Saturday, February 23, 2008

SPOOFING

WHAT IS SPOOFING:-


Spoofing is defined as :

Spoofing is basically "hiding your IP or MAC address and sending data or mail from Fake IP or MAC address."


Spoofing is an attempt to gain access to a system by posing as an authorized user. Synonymous with impersonating, masquerading or mimicking.
ftp.fas.org/irp/congress/1996_hr/s960605a.htm

Unauthorized use of legitimate identification and authentication data, however it was obtained, to mimic a subject different from the attacker. Impersonating, masquerading, piggybacking, and mimicking are forms of spoofing.
www.npd.ufes.br/Glossary_Security.htm

Impersonating another person or computer, usually by providing a false email name, URL or IP address.https://www.key.com/html/A-11.2.1.html

A method of fooling network end stations into believing that keep-alive signals have come from and return to the host. Polls are received and returned locally at either end of the network and are transmitted only over the open network if there is a condition change. ...www.nettedautomation.com/glossary_menue/glossary_s.html

CyberCrime Law of USA:-
Spoofing is UNDEFINED. Because it is not needed. The need for CyberCrime LAW is that of "phishing".
“Phishing” is a form of Internet fraud that aims to steal valuable information such as credit cards, social security numbers, user IDs and passwords
http://www.cybercrimelaw.org/tags/phishing/

Definitions of Cyber Crime in Pakistan LAW:-
The definitions of each type of cyber crimes are incorrect both from an IT technical point of view and also from a legal point of view. They are completely different from internationally recognized definitions and are simply incorrect. (e.g. Malicious code, electronic fraud, spoofing, cyber stalking).

Spoofing defined in BILL that is Article 7 is as follows:-
15. Spoofing. —Whoever establishes a website, or sends an electronic message with a counterfeit
source intended to be believed by the recipient or visitor or its electronic system to be an authentic
source with intent to gain unauthorized access or obtain valuable information which later can be
used for any unlawful purposes commits the offence of spooling.
(2) Whoever commits the offence of spoofing specified in sub-section
(1) shall be punished with imprisonment of either description for a term which may extend to three years, or with fine, or with both.

Now from PAKISTAN BILL definition of Spoofing seems to be incomplete. It is mixed up with Phishing. It is also mixed up with spamming.
The undefined investigation powers, lack of safeguards, violation of Fundamental Human Rights and Unconstitutional provisions of the Bill will assist the Cyber criminal.
These incorrect definitions will help cyber criminals in disproving charges and obstruct investigation agencies from fulfilling their duties.
So Pakistan will act as a HEAVEN for cyber-criminals. As no body can prove the actual criminal wrong. And may be a innocent person will suffer because of these laws.

SPOOFING A CRIME OR NOT?

From all above discussion about definition of Spoofing in Pakistan and in rest of world i am really surprised that no other country has defined spoofing in terms of CyberCrime but Pakistan. May be Pakistani's need more security in comparison to other countries of the world.
Actually CyberCrime is something very different from electronic fraud and forgery, unauthorized access to code and misuse of encryption, cyber stalking, spamming, unauthorized interception and cyber terrorism. Hiding yourself is not a crime. Pakistani's Bill has confused it with PHISHING in which one sends mail and gets illegal access to other person personal information and data.
Spoofing should be kept aside from these Cyber crimes list. As it is not a CRIME.

No comments: