Chapter 8: Emails Flashcards

1
Q

where can you find digital evidence relating to an email investigation

A

local machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what will the local machine tell you about an email

A
  • destination
  • email server(s)
  • device that was used to access the email
  • logs from the internet service provider
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is an emaill protocol

A

a standard that is used to allow 2 computer hosts to exchange email communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what does SMTP stand for

A

simple mail transfer protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what does RFC stand for and what is it

A
  • request for comments
  • used on internet/communications technology to create standards
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what do mail servers use SMTP for

A

to send and receive email messages from all points of the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what is the SMTP pathway

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

describe POP3

A
  • standardized protocol
  • allows users to access their inbox and download emails
  • cannot send emails (only receive)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what does POP3 stand for

A

post office protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what does IMAP stand for

A

internet message access protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

describe IMAP

A
  • standard protocol
  • used by clients to access emails on an email server
  • complete inbox management w multiple clients
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is the main difference between IMAP and POP

A
  • POP retrieves contents of the mailbox
  • IMAP was designed as a remote access mailbox protocol
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what are some examples of standard webmail providers

A
  • gmail
  • yahoo
  • outlook
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what happens to user deleted emails on web-based email servers

A

remain on the server until the system deletes them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what is a characteristc feature of web-based emails

A

when a user deletes an email, it goes into “trash/deleted” folder for a period of time before actually being deleted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what allows a DFI to serve judicially approved subpoenas/search warrants on emails

A
  • mailbox and domain name
  • message ID
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

what info does the email header contain

A
  • source
  • transmission
  • destination
  • (of a specific email)
18
Q

what is Message-Id field

A
  • unique identification for every email that has been sent
  • it is globally unique
19
Q

what does it mean if 2 emails have the same message ID

A
  • the email server is not compliant w the standard
  • OR
  • a user has altered the email
20
Q

what does Return-Path mean

A

it is the address where undeliverable messages will be sent

21
Q

what are the different types of IPv4 addresses

A
  • public
  • private
22
Q

what happens when you see a private IP address in emails

A

you cannot identify the provider

23
Q

what does MIME stand for

A

multipurpose internet mail extensions

24
Q

what is MIME

A

internet standard for allowing emails to accept text

25
what unique thing does the system do when email attachments are present
- the system separates the body of the email based upon the data type for each segment - each segment will start w a MIME header including *_PART_*
26
what clients are prevalent in the consumer market and why
- microsoft outlook/ outlook express - cause its preinstalled on the system
27
in what file type does outlook store info
- various - including pst, .mdb or .ost
28
what is an OST file
an offline file that may be stored on the user's hard drive
29
where do you find a MDB file
on the server
30
where do clients store windows emails
as an .eml file under the windows live mail folder
31
what is Mozilla Thunderbird
a free + open source email client
32
how does thunderbird store emails
- within a .MBOX file
33
what does MSF stand for
Mail summary files
34
how can users access emails without a client
webmail
35
can users use a client to access web-based emails
yes, but nobody really does
36
if a DFI wants to access content on a web-based email, what will they need
A search warrant
37
what can be found in the temporary internet files/cache
- images - text - any component of the web page the user has viewed in their browser
38
what did Gmail do differently regarding images and files
- no longer saved to the users local storage device - instead **they used Asynchronous JavaScript and XML files**
39
what do we look at before accessing the cache
the internet history
40