numbers to his fictitious Email IDs. The PINs & passwords were kept in these emails and forwarded to various buyers. He disclosed the names of buyers; one of such buyer was Mukesh Jindal of Chandigarh. Mukesh Jindal was arrested and he accepted that he purchased TM from Harish and received the same at his personal email ID. The detail of email Id of Mukesh Jindal collected from Rediffmail reveals that said ID was being used by the accused Mukesh Jindal. Collection of electronic evidence: The fake E-mail Id of the Harish was accessed containing pins and passwords to various cash cards of TMs. The data was seized. One hard disk of the computer belonging to Harish was made, seized from his residence: The image copy  prepared, generated hash value.  Seizure Memo prepared.  The laptop used by Mukesh Jindal containing the email records was seized from him: The image copy  prepared, generated hash value.  Seizure Memo prepared.  The mirror image copy of the Hard disks were analyzed-Contained incriminating evidence. Accused persons accessed their personal Email Ids- Misappropriated PINS found.            Other connecting evidence collected: The bank account statements of the banks in which money pertaining to misappropriated data exchanged hands.  Entry register record establishing the entry of Harish at the Corporate office.  Statement of officials of N4I u/s 161 Cr.P.C..  Conclusion of the case: The aforesaid mirror image copy and the hard drive was sent to FSL for forensic report. Forensic Report received corroborating the above facts, thus, connecting the accused persons to crime. Charge sheet against the accused person is filed in the court and awaiting verdict of court.  HYPERLINK 
http://www.neerajaarora.com/
 Neeraj Aarora (Advocate)
Embezzlement Of Telephonic Minutes A Case Study On Data Theft By Hacking
Embezzlement Of Telephonic Minutes A Case Study On Data Theft By Hacking

Contenu connexe

Plus de Neeraj Aarora

Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010
Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010
Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010Neeraj Aarora
 
Current trends in cyber crime scenario
Current trends in cyber crime scenarioCurrent trends in cyber crime scenario
Current trends in cyber crime scenarioNeeraj Aarora
 
State cannot claim sovereign immunity in motor accident cases says delhi high...
State cannot claim sovereign immunity in motor accident cases says delhi high...State cannot claim sovereign immunity in motor accident cases says delhi high...
State cannot claim sovereign immunity in motor accident cases says delhi high...Neeraj Aarora
 
DOCTRINE OF SOVEREIGN IMMUNITY
DOCTRINE OF SOVEREIGN IMMUNITYDOCTRINE OF SOVEREIGN IMMUNITY
DOCTRINE OF SOVEREIGN IMMUNITYNeeraj Aarora
 
Forensic Accountant: Reliability & admissibility as Expert Witness
Forensic Accountant: Reliability & admissibility as Expert WitnessForensic Accountant: Reliability & admissibility as Expert Witness
Forensic Accountant: Reliability & admissibility as Expert WitnessNeeraj Aarora
 
It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009
It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009
It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009Neeraj Aarora
 

Plus de Neeraj Aarora (7)

Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010
Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010
Neeraj aarora cyber_lawyer_article - uncitral arbitration rules, 2010
 
Current trends in cyber crime scenario
Current trends in cyber crime scenarioCurrent trends in cyber crime scenario
Current trends in cyber crime scenario
 
Blowing the whistle
Blowing the whistleBlowing the whistle
Blowing the whistle
 
State cannot claim sovereign immunity in motor accident cases says delhi high...
State cannot claim sovereign immunity in motor accident cases says delhi high...State cannot claim sovereign immunity in motor accident cases says delhi high...
State cannot claim sovereign immunity in motor accident cases says delhi high...
 
DOCTRINE OF SOVEREIGN IMMUNITY
DOCTRINE OF SOVEREIGN IMMUNITYDOCTRINE OF SOVEREIGN IMMUNITY
DOCTRINE OF SOVEREIGN IMMUNITY
 
Forensic Accountant: Reliability & admissibility as Expert Witness
Forensic Accountant: Reliability & admissibility as Expert WitnessForensic Accountant: Reliability & admissibility as Expert Witness
Forensic Accountant: Reliability & admissibility as Expert Witness
 
It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009
It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009
It Amendment ActIT Amendment Act, 2008 notified w.e.f. 27/10/2009
 

Dernier

Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 

Dernier (20)

Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 

Embezzlement Of Telephonic Minutes A Case Study On Data Theft By Hacking

  • 1. HYPERLINK http://www.neerajaarora.com/embezzlement-of-telephonic-minutes-a-case-study-on-data-theft-by-hacking/ Embezzlement of Telephonic minutes: A Case Study on Data Theft by Hacking NET4INDIA Case: The present case pertains to online theft of prepaid internet telephony minutes belonging to the complainant company maintained on its server by one of its employees. The said employee unauthorisedly accessed the server containing the PINS of the Internet Telephony minutes which was restricted by password and access was available to only few key employees. The unauthorized access was noticed from unknown (Internet Protocol address) IPs which the offender used to make unauthorized access. The brief facts of the case: The company N4India Ltd. (N4India) is engaged in providing a range of internet related services including internet telephony and voice over IP network services. It markets its internet telephony services under the brand name of “Phonewala.com”. Track Online Net India (P) Ltd. is the US Arm of N4India which buys bulk internet telephony minutes from US Companies like; Net2phone, Go2Call etc. The Internet Telephone Minutes (TM) sold in India as (1) Cash Calling Cards (2) Online Cash Cards. The PIN Number of TM is kept online at server of Net2Phone USA (Vendor) under its control –Restricted/protected by passwords to key employees of N4I. The management noticed the theft of internet telephony minutes which was most surprising as the access to the server was restricted by password which was available to few key employees only. The prepaid Internet Telephony cards belonging to N4I were available at cheaper rates in market not sold by Net4India causing it huge revenue loss. How the culprit was caught: Obviously, it appeared to be handiwork of some insider. The investigating agency advised the company to change the password and give access to few select key employees. The idea was to trap the person who is making unauthorized access to the server of Net2phone where the PINS of Internet Telephony minutes belonging to Net4India were stored. The intruder making unauthorized access would surely leave behind its footprint in the form of IP address. As predicted, failed unauthorized access was noticed at the web application of US Company Net2Phone server from a specific set of IP addresses. IP Address captured by Web Application Net2Phone’s application recorded failed/successful login from the IP addresses shown below:- Table A: IP AddressDateTimeEvent221.134.63.15119/08/200502.00 AMIncorrect Password221.134.63.15119/08/200502.04 AMIncorrect Password221.134.63.15119/08/200502.07 AMIncorrect Password221.134.63.820/08/200500.30 AMLogin Success221.134.63.820/08/200500.36 AMLogin Success Thus, someone was trying to make unauthorized access to the web application. Who is the intruder? It was noticed that an engineer of the N4India has accessed his email ID harish.s@n4i.net during the same time (as per IST) from the same IP addresses as above. Thus, he was the culprit and mouse trapped. The log detail of the email ID of Mr. Harish was obtained from ISP: Table B: IP addressDateTimeEvent202.71.133.1218/08/0506.10 PMIP belongs to N4I221.134.63.15119/08/0501.57 AMUser ID: Harish.s@n4i.netMachine ID: 10.251.132.151Franchise Details:B1-43, Near East End Apartments, New Ashok Nagar202.71.133.1219/08/0506.45 PMIP belongs to N4I221.134.63.820/08/0500.28 AMUser ID:Harish.s@n4i.netMachine ID: 10.251.132.151Franchise Details:B1-43, Near East End Apartments, New Ashok Nagar The comparative analysis of the Table A vis-à-vis Table B was made which revealed the following: Unauthorised access made by Harish to the web application but he failed. Harish made unauthorised entry to the Corporate office of the N4I at Noida. He accessed his email account unauthorisedly from the network of one colleague He collected the updated authentication details and sent it by his official mail harish.s@n4i.net to his personal E-mail account. After this he returned home and he tried to access the Net2phone application but his login failed. He again came to the corporate office and managed to get the appropriate password from the computer at corporate office. He returned home and accessed his email account and made a successful login to the Net2Phone application Accused persons arrested: The accused Harish was arrested. He confessed his involvement. He emailed the unauthorized PIN Numbers to his fictitious Email IDs. The PINs & passwords were kept in these emails and forwarded to various buyers. He disclosed the names of buyers; one of such buyer was Mukesh Jindal of Chandigarh. Mukesh Jindal was arrested and he accepted that he purchased TM from Harish and received the same at his personal email ID. The detail of email Id of Mukesh Jindal collected from Rediffmail reveals that said ID was being used by the accused Mukesh Jindal. Collection of electronic evidence: The fake E-mail Id of the Harish was accessed containing pins and passwords to various cash cards of TMs. The data was seized. One hard disk of the computer belonging to Harish was made, seized from his residence: The image copy  prepared, generated hash value. Seizure Memo prepared. The laptop used by Mukesh Jindal containing the email records was seized from him: The image copy  prepared, generated hash value. Seizure Memo prepared. The mirror image copy of the Hard disks were analyzed-Contained incriminating evidence. Accused persons accessed their personal Email Ids- Misappropriated PINS found.            Other connecting evidence collected: The bank account statements of the banks in which money pertaining to misappropriated data exchanged hands. Entry register record establishing the entry of Harish at the Corporate office. Statement of officials of N4I u/s 161 Cr.P.C.. Conclusion of the case: The aforesaid mirror image copy and the hard drive was sent to FSL for forensic report. Forensic Report received corroborating the above facts, thus, connecting the accused persons to crime. Charge sheet against the accused person is filed in the court and awaiting verdict of court. HYPERLINK http://www.neerajaarora.com/ Neeraj Aarora (Advocate)