Chapter 8: Emails Flashcards

1
Q

where can you find digital evidence relating to an email investigation

A

local machine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what will the local machine tell you about an email

A
  • destination
  • email server(s)
  • device that was used to access the email
  • logs from the internet service provider
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is an emaill protocol

A

a standard that is used to allow 2 computer hosts to exchange email communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what does SMTP stand for

A

simple mail transfer protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what does RFC stand for and what is it

A
  • request for comments
  • used on internet/communications technology to create standards
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what do mail servers use SMTP for

A

to send and receive email messages from all points of the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what is the SMTP pathway

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

describe POP3

A
  • standardized protocol
  • allows users to access their inbox and download emails
  • cannot send emails (only receive)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what does POP3 stand for

A

post office protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what does IMAP stand for

A

internet message access protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

describe IMAP

A
  • standard protocol
  • used by clients to access emails on an email server
  • complete inbox management w multiple clients
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is the main difference between IMAP and POP

A
  • POP retrieves contents of the mailbox
  • IMAP was designed as a remote access mailbox protocol
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what are some examples of standard webmail providers

A
  • gmail
  • yahoo
  • outlook
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what happens to user deleted emails on web-based email servers

A

remain on the server until the system deletes them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what is a characteristc feature of web-based emails

A

when a user deletes an email, it goes into “trash/deleted” folder for a period of time before actually being deleted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what allows a DFI to serve judicially approved subpoenas/search warrants on emails

A
  • mailbox and domain name
  • message ID
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

what info does the email header contain

A
  • source
  • transmission
  • destination
  • (of a specific email)
18
Q

what is Message-Id field

A
  • unique identification for every email that has been sent
  • it is globally unique
19
Q

what does it mean if 2 emails have the same message ID

A
  • the email server is not compliant w the standard
  • OR
  • a user has altered the email
20
Q

what does Return-Path mean

A

it is the address where undeliverable messages will be sent

21
Q

what are the different types of IPv4 addresses

A
  • public
  • private
22
Q

what happens when you see a private IP address in emails

A

you cannot identify the provider

23
Q

what does MIME stand for

A

multipurpose internet mail extensions

24
Q

what is MIME

A

internet standard for allowing emails to accept text

25
Q

what unique thing does the system do when email attachments are present

A
  • the system separates the body of the email based upon the data type for each segment
  • each segment will start w a MIME header including PART
26
Q

what clients are prevalent in the consumer market and why

A
  • microsoft outlook/ outlook express
  • cause its preinstalled on the system
27
Q

in what file type does outlook store info

A
  • various
  • including pst, .mdb or .ost
28
Q

what is an OST file

A

an offline file that may be stored on the user’s hard drive

29
Q

where do you find a MDB file

A

on the server

30
Q

where do clients store windows emails

A

as an .eml file under the windows live mail folder

31
Q

what is Mozilla Thunderbird

A

a free + open source email client

32
Q

how does thunderbird store emails

A
  • within a .MBOX file
33
Q

what does MSF stand for

A

Mail summary files

34
Q

how can users access emails without a client

A

webmail

35
Q

can users use a client to access web-based emails

A

yes, but nobody really does

36
Q

if a DFI wants to access content on a web-based email, what will they need

A

A search warrant

37
Q

what can be found in the temporary internet files/cache

A
  • images
  • text
  • any component of the web page the user has viewed in their browser
38
Q

what did Gmail do differently regarding images and files

A
  • no longer saved to the users local storage device
  • instead they used Asynchronous JavaScript and XML files
39
Q

what do we look at before accessing the cache

A

the internet history

40
Q
A