<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4670689435261450796</id><updated>2011-07-08T04:23:18.483-04:00</updated><title type='text'>Cyber-Tr@ce Technologies</title><subtitle type='html'>Cyber-Tr@ce Technologies specialize in crimes facilitated by computers. They assist police departments, private investigators, bail bond companies, and attorneys. Cyber-Tr@ce Technologies association with investigators from around the world allow us to legally and quickly have access to information that otherwise would be very difficult to obtain.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cybertracetechnologies.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4670689435261450796/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cybertracetechnologies.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Covert Investigations</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://1.bp.blogspot.com/_gbOFiqJaQaQ/SgTjXmzAPWI/AAAAAAAAADU/rzFdUgh7Azc/S220/image1.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4670689435261450796.post-7449568403830341148</id><published>2010-08-07T10:45:00.000-04:00</published><updated>2010-08-07T10:45:08.141-04:00</updated><title type='text'>Covert Investigations</title><content type='html'>&lt;object style="background-image: url(&amp;quot;http://i3.ytimg.com/vi/bjn56ndXPbg/hqdefault.jpg&amp;quot;);" height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/bjn56ndXPbg&amp;amp;hl=en_US&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/bjn56ndXPbg&amp;amp;hl=en_US&amp;amp;fs=1" allowscriptaccess="never" allowfullscreen="true" wmode="transparent" type="application/x-shockwave-flash" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4670689435261450796-7449568403830341148?l=cybertracetechnologies.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybertracetechnologies.blogspot.com/feeds/7449568403830341148/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybertracetechnologies.blogspot.com/2010/08/covert-investigations.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4670689435261450796/posts/default/7449568403830341148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4670689435261450796/posts/default/7449568403830341148'/><link rel='alternate' type='text/html' href='http://cybertracetechnologies.blogspot.com/2010/08/covert-investigations.html' title='Covert Investigations'/><author><name>Covert Investigations</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://1.bp.blogspot.com/_gbOFiqJaQaQ/SgTjXmzAPWI/AAAAAAAAADU/rzFdUgh7Azc/S220/image1.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4670689435261450796.post-1005753268426081497</id><published>2009-05-08T21:02:00.096-04:00</published><updated>2009-08-28T21:05:21.713-04:00</updated><title type='text'>Investigations Involving the Internet</title><content type='html'>When an individual uses the Internet as a common way of communication, they leave what we call "footprints. “We’re able to gather that personal information for your review. An Internet profile reveals where they've been on the Internet including their interaction with social networking groups (e.g. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;MySpace&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Facebook&lt;/span&gt;, etc).&lt;br /&gt;&lt;br /&gt;While on the Internet they may have admitted committing a crime, denied knowing a person of which they've previously had conversations with, or placed pictures online of which could be very damaging to his or her reputation.&lt;br /&gt;&lt;ul style="color: rgb(0, 0, 0);"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;TRACING AN EMAIL&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;There are two types of email traces, an "EMAIL ADDRESS" trace and an "EMAIL MESSAGE" trace. Below is the explaination of both:&lt;br /&gt;&lt;br /&gt;Tracing an &lt;span&gt;"EMAIL ADDRESS"&lt;/span&gt; reports only the mail server for the address. This is useful for identifying both the company and the network that provides the service for the email address. What it doesn't do is provide information about who sent the email.&lt;br /&gt;&lt;br /&gt;Tracing an &lt;span&gt;"EMAIL MESSAGE"&lt;/span&gt; provides a lot more information on the sender. Every email message includes a header with valuable information. This allows you to analyze the email header and the IP address of the computer where the message originated. Also it may come down to how much of a "Footprint" the sender has left on the Internet.&lt;br /&gt;&lt;br /&gt;With that said you never know if the sender temporarily created the email address to use as a communication tool only to delete it a few minutes later, thus leaving no "Footprints" on the Internet. Additionally many times a sender CAN be physically and/or geographically pin-pointed by producing a subpoena to the host ISP.&lt;br /&gt;&lt;br /&gt;*********************************************************************************&lt;br /&gt;&lt;ul style="color: rgb(51, 0, 51);"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;TRACING AN &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;IP&lt;/span&gt; ADDRESS OR DOMAIN NAME&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;*Resolve domain name&lt;/span&gt;&lt;br /&gt;First up on your list is to try and resolve the domain name (e.g. &lt;a class="linkification-ext" href="http://www.resolve.com/" title="Linkification: http://www.resolve.com"&gt;www.resolve.com&lt;/a&gt;) to an &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;IP&lt;/span&gt; address. Many software tools are available to aid investigators in resolving domain names into &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;IP&lt;/span&gt; addresses.&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;NOTE&lt;/span&gt;:&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0); font-weight: bold;font-size:100%;" &gt;Be aware that inquiries made on these Websites could be monitored and recorded. It’s important to perform inquiries from a computer that cannot be traced back to you.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;Determine and record domain name registrations&lt;/span&gt;. Information that's available is the registrar’s name and addresses, billing information, administrative contact such as telephone and fax numbers, the range of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;IP&lt;/span&gt; addresses associated with the domain name, and technical contact information. The list of contacts may also provide additional information regarding the specific computer being investigated, including both the location and the person designated to receive legal process.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;NOTE&lt;/span&gt;:&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;&lt;span style="color: rgb(0, 0, 0); font-style: italic;"&gt;The very same process can also be used to resolve an &lt;/span&gt;&lt;span style="color: rgb(0, 0, 0); font-style: italic;" class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;IP&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0); font-style: italic;"&gt; address to a domain name to obtain contact information.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*&lt;span style="color: rgb(51, 0, 51);"&gt;Where’s the evidence? &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Information can be found in numerous locations, including the user’s computer, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;the ISP&lt;/span&gt; for the user,&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt; and the ISP&lt;/span&gt; for a victim and/or suspect.&lt;br /&gt;&lt;br /&gt;&lt;span&gt;Log files can be contained on the victim’s, and/or the suspect’s&lt;/span&gt; routers, firewalls, web servers, email servers, and other connected devices.&lt;br /&gt;&lt;br /&gt;Most &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;ISPs&lt;/span&gt; can identify the registered user assigned to the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;IP&lt;/span&gt; address at “the specific time,” enabling the investigators to request additional information. However, the investigator may have to use “traditional investigative methods” to identify the person using the account at that time.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*&lt;span style="color: rgb(51, 0, 51);"&gt;Provide legal service of process&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The third step is to determine who the appropriate parties are, so as to contact and/or serve the legal documents. Warrants, court orders, or subpoenas are usually required to release the exact end-user information to law enforcement agencies. Many of these requirements are governed by the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;ECPA&lt;/span&gt;, (Electronic Communications Privacy Act), and other applicable Federal and State laws. A preservation letter may assist in preserving information until the proper legal requirements can be met. These requests should specify the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;IP&lt;/span&gt; address, the date, and the time, including the time zone. Be aware of the need for expeditious service of preservation letters under 18 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;USC&lt;/span&gt; § 2703(f) (appendix G).&lt;br /&gt;&lt;br /&gt;&lt;span&gt;Information that may be obtained from the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;ISP&lt;/span&gt; may include &lt;/span&gt;the registered owner, the address, payment method, dates, connection times&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;, and the IP&lt;/span&gt; addresses.&lt;br /&gt;&lt;br /&gt;*********************************************************************************&lt;br /&gt;&lt;ul style="color: rgb(51, 0, 51);"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;SPOOFING, MASKING, AND REDIRECTING&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;Advanced methods of hiding activities on the Internet include hiding the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;IP&lt;/span&gt; address, pretend to be someone else, and sending traffic through another &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;IP&lt;/span&gt; address. These methods are commonly referred to as:&lt;br /&gt;&lt;br /&gt;a. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;"IP&lt;/span&gt; Masking" is a method of hiding or obscuring the true source &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;IP&lt;/span&gt; address.&lt;br /&gt;b. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;"IP&lt;/span&gt; Spoofing" is a method of impersonating another system’s &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;IP&lt;/span&gt; address.&lt;br /&gt;c. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;"IP&lt;/span&gt; Redirecting" forwarding/routing Internet traffic to an obscured &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;IP&lt;/span&gt; address.&lt;br /&gt;&lt;br /&gt;Advanced training is needed to investigate or identify when these actions have occurred. Even after completing legal process, “traditional investigative methods” still may be necessary to identify the end-user. In many cases, masking, spoofing, or redirecting may prevent the identification of the user.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*&lt;span style="color: rgb(51, 0, 51);"&gt;Dynamic and static &lt;/span&gt;&lt;span style="color: rgb(51, 0, 51);" class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;IP&lt;/span&gt;&lt;span style="color: rgb(51, 0, 51);"&gt; addresses&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;"Dynamic &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;IP&lt;/span&gt; Addresses" are temporarily assigned from available addresses registered to an &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;ISP&lt;/span&gt;. These addresses are assigned to a device when a user begins an online session. As a result, a device’s &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;IP&lt;/span&gt; address may vary from one &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;logon&lt;/span&gt; session to the next.&lt;br /&gt;&lt;br /&gt;"Static &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;IP&lt;/span&gt; Addresses" are permanently assigned to devices configured to always have the same &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;IP&lt;/span&gt; address.&lt;br /&gt;&lt;br /&gt;A person, business, or organization maintaining a constant Internet presence, such as a Website, generally requires a static &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;IP&lt;/span&gt; address. Both the date and time an &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;IP&lt;/span&gt; address was assigned MUST be determined to tie it in to a specific device or user account. The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;ISP&lt;/span&gt; may maintain historical log files relating these dynamically assigned &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;IP&lt;/span&gt; addresses back to a particular subscriber and/or user at a particular time.&lt;br /&gt;&lt;br /&gt;*********************************************************************************&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;LEGAL CONSIDERATIONS&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;All investigations involving both computer evidence and the recovery of computer information, specific legal requirements and reliable forensic procedures must be followed to the tee.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Sample language:&lt;/span&gt;&lt;br /&gt;When drafting legal process, the following "sample language" may be useful. However, the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;ISP&lt;/span&gt; may require other specific language.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;*ISP&lt;/span&gt; account information:&lt;/span&gt; “Any and all subscriber information relating to the account of (Name) including but not limited to user identity, user account information, screen names, account status, detailed billing records, e-mail account information, caller line identification (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_38"&gt;ANI&lt;/span&gt;), account maintenance history notes, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_39"&gt;IP&lt;/span&gt; history from (Date) to present.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Email address information:&lt;/span&gt; “Any and all subscriber information relating to the individual who registered and maintains the e-mail address of (&lt;a class="linkification-ext" href="mailto:JonDoe@Email.com" title="Linkification: mailto:JonDoe@Email.com"&gt;JonDoe@Email.com&lt;/a&gt;) including but not limited to user identity, user account information, screen names, account status, detailed billing records, e-mail account information, caller line identification (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_40"&gt;ANI&lt;/span&gt;), account maintenance history notes, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_41"&gt;IP&lt;/span&gt; history from (Date) to present.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_42"&gt;*IP&lt;/span&gt; address information:&lt;/span&gt; “Any and all subscriber information relating to the account of the individual who was assigned the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_43"&gt;IP&lt;/span&gt; address of (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_44"&gt;IP&lt;/span&gt; Address) on (Date) at (Time and Time Zone) and the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_45"&gt;IP&lt;/span&gt; address of (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_46"&gt;IP&lt;/span&gt; Address) for (Date) at (Date and Time Zone) including but not limited to user identity, user account information, screen names, account status, detailed billing records, e-mail account information, caller line identification (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_47"&gt;ANI&lt;/span&gt;), account maintenance history notes, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_48"&gt;IP&lt;/span&gt; history from (Date) to present."&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Domain name information:&lt;/span&gt; “Any and all information relating to the identity of the individual who registered and maintains the domain names of (&lt;a class="linkification-ext" href="http://www.xxxxxxxx.com/" title="Linkification: http://www.xxxxxxxx.com"&gt;www.xxxxxxxx.com&lt;/a&gt;) and (&lt;a class="linkification-ext" href="http://www.xxxxxxxx.org/" title="Linkification: http://www.xxxxxxxx.org"&gt;www.xxxxxxxx.org&lt;/a&gt;) including but not limited to all account information, billing records including credit card number or other payment information, user identity, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_49"&gt;IP&lt;/span&gt; history, and caller line identification.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Web page information:&lt;/span&gt; “All information on the individual who created and maintains the (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_50"&gt;ISP&lt;/span&gt;) Web page (Web page name) including but not limited to user identity, user account information, billing records, e-mail account information, caller line identification, usage logs, and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_51"&gt;IP&lt;/span&gt; history.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Telnet session providers:&lt;/span&gt; “Any and all &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_52"&gt;IP&lt;/span&gt; history relating to Internet traffic of (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_53"&gt;xxxxx&lt;/span&gt;.net) and user logs of (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_54"&gt;xxxx&lt;/span&gt;.net’s) Telnet sessions for (Date) and (Date) including but not limited to user identity, user name, user commands issued, and user address.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Point of Presence (POP) information:&lt;/span&gt; “Any and all information relating to the (ANS.NET or other &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_55"&gt;ISP&lt;/span&gt;) Point of Presence location that issued the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_56"&gt;IP&lt;/span&gt; (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_57"&gt;IP&lt;/span&gt; Address) on (Date/Time) including but not limited to dial-in access phone number, physical address, and (Telephone Company) to whom the dial-in access phone number is subscribed.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;*Outgoing telephone records:&lt;/span&gt; “Any and all information including but not limited to subscriber information and billing information for the address of (Address of Subscriber). Any and all information including, but not limited to subscriber information and billing information for the telephone number of (Telephone Number). Include a listing of any local outgoing calls made from the above address. Include above information for any and all telephone numbers listed for the above address for the period of (Date/Time).”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;NOTE:&lt;/span&gt; &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);font-size:100%;" &gt;In determining legal issues, at a minimum the following should be considered: &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255); font-weight: bold; font-family: verdana;" href="http://caselaw.lp.findlaw.com/data/constitution/amendment04/"&gt;&lt;span&gt;The Fourth Amendment&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;If the e-mail resides on the sender’s or recipient’s computer or other device, then the steps taken to secure that evidence must be analyzed under the Fourth Amendment and State constitutional requirements. The investigator must consider whether the person on whose computer the evidence resides has a reasonable expectation of privacy on that computer. The Fourth Amendment would require a search warrant or one of the recognized exceptions to the search warrant requirements such as consent or exigent circumstances.&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.usdoj.gov/criminal/cybercrime/s&amp;amp;smanual2002.htm#_III_"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);font-family:verdana;" &gt;Electronic Communications Privacy Act &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;If the e-mail is stored by an Internet Service Provider or any other communications network, retrieval of that evidence must be analyzed under the Electronic Communications Privacy Act (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_61"&gt;ECPA&lt;/span&gt;). &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_62"&gt;ECPA&lt;/span&gt; creates statutory restrictions on government access to such evidence from &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_63"&gt;ISPs&lt;/span&gt; or other electronic communications service providers.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_64"&gt;ECPA&lt;/span&gt; requires different legal processes to obtain specific types of information. Basic subscriber information (name, address, billing information including a credit card number, telephone toll billing records, subscriber’s telephone number, type of service, and length of service) can be obtained by subpoena, court order, or search warrant.&lt;br /&gt;&lt;br /&gt;Transactional information (such as Web sites visited, e-mail addresses of others from whom or to whom the subscriber exchanged e-mail, and buddy lists) can be obtained by court order or search warrant.&lt;br /&gt;&lt;br /&gt;A search warrant can be used to obtain content information from retrieved e-mail and must be used to obtain &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_65"&gt;unretrieved&lt;/span&gt; stored e-mails. Real-time access (traffic intercepted as it is sent or received) requires a wiretap order under the provisions of Title III.&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www4.law.cornell.edu/uscode/18/3121.html"&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);font-family:verdana;" &gt;Pen Register and Trap and Trace Statute&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;This applies not only to telephone communications, but also Internet communications. For example, every e-mail communication contains to and from information. A pen/trap device captures &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_66"&gt;noncontent&lt;/span&gt; information of communications in real time.&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.cdt.org/wiretap/wiretap_overview.html"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);font-family:verdana;" &gt;Title III wiretaps&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Title III may need to be considered, depending on how an &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_67"&gt;ISP&lt;/span&gt; executes a request to obtain a subscriber’s e-mail. However, to obtain e-mail in real time as it is ingoing and outgoing from the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_68"&gt;ISP&lt;/span&gt;, a Title III wiretap order is always required.&lt;br /&gt;&lt;br /&gt;Information obtained from an e-mail message can be valuable evidence. This chapter provides techniques to obtain one piece of the investigation puzzle. Once the e-mail account subscriber is identified, however, other investigative techniques should be used to actually place an individual at the keyboard at the time the message was sent. Keep in mind the legal procedures that must be followed to ensure the evidence gathered can be used in court.&lt;br /&gt;&lt;br /&gt;****************************************************************************************************************&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;PERVERTED JUSTICE RECENT BUSTS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://www.howdev.com/products/feedsweep/producer.aspx?feeds=http%3a%2f%2fwww.perverted-justice.com%2frss.php&amp;amp;title=Perverted+Justice+Recent+Busts&amp;amp;maxoutput=20&amp;amp;implementation=divs"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4670689435261450796-1005753268426081497?l=cybertracetechnologies.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4670689435261450796/posts/default/1005753268426081497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4670689435261450796/posts/default/1005753268426081497'/><link rel='alternate' type='text/html' href='http://cybertracetechnologies.blogspot.com/2009/05/tracing-email.html' title='Investigations Involving the Internet'/><author><name>Covert Investigations</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://1.bp.blogspot.com/_gbOFiqJaQaQ/SgTjXmzAPWI/AAAAAAAAADU/rzFdUgh7Azc/S220/image1.gif'/></author></entry></feed>
